Prove perimeter exposure
Confirm whether public services and remote-access paths provide a practical route into the organisation.
Damocles External Network Penetration Testing assesses public attack surface, exposed services, remote access and perimeter controls to validate whether an attacker can gain unauthorised access or create a path into the environment.
External testing starts from the attacker position most organisations face every day: no trusted network access and no internal account. The test identifies exposed systems and validates weaknesses that could lead to unauthorised access, administrative control, sensitive information disclosure or an initial foothold.
It is commonly used for annual assurance, pre-production review, major internet-facing changes, acquisition due diligence and environments where the customer is not confident that its public exposure matches the intended perimeter design.
Confirm whether public services and remote-access paths provide a practical route into the organisation.
Separate attackable conditions from low-value scanner observations and informational findings.
Focus remediation on the weaknesses that provide the strongest attacker capability or initial foothold.
The scope can be a defined public IP range, named internet-facing systems, remote-access services or an approved external attack surface.
Approved public IPs, hosts and services exposed to the internet.
VPN, portals, gateways, remote administration and other externally reachable access paths.
Internet-facing network and application services, protocol behaviour, access controls and misconfiguration.
Publicly reachable management interfaces, administrative services and control-plane exposure.
Approved DNS records, exposed hosts, service discovery and externally visible naming that expands attack surface.
Certificate and protocol configuration where it contributes to exploitable or material exposure.
Test exposed hosts, services and remote-access paths to identify exploitable weaknesses that could provide an initial foothold or expose sensitive information.
Hosts, ports and services reachable from outside the organisation.
Configuration, encryption and known weakness exposure.
Authentication, MFA and post-connect security controls.
Exposed administrative and supporting web interfaces.
Details that make targeting or exploitation easier.
Practical routes from exposure to controlled access.
Observable activity that can support defensive improvement.
These are governed procedures from the service assurance profile—not generic marketing categories. The complete matrix below records applicability, access requirements and limitations for every coverage area.
Damocles enumerates approved DNS zones and public ranges, correlates certificate names, hostnames and virtual hosts, and reconciles every discovery with the expected public asset inventory.
Damocles confirms listening ports, protocols, banners, product or version indicators, authentication surfaces and externally reachable management services on each discovered host.
Damocles identifies unauthenticated portal and gateway exposure; with a supplied identity it tests authentication, MFA, session establishment, expected post-connect access and revocation, then reconciles results with supplied gateway configuration.
Damocles identifies internet-reachable administrative interfaces and protocols, tests their authentication surfaces and intended source restrictions, and correlates observations with supplied gateway or firewall policy.
Damocles exercises each approved external login surface for account enumeration, MFA behaviour, legacy paths, error differences and bounded lockout or throttling using dedicated identities where supplied.
Damocles negotiates externally available protocol and TLS versions, cipher suites and certificates, checks downgrade and legacy behaviour, and compares observations with supplied perimeter cryptographic settings.
Showing 6 representative areas. The full governed matrix contains 12 coverage areas.
References are shown according to the role they play in the engagement. Methodologies guide testing, taxonomies classify findings, severity methods support consistent scoring, and control mappings connect scoped evidence to broader assurance work.
Approved methodology, verification and testing guidance used to select and structure relevant procedures within the authorised scope.
Approved risk, weakness and severity references provide a consistent language for confirmed findings without replacing customer-specific business impact.
Tests representative externally reachable services and perimeter paths from an unauthenticated internet position and reconciles observed exposure with supplied boundary policy where available.
Where remote access is included, tests portal or gateway authentication, MFA, session establishment, assigned access and revocation with dedicated identities.
Tests externally available TLS and security-sensitive protocol versions, certificates and legacy behaviour within agreed safety limits.
+ 7 additional governed mappings in the full control matrix.
Jump to full control mapping ↓A prioritised report with validated attack paths, reproducible evidence, remediation guidance and retest results.
