External Network Penetration Testing Services

Scanned by everyone. Tested by someone.

Scanners hit your edge every day and call it clean. A senior U.S. engineer reads the same hosts by hand and finds the one way in. When we reach what matters, we leave a card.

The Internet

Scanned every day

  1. VPN Portal

    Clean

  2. Mail Login

    Info

  3. Web App

    Low

  4. Cloud Storage

    Clean

  5. Admin Panel

    Low

  6. Forgotten Host

    Rated Low

    Exploited

    Unpatched. Reverse shell.

Internal Network

Domain Admin

  • Scanner
  • Scanner pass
  • Raxis engineer

Nothing replaces skill. Illustrative scope. A scanner passed all six. One was the way in.

What We Test

The pentester on your scope call is the one breaking in, and the one retesting your fix. We launch from Raxis attack infrastructure across the internet, the same vantage a real attacker has. No hardware, no travel, no agents; we need your IP ranges and domains.

Reconnaissance & OSINT

We map your attack surface and hunt exposed credentials, leaked data, and anything that lowers the bar for an attacker.

Full Service Enumeration

Every exposed host, port, and service, identified and fingerprinted.

Manual Exploitation

We exploit by hand and chain weaknesses into real impact, not a list of theoretical risk.

Password Attacks

Spraying and credential attacks against VPN, email, and login portals test your MFA, lockout, and password policy.

Exposed Web Surfaces

Public login pages and forms probed for injection, authentication bypass, and information disclosure.

Cloud Perimeter

Internet-facing assets in AWS, Azure, and Google Cloud tested alongside your traditional infrastructure.

Findings We See in the Wild

A scanner rated three of these Low and cleared the rest. Each one became access. This is the difference the hero shows, on real external scopes.

Open Telnet & FTP

No credentials required, and file uploads allowed.

Exposed Admin Pages

Default credentials that reveal device settings and customer data.

Weak Login Pages

Valid usernames confirmed, and unlimited guesses allowed.

Missing MFA

VPN and email where one guessed password becomes full access.

Forgotten Systems

Outdated software with a public exploit already written.

Leaked Credentials

Breach-dump passwords that still work on live systems.

Two Ways to Test Your Perimeter

Same senior engineers, same manual tradecraft, same live findings in Raxis One. The difference is when you want us on it: once, for a fixed window, or all year, every time it changes.

What You Get

Everything you need to understand, fix, and prove your posture, written by the engineer who did the work. Track status, findings, and delivery in real time.

Executive Summary

A concise readout for leadership and auditors.

Technical Findings

Each with a severity rating, reproduction steps, and clear remediation.

Attack Storyboard

A step-by-step narrative of exactly how we got in and how far we went.

Included Retest

We verify your fixes and deliver a clean final report, at no extra cost.

Looting the Shop

Our stories are based on real events encountered by Raxis engineers. Some details have been altered or omitted to protect customer identities.

Pentesters usually prefer internal tests because modern perimeters are hard to crack. That’s the result most customers hope for: proof the controls work.

This engagement told a different story. Mapping a large internet-facing network, our team found dozens of hosts with open ports and discovered an obsolete operating system running unpatched software. A reverse shell gave them internal access. From there they escalated privileges, harvested credentials across the network, and pivoted to a domain controller, cracking more than half of the domain’s password hashes.

External access became domain admin. The real winner was the customer, who used the Raxis report to secure emergency budget for upgrades and remediation.

FAQ: External Penetration Testing

How often should we run an external penetration test?

At least annually, and after any significant change to your perimeter. PCI DSS and most frameworks require this. Continuous testing through Raxis Attack covers you between point-in-time tests.

How is this different from a vulnerability scan?

A scan lists potential issues based on version numbers. A Raxis pentest exploits them, eliminates false positives, chains attacks, and shows real business impact.

Will testing take our systems down?

It's very unlikely. Your systems face hostile scans daily. We flag fragile systems during kickoff and test with care.

How long does it take?

Most external tests run one to two weeks including reporting. Scope, primarily the number of live internet-facing hosts, drives the timeline.

What do we need to provide?

Your external IP ranges and domains, a point of contact, and any systems needing special handling. We handle the rest.

What drives the cost?

Scope is the main factor, primarily the number of live internet-facing hosts. Prices start around $3,500 and can range into the six figures for a very large scope. Contact us for a quote sized to your environment.

Does this include web application testing?

Unauthenticated testing of exposed web pages may partially be included. Authenticated, in-depth application testing is a separate web application penetration test.

Should we notify our SOC or MSSP before testing?

That's your call. Some customers stay silent to validate detection and response; others notify in advance. We cover this during kickoff.

Do we test cloud-hosted systems?

Yes. Internet-facing assets in AWS, Azure, Google Cloud, and other providers are tested alongside your traditional infrastructure.

Who performs the testing?

Senior US-based Raxis engineers holding certifications such as OSCP and OSCE. No outsourcing, no junior testers learning on your network.

Request a quote

Tell Us What You Need Tested

We usually respond in one business day.

Please let us know what's on your mind. Include any details about your target environment, timeline, or compliance drivers.