External network penetration testing

Find out what an unauthenticated internet attacker can actually reach.

Damocles External Network Penetration Testing assesses public attack surface, exposed services, remote access and perimeter controls to validate whether an attacker can gain unauthorised access or create a path into the environment.

Public IPs and exposed servicesRemote access and perimeter controlsManual exploit validationRetesting available
Why customers buy this test

Understand the real internet-facing attack surface.

External testing starts from the attacker position most organisations face every day: no trusted network access and no internal account. The test identifies exposed systems and validates weaknesses that could lead to unauthorised access, administrative control, sensitive information disclosure or an initial foothold.

It is commonly used for annual assurance, pre-production review, major internet-facing changes, acquisition due diligence and environments where the customer is not confident that its public exposure matches the intended perimeter design.

01

Prove perimeter exposure

Confirm whether public services and remote-access paths provide a practical route into the organisation.

02

Validate exploitable weaknesses

Separate attackable conditions from low-value scanner observations and informational findings.

03

Prioritise the fixes that matter

Focus remediation on the weaknesses that provide the strongest attacker capability or initial foothold.

What we test

Internet-facing systems, services and access paths in the agreed target range.

The scope can be a defined public IP range, named internet-facing systems, remote-access services or an approved external attack surface.

IP

Public IP addresses

Approved public IPs, hosts and services exposed to the internet.

RA

Remote access

VPN, portals, gateways, remote administration and other externally reachable access paths.

SV

Exposed services

Internet-facing network and application services, protocol behaviour, access controls and misconfiguration.

PM

Perimeter management

Publicly reachable management interfaces, administrative services and control-plane exposure.

DN

DNS and naming

Approved DNS records, exposed hosts, service discovery and externally visible naming that expands attack surface.

TL

TLS and service security

Certificate and protocol configuration where it contributes to exploitable or material exposure.

Technical assurance

Understand what an internet attacker can reach.

Test exposed hosts, services and remote-access paths to identify exploitable weaknesses that could provide an initial foothold or expose sensitive information.

Internet attack surface

Hosts, ports and services reachable from outside the organisation.

Service security

Configuration, encryption and known weakness exposure.

Remote access

Authentication, MFA and post-connect security controls.

Public applications

Exposed administrative and supporting web interfaces.

Information exposure

Details that make targeting or exploitation easier.

Exploit paths

Practical routes from exposure to controlled access.

Detection opportunities

Observable activity that can support defensive improvement.

12governed test areas
3authorised testing perspectives
6controlled evidence outputs
10framework / control evidence mappings
What we actually test

Representative technical coverage with the evidence produced.

These are governed procedures from the service assurance profile—not generic marketing categories. The complete matrix below records applicability, access requirements and limitations for every coverage area.

Jump to full coverage matrix ↓
Coverage area

Public attack-surface discovery

Damocles enumerates approved DNS zones and public ranges, correlates certificate names, hostnames and virtual hosts, and reconciles every discovery with the expected public asset inventory.

Evidence producedA discovered-asset record containing each name, address, certificate relationship and confirmed or unresolved ownership status.
Framework references
Technical Guide to Information Security Testing and Assessment SP 800-115
Coverage area

Exposed hosts and services

Damocles confirms listening ports, protocols, banners, product or version indicators, authentication surfaces and externally reachable management services on each discovered host.

Evidence producedA host-and-service record with address, port, protocol, observed service, response detail and management or authentication exposure.
Framework references
Technical Guide to Information Security Testing and Assessment SP 800-115
Coverage area

Remote-access services

Damocles identifies unauthenticated portal and gateway exposure; with a supplied identity it tests authentication, MFA, session establishment, expected post-connect access and revocation, then reconciles results with supplied gateway configuration.

