External Assessment · Fixed Scope
External attack surface assessment.
A structured review of what an attacker sees from the outside. Subdomain enumeration, port scanning, service fingerprinting, vulnerability identification, email integrity, credential exposure, cloud leak hunting, and a written executive report with prioritized remediation.
What's included
OSINT & Attack Surface
Subdomain enumeration via certificate transparency, DNS reconnaissance, forgotten assets, related domains, and historical data.
Port Scanning
Full TCP scan across all discovered hosts, top UDP ports, service and version detection, and banner grabbing.
Vulnerability Identification
Service-level vulnerability checks against discovered software, with manual validation to eliminate false positives.
Web Application Checks
Directory enumeration, technology fingerprinting, common misconfigurations, and targeted checks for injection classes where applicable.
Email & Domain Integrity
SPF, DKIM, and DMARC review, plus a spoofing risk assessment for your primary sending domains.
Credential Exposure
Breach and credential-leak lookups for email addresses associated with your domain, sourced from public and commercial databases.
Cloud & Data Leak Hunting
Public storage buckets, exposed backup files, misconfigured services, and other unintended public data exposure.
SSL/TLS & Headers
Cipher suite review, certificate expiry and configuration, HTTP security headers, and protocol version checks.
Executive Report (PDF)
Findings ranked by real-world exploitability, each with a concrete remediation step. Written for both technical and non-technical readers.
Scope and exclusions
This is an external assessment. It covers what is reachable from the public internet. It does not include internal network testing, authenticated application testing, physical access, or social engineering. Those are available as separate engagements.
What "one engagement" covers. A single primary domain plus associated subdomains, up to a reasonable ceiling we agree on during scoping. If the footprint is unusually large, we will tell you before starting and either cap the scope or adjust the price. No surprises.
Pricing
Standard external assessment
$3,500
Additional primary domain
$1,200
Retest after remediation (within 90 days)
$800
Rush delivery (5 business days)
$1,500
Fixed fee. No hourly billing. Invoice issued on engagement start, payable on delivery.
Timeline
Day 0 — Scoping call
30 minutes. Confirm in-scope domains, rules of engagement, and points of contact. We sign your NDA if you have one.
Days 1–3 — Reconnaissance and scanning
Passive OSINT, then active scanning. Rate-limited to avoid disruption.
Days 4–7 — Manual validation
Each finding is manually verified. Automated scanner noise is discarded before it reaches the report.
Days 8–10 — Report writing
Executive summary, technical findings, remediation roadmap. Delivered as PDF.
Day 10 — Debrief call
45-minute walkthrough with your team. Questions answered, priorities agreed.
What you get
- A written report with an executive summary and technical detail, both in the same document.
- Each finding rated by exploitability and business impact, not just CVSS score.
- Exact remediation steps — config changes, patches, or policy updates.
- A debrief call where we walk through the findings and answer questions.
- A retest option within 90 days to confirm remediation.
What we do not do. We do not deliver a raw scanner output renamed as a report. We do not bill for findings a client cannot act on. We do not sell ongoing retainers on top of an assessment unless you ask for one.
Enquire about an assessment
Send a message with your primary domain and a preferred week. We will confirm scope, price, and start date within one business day.