Core service
External Infrastructure Penetration Testing
An attacker’s-eye assessment of internet-facing systems, services and remote-access infrastructure.
External infrastructure testing evaluates the systems an internet-based attacker can discover and reach. Safestorm identifies the exposed attack surface, verifies weaknesses manually and assesses whether they provide a credible route to unauthorised access, sensitive information or a foothold into the wider environment.
Founder-led technical delivery
Why Safestorm for this assessment
Drawing on red-team and adversary-simulation experience, Felix assesses the perimeter as a connected attack surface rather than a collection of unrelated IP addresses. The work prioritises discoverability, viable entry paths and controlled proof of impact while respecting operational safety.
- More than six years’ offensive-security experience
- OSCP and OSEP certified
- Red teaming, adversary simulation and control validation
- Published IPv6 research presented at BSides London
Felix’s prior experience includes identifying high-impact weaknesses in healthcare environments. Client identities and engagement details remain confidential.
What the assessment covers
Final coverage is agreed during scoping and reflects your technologies, user roles, threat model and operational constraints.
- Internet attack-surface discovery across agreed domains, addresses and subsidiaries
- DNS, TLS, certificate, mail and security-header configuration
- Exposed network services, management interfaces and unexpected protocols
- VPN, remote desktop, file-transfer and other remote-access gateways
- Authentication controls, MFA coverage, account enumeration and password policy
- Known vulnerabilities, unsupported software and unsafe service configuration
- Cloud-hosted endpoints, origin exposure and perimeter trust relationships
- Controlled exploitation and post-exploitation only where explicitly authorised
Common risks identified
Testing is not limited to this list. These examples illustrate the types of material risk the assessment is designed to uncover.
- Unmanaged or forgotten internet-facing systems outside normal patching processes
- Remote-access services that permit account discovery or lack robust MFA
- Critical known vulnerabilities with a practical external attack path
- Exposed management services, sensitive metadata or diagnostic interfaces
- Perimeter compromise providing a foothold into internal or cloud environments
A controlled process
How the engagement works
- Step 1
Confirm ownership, scope, exclusions and third-party authorisation
- Step 2
Establish rules of engagement and emergency contacts
- Step 3
Discover and fingerprint reachable assets and services
- Step 4
Assess exposed services, identity controls and configuration
- Step 5
Validate viable compromise paths under agreed constraints
- Step 6
Report, debrief and confirm remediation through retesting
Who this service is suitable for
- Organisations seeking assurance over their public attack surface
- New services or remote-access platforms before internet exposure
- Businesses following acquisitions, migrations or perimeter changes
- Teams validating vulnerability-management and external monitoring coverage
Not sure whether this is the right assessment? Safestorm can help define the assurance question before recommending a scope.
Methodology and industry references
Testing is risk-led and tailored rather than reduced to a checklist. Relevant, recognised guidance helps structure coverage and communicate results.
Referencing a framework does not represent certification against it or guarantee compliance with every control.
Frequently asked questions
How do you establish the external scope?
Scope normally includes confirmed IP addresses, domains and cloud endpoints owned or authorised by the customer. Safestorm helps identify adjacent assets, but testing does not extend to third parties without written authorisation.
Is denial-of-service testing included?
Not by default. Destructive, volumetric and availability-impacting tests require a separate objective, safeguards and explicit written approval.
How is this different from an external vulnerability scan?
Scanning helps identify potential issues at scale. Penetration testing adds manual enumeration, validation, attack-path analysis and business context, reducing false positives and identifying weaknesses scanners commonly miss.
Define the right scope
Tell us what you need to assess, your timescale and the assurance outcome you need. We will propose a proportionate scope and clear rules of engagement.
Discuss your requirements