Evidence producedPortal responses, authentication and MFA results, session establishment evidence, post-connect connectivity checks, revocation result and cited configuration excerpts.
Framework references
Technical Guide to Information Security Testing and Assessment SP 800-115
Coverage area

Perimeter management interfaces

Damocles identifies internet-reachable administrative interfaces and protocols, tests their authentication surfaces and intended source restrictions, and correlates observations with supplied gateway or firewall policy.

Evidence producedEvidence records the host, port, protocol, response, configuration or ownership evidence relevant to perimeter management interfaces.
Framework references
Technical Guide to Information Security Testing and Assessment SP 800-115
Coverage area

Authentication behaviour

Damocles exercises each approved external login surface for account enumeration, MFA behaviour, legacy paths, error differences and bounded lockout or throttling using dedicated identities where supplied.

Evidence producedEvidence records the host, port, protocol, response, configuration or ownership evidence relevant to authentication behaviour.
Framework references
Technical Guide to Information Security Testing and Assessment SP 800-115
Coverage area

TLS and protocol security

Damocles negotiates externally available protocol and TLS versions, cipher suites and certificates, checks downgrade and legacy behaviour, and compares observations with supplied perimeter cryptographic settings.

Evidence producedNegotiated protocol and cipher results, certificate chain details, downgrade observations and the corresponding configuration excerpt.
Framework references
Technical Guide to Information Security Testing and Assessment SP 800-115

Showing 6 representative areas. The full governed matrix contains 12 coverage areas.

Standards and assurance coverage

See how this engagement is structured, classified and mapped before opening the full evidence matrix.

References are shown according to the role they play in the engagement. Methodologies guide testing, taxonomies classify findings, severity methods support consistent scoring, and control mappings connect scoped evidence to broader assurance work.

01 · Test method

How testing is structured

Approved methodology, verification and testing guidance used to select and structure relevant procedures within the authorised scope.

Technical Guide to Information Security Testing and Assessment SP 800-115
02 · Finding language

How weaknesses and severity are classified

Approved risk, weakness and severity references provide a consistent language for confirmed findings without replacing customer-specific business impact.

Common Weakness Enumeration 4.20Common Vulnerability Scoring System 4.0
03 · Control evidence

What maps into compliance and assurance work

10governed evidence mappings across 7 approved frameworks and 6 referenced controls.
3 directly assessed3 supporting evidence4 contextual
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0Directly assessed
SC-7

Tests representative externally reachable services and perimeter paths from an unauthenticated internet position and reconciles observed exposure with supplied boundary policy where available.

Security and Privacy Controls for Information Systems and Organizations Release 5.2.0Directly assessed
AC-17

Where remote access is included, tests portal or gateway authentication, MFA, session establishment, assigned access and revocation with dedicated identities.

Security and Privacy Controls for Information Systems and Organizations Release 5.2.0Directly assessed
SC-8

Tests externally available TLS and security-sensitive protocol versions, certificates and legacy behaviour within agreed safety limits.

+ 7 additional governed mappings in the full control matrix.

Jump to full control mapping ↓
04 · Evidence package

What the customer can use after the engagement

A prioritised report with validated attack paths, reproducible evidence, remediation guidance and retest results.

  • Authorised scope and rules of engagement
  • Coverage matrix
  • Retest and residual-risk record
  • + 3 additional controlled outputs

What this means: technical evidence may support risk, compliance and audit activity where the mapping is applicable. It does not by itself certify the organisation, establish complete compliance or assess controls outside the authorised scope.

How we test

Manual validation backed by controlled evidence.

Damocles reconciles internet observations with the authorised asset inventory, then safely validates exposed services from unauthenticated and supplied remote-user viewpoints. Configuration evidence is reviewed separately from live behaviour; denial-of-service, destructive exploitation and uncontrolled credential attacks remain excluded.

How to read the mapping

Evidence is mapped to the part of a control we can actually assess.

Directly assessed means the engagement tests the relevant behaviour. Supporting evidence means the result can contribute to a broader control assessment. Contextual references explain relevance without claiming that the control was tested.