What this means: technical evidence may support risk, compliance and audit activity where the mapping is applicable. It does not by itself certify the organisation, establish complete compliance or assess controls outside the authorised scope.
Damocles reconciles internet observations with the authorised asset inventory, then safely validates exposed services from unauthenticated and supplied remote-user viewpoints. Configuration evidence is reviewed separately from live behaviour; denial-of-service, destructive exploitation and uncontrolled credential attacks remain excluded.
Directly assessed means the engagement tests the relevant behaviour. Supporting evidence means the result can contribute to a broader control assessment. Contextual references explain relevance without claiming that the control was tested.
Enumerates and interacts with approved public hosts and services from an ordinary external network without customer credentials.
Signs into an approved VPN or remote-access gateway and examines MFA, session establishment, assigned access and revocation.
Reconciles observed exposure with firewall, gateway, DNS, certificate and asset-ownership evidence.
| Coverage area | What Damocles tests | Perspective and access | Evidence produced | References and limits |
|---|---|---|---|---|
| Public attack-surface discovery | Damocles enumerates approved DNS zones and public ranges, correlates certificate names, hostnames and virtual hosts, and reconciles every discovery with the expected public asset inventory. | Unauthenticated internet attacker Approved public IP ranges, DNS zones, expected public asset inventory and ownership contacts. | A discovered-asset record containing each name, address, certificate relationship and confirmed or unresolved ownership status. | Technical Guide to Information Security Testing and Assessment SP 800-115 Applicability: Performed for customer-owned public ranges and zones expressly listed in scope. Limit: Point-in-time discovery cannot prove ownership or absence outside approved ranges; enumeration stops at third-party and rate-safety boundaries. |
| Exposed hosts and services | Damocles confirms listening ports, protocols, banners, product or version indicators, authentication surfaces and externally reachable management services on each discovered host. | Unauthenticated internet attacker Approved public targets, expected service inventory and, when reconciliation is included, read-only perimeter configuration evidence. | A host-and-service record with address, port, protocol, observed service, response detail and management or authentication exposure. | Technical Guide to Information Security Testing and Assessment SP 800-115 Applicability: Performed for reachable hosts inside approved public ranges. Limit: Service identification may be inconclusive when banners are suppressed; intrusive fingerprinting stops if service stability is affected. |
| Remote-access services | Damocles identifies unauthenticated portal and gateway exposure; with a supplied identity it tests authentication, MFA, session establishment, expected post-connect access and revocation, then reconciles results with supplied gateway configuration. | Unauthenticated internet attacker, Authenticated remote-access user, Perimeter configuration and ownership reviewer Approved gateway URLs or addresses, a dedicated remote-access identity and MFA method, expected post-connect access matrix, revocation contact and optional read-only gateway export. | Portal responses, authentication and MFA results, session establishment evidence, post-connect connectivity checks, revocation result and cited configuration excerpts. | Technical Guide to Information Security Testing and Assessment SP 800-115 Applicability: Authenticated procedures apply only when a dedicated test identity is supplied; configuration reconciliation applies only when evidence is provided. Limit: Credential spraying and lockout testing are excluded unless separately authorised; testing stops on account lockout, instability or unexpected production access. |
| Perimeter management interfaces | Damocles identifies internet-reachable administrative interfaces and protocols, tests their authentication surfaces and intended source restrictions, and correlates observations with supplied gateway or firewall policy. | Perimeter configuration and ownership reviewer Assessment requires approved public targets, dedicated identities where required, perimeter exports and ownership records, selected specifically for perimeter management interfaces. | Evidence records the host, port, protocol, response, configuration or ownership evidence relevant to perimeter management interfaces. | Technical Guide to Information Security Testing and Assessment SP 800-115 Applicability: Applies to Perimeter management interfaces when the described public service or boundary is authorised and present. Limit: The conclusion is limited to the sampled perimeter management interfaces; internet observation is point-in-time; disruptive, destructive and unauthorised assets remain excluded. |
