External Assessment · Fixed Scope

External attack surface assessment.

A structured review of what an attacker sees from the outside. Subdomain enumeration, port scanning, service fingerprinting, vulnerability identification, email integrity, credential exposure, cloud leak hunting, and a written executive report with prioritized remediation.

What's included

OSINT & Attack Surface
Subdomain enumeration via certificate transparency, DNS reconnaissance, forgotten assets, related domains, and historical data.
Port Scanning
Full TCP scan across all discovered hosts, top UDP ports, service and version detection, and banner grabbing.
Vulnerability Identification
Service-level vulnerability checks against discovered software, with manual validation to eliminate false positives.
Web Application Checks
Directory enumeration, technology fingerprinting, common misconfigurations, and targeted checks for injection classes where applicable.
Email & Domain Integrity
SPF, DKIM, and DMARC review, plus a spoofing risk assessment for your primary sending domains.
Credential Exposure
Breach and credential-leak lookups for email addresses associated with your domain, sourced from public and commercial databases.
Cloud & Data Leak Hunting
Public storage buckets, exposed backup files, misconfigured services, and other unintended public data exposure.
SSL/TLS & Headers
Cipher suite review, certificate expiry and configuration, HTTP security headers, and protocol version checks.
Executive Report (PDF)
Findings ranked by real-world exploitability, each with a concrete remediation step. Written for both technical and non-technical readers.

Scope and exclusions

This is an external assessment. It covers what is reachable from the public internet. It does not include internal network testing, authenticated application testing, physical access, or social engineering. Those are available as separate engagements.

What "one engagement" covers. A single primary domain plus associated subdomains, up to a reasonable ceiling we agree on during scoping. If the footprint is unusually large, we will tell you before starting and either cap the scope or adjust the price. No surprises.

Pricing

Standard external assessment $3,500
Additional primary domain $1,200
Retest after remediation (within 90 days) $800
Rush delivery (5 business days) $1,500

Fixed fee. No hourly billing. Invoice issued on engagement start, payable on delivery.

Timeline

Day 0 — Scoping call
30 minutes. Confirm in-scope domains, rules of engagement, and points of contact. We sign your NDA if you have one.
Days 1–3 — Reconnaissance and scanning
Passive OSINT, then active scanning. Rate-limited to avoid disruption.
Days 4–7 — Manual validation
Each finding is manually verified. Automated scanner noise is discarded before it reaches the report.
Days 8–10 — Report writing
Executive summary, technical findings, remediation roadmap. Delivered as PDF.
Day 10 — Debrief call
45-minute walkthrough with your team. Questions answered, priorities agreed.

What you get

What we do not do. We do not deliver a raw scanner output renamed as a report. We do not bill for findings a client cannot act on. We do not sell ongoing retainers on top of an assessment unless you ask for one.

Enquire about an assessment

Send a message with your primary domain and a preferred week. We will confirm scope, price, and start date within one business day.