All relevant frameworks
Technical Guide to Information Security Testing and Assessment SP 800-115Common Weakness Enumeration 4.20Common Vulnerability Scoring System 4.0Security and Privacy Controls for Information Systems and Organizations Release 5.2.0Information Security Manual June 2026Prudential Standard CPS 234 Information Security effective 1 July 2019Prudential Practice Guide CPG 234 Information Security published June 2019ISO/IEC 27001 2022 with Amendment 1:2024ISO/IEC 27002 2022Payment Card Industry Data Security Standard 4.0.1
Testing perspectives3 authorised viewpoints and access models

Unauthenticated internet attacker

Enumerates and interacts with approved public hosts and services from an ordinary external network without customer credentials.

Included when
Used for public discovery, pre-authentication behaviour and internet-exposure validation.
Access required
Approved public ranges, hostnames, DNS zones, ownership boundaries and testing windows.
Limitations
Cannot establish authenticated, internal or source-restricted behaviour.

Authenticated remote-access user

Signs into an approved VPN or remote-access gateway and examines MFA, session establishment, assigned access and revocation.

Included when
Used only where post-authentication remote-access behaviour is included.
Access required
A dedicated account, MFA method, client requirements and expected post-connect access.
Limitations
Conclusions apply only to the supplied identity, device posture and gateway path.

Perimeter configuration and ownership reviewer

Reconciles observed exposure with firewall, gateway, DNS, certificate and asset-ownership evidence.

Included when
Used when configuration or ownership records are supplied to explain external observations.
Access required
Current exports, asset owners, expected services, source restrictions and third-party authority records.
Limitations
Configuration review is point-in-time and does not prove live enforcement unless separately validated.
Exact test coverage and evidence12 governed coverage areas
What Damocles tests, the evidence produced and the scope boundary for each controlled coverage area.
Coverage areaWhat Damocles testsPerspective and accessEvidence producedReferences and limits
Public attack-surface discoveryDamocles enumerates approved DNS zones and public ranges, correlates certificate names, hostnames and virtual hosts, and reconciles every discovery with the expected public asset inventory.Unauthenticated internet attacker
Approved public IP ranges, DNS zones, expected public asset inventory and ownership contacts.
A discovered-asset record containing each name, address, certificate relationship and confirmed or unresolved ownership status.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Performed for customer-owned public ranges and zones expressly listed in scope.

Limit: Point-in-time discovery cannot prove ownership or absence outside approved ranges; enumeration stops at third-party and rate-safety boundaries.

Exposed hosts and servicesDamocles confirms listening ports, protocols, banners, product or version indicators, authentication surfaces and externally reachable management services on each discovered host.Unauthenticated internet attacker
Approved public targets, expected service inventory and, when reconciliation is included, read-only perimeter configuration evidence.
A host-and-service record with address, port, protocol, observed service, response detail and management or authentication exposure.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Performed for reachable hosts inside approved public ranges.

Limit: Service identification may be inconclusive when banners are suppressed; intrusive fingerprinting stops if service stability is affected.

Remote-access servicesDamocles identifies unauthenticated portal and gateway exposure; with a supplied identity it tests authentication, MFA, session establishment, expected post-connect access and revocation, then reconciles results with supplied gateway configuration.Unauthenticated internet attacker, Authenticated remote-access user, Perimeter configuration and ownership reviewer
Approved gateway URLs or addresses, a dedicated remote-access identity and MFA method, expected post-connect access matrix, revocation contact and optional read-only gateway export.
Portal responses, authentication and MFA results, session establishment evidence, post-connect connectivity checks, revocation result and cited configuration excerpts.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Authenticated procedures apply only when a dedicated test identity is supplied; configuration reconciliation applies only when evidence is provided.

Limit: Credential spraying and lockout testing are excluded unless separately authorised; testing stops on account lockout, instability or unexpected production access.

