Comprehensive Port Scanning
We perform full TCP port scanning across all 65,535 ports on your external IP addresses - not the truncated scan most tools default to. Our scanning engine uses SYN, connect, and version detection techniques to identify every service listening on your perimeter. We also scan the top 1,000 UDP ports for services like DNS, SNMP, VPN endpoints, and NTP that attackers commonly target. Each discovered service is fingerprinted to identify exact software versions and potential CVE matches.
Firewall Rule Analysis
We test your firewall configuration from the outside - identifying rules that are overly permissive, services that should be blocked but are reachable, and inconsistencies between your intended security policy and actual enforcement. This includes testing for common misconfigurations like allowing inbound traffic on management ports (SSH, RDP, Telnet), permitting source-routed packets, and failing to block known-bad IP ranges. We also check for firewall bypass techniques like protocol tunnelling.
Rule permissiveness testing Policy vs reality gap analysis SSL/TLS Security Assessment
Every encrypted service on your perimeter is tested for TLS version support (checking for deprecated TLS 1.0/1.1), cipher suite strength, certificate validity and chain integrity, HSTS implementation, and known protocol vulnerabilities (BEAST, POODLE, Heartbleed, ROBOT, DROWN). We also check for certificate expiry dates, wildcard certificate exposure, and whether certificate transparency logs reveal hidden subdomains that attackers could target.
Protocol version checking Certificate chain validation Known vulnerability testing Service Enumeration & Vulnerability Mapping
For every discovered service, we identify the exact software name and version, then cross-reference against the National Vulnerability Database (NVD) and Exploit-DB to identify known CVEs with available exploits. This goes beyond simple version matching - we test for default credentials, information disclosure through service banners, and configuration weaknesses specific to each service type. Common findings include outdated web servers, exposed database ports, and VPN endpoints with known authentication bypasses.
Software version identification Default credential testing Banner information analysis DNS Security Assessment
Your DNS configuration controls how the world finds your services. We check for DNS zone transfer vulnerabilities (which can expose your entire internal network topology), DNSSEC implementation status, dangling DNS records pointing to decommissioned services (subdomain takeover risk), and DNS cache poisoning susceptibility. We also enumerate subdomains through certificate transparency logs, search engine results, and brute-force discovery to map your full external footprint.
Dangling record detection Remote Access & VPN Assessment
Remote access services - VPNs, RDP gateways, SSH jump hosts, and web-based remote desktop - are high-value targets. We test these for authentication strength, known CVEs (especially critical VPN vulnerabilities like CVE-2023-4966 in Citrix and CVE-2024-3400 in Palo Alto), multi-factor authentication enforcement, and brute force resistance. For organisations using split-tunnel VPNs, we assess whether the configuration could allow lateral movement from compromised remote devices into the corporate network.
VPN vulnerability testing Split-tunnel risk assessment