External Network Penetration Testing
Test public IPs, exposed services, remote access, perimeter devices and internet-facing management paths from the perspective of an unauthenticated external attacker.
View External Testing →Damocles sells penetration testing as defined technical services—not one generic assessment. Choose the environment an attacker would target, the access they are assumed to have and the business question the test must answer.
Each service has its own scope, attack paths, evidence and engagement options. Multiple test types can be combined where the customer needs an end-to-end compromise assessment.
Test public IPs, exposed services, remote access, perimeter devices and internet-facing management paths from the perspective of an unauthenticated external attacker.
View External Testing →Model a compromised workstation, user or internal foothold and test lateral movement, privilege, segmentation and access to sensitive systems.
View Internal Testing →Test authentication, authorisation, session handling, business logic, file handling, input paths and sensitive-data exposure in web applications.
View Web Application Testing →Test object-level authorisation, authentication, role enforcement, workflow abuse, rate controls, data exposure and unsafe API behaviours.
View API Testing →Assess corporate, guest and operational wireless security, authentication, encryption, client isolation, segmentation and post-connect access.
View Wireless Testing →Test credential exposure, privilege escalation, delegation, trust abuse, administrative paths and identity controls that can lead to domain or sensitive-system compromise.
View Identity Testing →Assess mobile application authentication, local storage, transport security, API interaction, platform permissions, deep links and application-specific abuse paths.
View Mobile Testing →External testing answers whether internet-facing systems can be compromised from outside. Internal testing answers what happens after a workstation, account or internal position is compromised. Web and API testing focus on application security and business logic. Wireless and identity testing examine trust paths that are easy to miss in a generic infrastructure test.
Where the customer needs a broader compromise scenario, Damocles can combine selected service types into one authorised attack-path assessment. The statement of work still identifies each environment, target set, account type and testing boundary so coverage remains measurable.
Choose External Network Penetration Testing for public services, remote access and perimeter attack paths.
Choose Web Application or API Penetration Testing when users, roles, objects, workflows and application logic are the primary attack surface.
Choose Internal Network or Active Directory & Identity Testing to assess lateral movement, privilege escalation and access to sensitive systems.
Assess the internet perimeter and then model what an attacker could do after obtaining an internal foothold or credential.
Test the user-facing application and its supporting APIs together so authentication, authorisation and business workflows are assessed end to end.
Combine network access, host paths, identity abuse, delegation, privilege escalation and administrative control paths.
Assess whether wireless access creates an unintended internal foothold and what can be reached after connection.
Test the mobile client and supporting APIs together, including token handling, local storage, platform controls and server-side authorisation.
Reproduce agreed findings after remediation and record resolved, reduced and still-exploitable conditions.
Material attack paths, likely consequence, affected business capability and the decisions requiring leadership attention.
Reproducible evidence, affected targets, attack conditions, impact and practical remediation guidance.
Where issues can be chained, a step-by-step explanation of how access, privilege and trust combine.
Fix order based on exploitability, exposure, impact, dependency and available compensating controls.
Walkthrough with security, infrastructure, application or identity teams responsible for remediation.
Evidence showing whether agreed findings were resolved, reduced, accepted or remain exploitable.
Where retesting is included, Damocles reproduces agreed findings against the remediated environment and records whether the original attack condition is resolved, reduced or still present. A changed screenshot or ticket status is not treated as proof when the issue can be tested directly.
The proposal identifies the retest window, eligible findings and any limits on changed scope. Material new functionality, architecture or targets can be assessed separately where they fall outside the original engagement.
We will recommend the specific penetration testing service or combined scope required—rather than selling a generic test that leaves important attack surfaces ambiguous.