Perimeter management interfacesDamocles identifies internet-reachable administrative interfaces and protocols, tests their authentication surfaces and intended source restrictions, and correlates observations with supplied gateway or firewall policy.Perimeter configuration and ownership reviewer
Assessment requires approved public targets, dedicated identities where required, perimeter exports and ownership records, selected specifically for perimeter management interfaces.
Evidence records the host, port, protocol, response, configuration or ownership evidence relevant to perimeter management interfaces.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Applies to Perimeter management interfaces when the described public service or boundary is authorised and present.

Limit: The conclusion is limited to the sampled perimeter management interfaces; internet observation is point-in-time; disruptive, destructive and unauthorised assets remain excluded.

Authentication behaviourDamocles exercises each approved external login surface for account enumeration, MFA behaviour, legacy paths, error differences and bounded lockout or throttling using dedicated identities where supplied.Authenticated remote-access user
Assessment requires approved public targets, dedicated identities where required, perimeter exports and ownership records, selected specifically for authentication behaviour.
Evidence records the host, port, protocol, response, configuration or ownership evidence relevant to authentication behaviour.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Applies to Authentication behaviour when the described public service or boundary is authorised and present.

Limit: The conclusion is limited to the sampled authentication behaviour; internet observation is point-in-time; disruptive, destructive and unauthorised assets remain excluded.

TLS and protocol securityDamocles negotiates externally available protocol and TLS versions, cipher suites and certificates, checks downgrade and legacy behaviour, and compares observations with supplied perimeter cryptographic settings.Unauthenticated internet attacker, Perimeter configuration and ownership reviewer
Approved public endpoints and, when configuration comparison is included, current TLS or service configuration.
Negotiated protocol and cipher results, certificate chain details, downgrade observations and the corresponding configuration excerpt.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Performed for encrypted or security-sensitive protocols exposed by approved targets.

Limit: Results describe the tested endpoint and time; no traffic interception, certificate replacement or disruptive protocol testing occurs without separate authority.

Known exploitable service conditionsDamocles correlates safely observed product, version and configuration indicators with verified exploit prerequisites, then performs controlled confirmation only where the rules of engagement permit it.Unauthenticated internet attacker
Approved targets, observed or supplied versions, relevant configuration evidence, exploit-safety constraints and an escalation contact.
The observed prerequisite, affected service and version evidence, controlled confirmation result and any stopping condition reached.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Performed where reliable indicators match a known condition and confirmation is explicitly authorised.

Limit: No destructive payload, persistence, denial of service or material data access is attempted; confirmation stops on instability or when the minimum proof is obtained.

Information disclosureDamocles inspects banners, response headers, certificates, public metadata, exposed files and error responses for information that materially assists initial access.Unauthenticated internet attacker
Approved public hostnames, addresses and URLs, plus any known public-file exclusions.
The exposed response, file, certificate, banner or metadata item with its target and retrieval path.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Performed only against content directly reachable from approved public targets.

Limit: The review does not access third-party repositories or extract sensitive data beyond the minimum needed to confirm exposure; testing stops when customer or personal data is encountered.

Configuration exposureDamocles examines externally observable default pages, management and diagnostic paths, exposed configuration files, service disclosures and relevant supplied perimeter settings.Perimeter configuration and ownership reviewer
Approved public targets and, where available, the expected service baseline and relevant perimeter configuration excerpts.
The exposed page, path, file, response or configuration excerpt is retained with its public host and service context.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Applies to externally reachable services and management surfaces named in the authorised target inventory.

Limit: Only information exposed to the tested internet position or present in supplied configuration is assessed; no unauthorised file retrieval is attempted.

Chained initial-access pathsDamocles connects separately confirmed exposure, disclosure, authentication and exploit-prerequisite observations into a realistic initial-access path and validates only the least invasive step needed to substantiate the chain.Authenticated remote-access user
The approved public targets, dedicated accounts where needed, evidence from preceding procedures and explicit authority for the minimum confirmation step.
An ordered path records each host, service, prerequisite, observation and controlled validation step leading toward initial access.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Applies when two or more confirmed in-scope observations create a credible initial-access sequence.

Limit: The chain stops at the agreed proof point; Damocles does not establish persistence, pivot internally or assume unvalidated prerequisites.

Third-party ownership boundariesDamocles reconciles discovered names, addresses and services with ownership records and stops active interaction when written authority cannot be established.Perimeter configuration and ownership reviewer
Assessment requires approved public targets, dedicated identities where required, perimeter exports and ownership records, selected specifically for third-party ownership boundaries.
Evidence records the host, port, protocol, response, configuration or ownership evidence relevant to third-party ownership boundaries.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Applies to Third-party ownership boundaries when the described public service or boundary is authorised and present.

Limit: The conclusion is limited to the sampled third-party ownership boundaries; internet observation is point-in-time; disruptive, destructive and unauthorised assets remain excluded.

Disruptive and credential-attack exclusionsDamocles records and applies scan-rate, credential-attempt, exploitation, destructive-action and denial-of-service boundaries before testing begins and whenever a stopping condition is reached.Unauthenticated internet attacker
Assessment requires approved public targets, dedicated identities where required, perimeter exports and ownership records, selected specifically for disruptive and credential-attack exclusions.
Evidence records the host, port, protocol, response, configuration or ownership evidence relevant to disruptive and credential-attack exclusions.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Applies to Disruptive and credential-attack exclusions when the described public service or boundary is authorised and present.

Limit: The conclusion is limited to the sampled disruptive and credential-attack exclusions; internet observation is point-in-time; disruptive, destructive and unauthorised assets remain excluded.

Framework and control mappings10 governed evidence mappings
Where scoped technical evidence maps to approved security frameworks and control objectives.
Framework and controlsMapping typeWhat Damocles assessesEvidence producedApplicability and limits
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
SC-7
Directly assessedTests representative externally reachable services and perimeter paths from an unauthenticated internet position and reconciles observed exposure with supplied boundary policy where available.Public attack-surface inventory, host-and-service evidence, reachable management surfaces and validated path results.

Applies: Applies to authorised public ranges, hostnames, services and perimeter evidence included in scope.

Limit: Tests only the sampled external position and approved targets; it does not establish all boundary architecture, alternate paths or continuous enforcement.

Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
AC-17
Directly assessedWhere remote access is included, tests portal or gateway authentication, MFA, session establishment, assigned access and revocation with dedicated identities.Authentication and MFA outcomes, session evidence, post-connect connectivity, revocation results and supplied gateway evidence.

Applies: Applies only when remote-access services, dedicated identities and expected post-connect access are included.

Limit: Does not establish every remote-access method, identity, device posture, administration process or continuous control operation.

Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
SC-8
Directly assessedTests externally available TLS and security-sensitive protocol versions, certificates and legacy behaviour within agreed safety limits.Negotiated protocol observations, certificate chain details, affected endpoint records and configuration comparison where supplied.

Applies: Applies to encrypted or security-sensitive protocols exposed by authorised public targets.

Limit: Point-in-time endpoint testing does not establish every internal transport path or the organisation's complete cryptographic key-management process.

Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
CA-8
Supporting evidencePerforms an authorised external penetration test and records exposure, controlled exploit confirmation, initial-access paths and stopping conditions.Rules of engagement, attack-surface register, host/service evidence, validated initial-access paths, findings and retest records where included.

Applies: Relevant where the customer uses external penetration testing within a broader assessment program.

Limit: Does not establish testing frequency, enterprise coverage, assessor governance or completeness of the broader program.

Information Security Manual June 2026
ISM-2118
Supporting evidenceProvides scoped external penetration-test evidence that can support an organisation's security-assurance testing program.Authorised scope, public exposure evidence, validated findings, remediation guidance and retest results where included.

Applies: Relevant where the organisation uses the engagement within its vulnerability-assessment and penetration-testing program.

Limit: A single engagement does not establish required testing cadence, full asset coverage or compliance with ISM-2118.

Prudential Standard CPS 234 Information Security effective 1 July 2019
CPS 234 paragraph 27
Supporting evidenceProduces scoped external network penetration-testing evidence that may support an APRA-regulated entity's systematic testing of information-security control effectiveness.Governed scope, public attack-surface and host/service evidence, findings, remediation guidance and retest results where included.

Applies: Relevant only where the customer determines that the assessed internet-facing systems and evidence are applicable to its assurance or compliance scope. For APRA-regulated entities, the customer determines how the engagement contributes to its broader systematic control-testing program.

Limit: A scoped engagement does not by itself establish the customer's systematic testing program, testing frequency, full control population, specialist independence, governance, reporting or compliance with other CPS 234 requirements.

Prudential Practice Guide CPG 234 Information Security published June 2019
Framework-level context
ContextualProduces scoped external network penetration-testing evidence consistent with CPG 234 guidance that testing techniques should be selected for the control and risk being assessed.Governed scope, public attack-surface and host/service evidence, findings, remediation guidance and retest results where included.

Applies: Relevant only where the customer determines that the assessed internet-facing systems and evidence are applicable to its assurance or compliance scope. APRA-regulated customers determine how this evidence contributes to their broader assurance program.

Limit: CPG 234 is prudential guidance rather than a standalone certification target; this mapping does not claim assessment of the complete guidance or customer compliance.

ISO/IEC 27001 2022 with Amendment 1:2024
Framework-level context
ContextualProduces scoped external network penetration-testing evidence that may support customer assurance activities organised around ISO/IEC 27001 where the assessed systems and behaviours are relevant.Governed scope, public attack-surface and host/service evidence, findings, remediation guidance and retest results where included.

Applies: Relevant only where the customer determines that the assessed internet-facing systems and evidence are applicable to its assurance or compliance scope.

Limit: Licensed ISO/IEC 27001 control or requirement identifiers and text are intentionally withheld. The engagement does not establish ISO/IEC 27001 certification, attestation or whole-framework conformity.

ISO/IEC 27002 2022
Framework-level context
ContextualProduces scoped external network penetration-testing evidence that may support customer assurance activities organised around ISO/IEC 27002 where the assessed systems and behaviours are relevant.Governed scope, public attack-surface and host/service evidence, findings, remediation guidance and retest results where included.

Applies: Relevant only where the customer determines that the assessed internet-facing systems and evidence are applicable to its assurance or compliance scope.

Limit: Licensed ISO/IEC 27002 control or requirement identifiers and text are intentionally withheld. The engagement does not establish ISO/IEC 27002 certification, attestation or whole-framework conformity.

Payment Card Industry Data Security Standard 4.0.1
Framework-level context
ContextualProduces scoped external network penetration-testing evidence that may support customer assurance activities organised around PCI DSS where the assessed systems and behaviours are relevant.Governed scope, public attack-surface and host/service evidence, findings, remediation guidance and retest results where included.

Applies: Relevant only where the customer determines that the assessed internet-facing systems and evidence are applicable to its assurance or compliance scope.

Limit: Licensed PCI DSS control or requirement identifiers and text are intentionally withheld. The engagement does not establish PCI DSS certification, attestation or whole-framework conformity.

Assurance boundary: Damocles maps assessed coverage and findings to agreed security frameworks and control objectives. This provides traceable technical evidence that may support risk, assurance and audit activities. A penetration test does not by itself certify an organisation, establish complete compliance with a framework or confirm the effectiveness of controls outside the authorised scope.

Report and evidence outputs6 controlled output types

Authorised scope and rules of engagement

Records authorised scope and rules of engagement produced from the authorised External network penetration testing work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Coverage matrix

Records coverage matrix produced from the authorised External network penetration testing work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Retest and residual-risk record

Records retest and residual-risk record produced from the authorised External network penetration testing work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Public attack-surface register

Records public attack-surface register produced from the authorised External network penetration testing work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Host and service evidence

Records host and service evidence produced from the authorised External network penetration testing work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Initial-access path record

Records initial-access path record produced from the authorised External network penetration testing work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.
What you receive

A prioritised report with validated attack paths, reproducible evidence, remediation guidance and retest results.

Attack paths we look for

Initial-access paths that can turn public exposure into compromise.

The exact techniques depend on the authorised target set and service behaviour.

AU

Authentication weakness

Weak, bypassable or exposed authentication on public services and administrative interfaces.

VC

Vulnerable exposed service

Known or misconfigured service behaviour that can provide code execution, file access or unauthorised control.

CF

Configuration exposure

Default access, unsafe interfaces, unintended files, administrative functions or trust assumptions visible externally.

RS

Remote-service abuse

Paths through remote access, gateways or externally accessible infrastructure that could create an internal foothold.

ID

Information disclosure

Exposed information that materially assists credential attacks, target selection or follow-on exploitation.

CH

Chained compromise

Multiple smaller weaknesses combined to produce a meaningful initial-access or privilege outcome.

Engagement options

Scope the test to the internet-facing estate and assurance requirement.

The proposal records the approved ranges, systems, source addresses, testing window, exclusions and evidence requirements.

Focused
FS

Critical-system external test

Assess a defined set of public systems such as remote access, customer portals or perimeter infrastructure.

Perimeter
PR

Public IP range assessment

Assess an approved range of internet-facing infrastructure and exposed services.

Change assurance
PC

Post-change perimeter validation

Test after firewall, remote-access, hosting or major service changes.

Recurring
CR

Recurring external assurance

Repeat testing on an agreed cadence with trend and remediation context retained across engagements.

What you receive

A clear answer on what the internet can reach and which exposures require action first.

Evidence is written for the infrastructure and security teams responsible for the perimeter.

ES

Executive exposure summary

Material internet-facing attack paths and the likely consequence of successful exploitation.

AS

Attack-surface record

Approved targets, discovered exposed services and the tested conditions relevant to the assessment.

TF

Technical findings

Reproducible evidence, affected target, attack condition, impact and remediation guidance.

AP

Attack-path narrative

Where weaknesses combine, a clear explanation of how an external foothold could be obtained.

RP

Prioritised remediation

Fix order based on exploitability, exposure, business impact and dependency.

RR

Retest evidence

Verification of agreed fixes where retesting is included.

Remediation and retesting

Re-test the exposed service after the fix rather than closing the finding from a ticket update.

Damocles can reproduce agreed external findings after remediation and record whether the original attack path is resolved, reduced or still exploitable.

Material changes to public scope, new services or major architecture are treated as new testing scope rather than silently folded into a limited retest.

Testing delivery

A controlled technical engagement without turning the service page into a methodology manual.

The commercial scope comes first. Delivery is then controlled through written authority, agreed safety boundaries and a clear retest path.

01

Scope and authorise

Confirm targets, ownership, attacker perspective, accounts, exclusions, timing, contacts and prohibited activity.

02

Test and validate

Perform the authorised manual and technical testing required to prove or disprove the attack paths in scope.

03

Report and brief

Provide evidence, impact, affected scope, remediation priorities and a technical walkthrough with the people responsible for the fix.

04

Retest

Reproduce agreed findings after remediation and record whether they are resolved, reduced or still exploitable.

Scope boundaries

External testing is limited to the approved public scope and authorised techniques.

Denial-of-service, password spraying, destructive exploitation, data extraction and testing of third-party systems are included only where expressly authorised and controlled.

External testing does not replace internal, identity, web application or API penetration testing when those attack surfaces require dedicated coverage.

Scope the right test

Give us the public ranges, internet-facing systems and remote-access services that need to be tested.

We will define the minimum useful external scope, testing window, safety controls, deliverables and retest allowance.