| Authentication behaviour | Damocles exercises each approved external login surface for account enumeration, MFA behaviour, legacy paths, error differences and bounded lockout or throttling using dedicated identities where supplied. | Authenticated remote-access user Assessment requires approved public targets, dedicated identities where required, perimeter exports and ownership records, selected specifically for authentication behaviour. | Evidence records the host, port, protocol, response, configuration or ownership evidence relevant to authentication behaviour. | Technical Guide to Information Security Testing and Assessment SP 800-115 Applicability: Applies to Authentication behaviour when the described public service or boundary is authorised and present. Limit: The conclusion is limited to the sampled authentication behaviour; internet observation is point-in-time; disruptive, destructive and unauthorised assets remain excluded. |
| TLS and protocol security | Damocles negotiates externally available protocol and TLS versions, cipher suites and certificates, checks downgrade and legacy behaviour, and compares observations with supplied perimeter cryptographic settings. | Unauthenticated internet attacker, Perimeter configuration and ownership reviewer Approved public endpoints and, when configuration comparison is included, current TLS or service configuration. | Negotiated protocol and cipher results, certificate chain details, downgrade observations and the corresponding configuration excerpt. | Technical Guide to Information Security Testing and Assessment SP 800-115 Applicability: Performed for encrypted or security-sensitive protocols exposed by approved targets. Limit: Results describe the tested endpoint and time; no traffic interception, certificate replacement or disruptive protocol testing occurs without separate authority. |
| Known exploitable service conditions | Damocles correlates safely observed product, version and configuration indicators with verified exploit prerequisites, then performs controlled confirmation only where the rules of engagement permit it. | Unauthenticated internet attacker Approved targets, observed or supplied versions, relevant configuration evidence, exploit-safety constraints and an escalation contact. | The observed prerequisite, affected service and version evidence, controlled confirmation result and any stopping condition reached. | Technical Guide to Information Security Testing and Assessment SP 800-115 Applicability: Performed where reliable indicators match a known condition and confirmation is explicitly authorised. Limit: No destructive payload, persistence, denial of service or material data access is attempted; confirmation stops on instability or when the minimum proof is obtained. |
| Information disclosure | Damocles inspects banners, response headers, certificates, public metadata, exposed files and error responses for information that materially assists initial access. | Unauthenticated internet attacker Approved public hostnames, addresses and URLs, plus any known public-file exclusions. | The exposed response, file, certificate, banner or metadata item with its target and retrieval path. | Technical Guide to Information Security Testing and Assessment SP 800-115 Applicability: Performed only against content directly reachable from approved public targets. Limit: The review does not access third-party repositories or extract sensitive data beyond the minimum needed to confirm exposure; testing stops when customer or personal data is encountered. |
| Configuration exposure | Damocles examines externally observable default pages, management and diagnostic paths, exposed configuration files, service disclosures and relevant supplied perimeter settings. | Perimeter configuration and ownership reviewer Approved public targets and, where available, the expected service baseline and relevant perimeter configuration excerpts. | The exposed page, path, file, response or configuration excerpt is retained with its public host and service context. | Technical Guide to Information Security Testing and Assessment SP 800-115 Applicability: Applies to externally reachable services and management surfaces named in the authorised target inventory. Limit: Only information exposed to the tested internet position or present in supplied configuration is assessed; no unauthorised file retrieval is attempted. |
| Chained initial-access paths | Damocles connects separately confirmed exposure, disclosure, authentication and exploit-prerequisite observations into a realistic initial-access path and validates only the least invasive step needed to substantiate the chain. | Authenticated remote-access user The approved public targets, dedicated accounts where needed, evidence from preceding procedures and explicit authority for the minimum confirmation step. | An ordered path records each host, service, prerequisite, observation and controlled validation step leading toward initial access. | Technical Guide to Information Security Testing and Assessment SP 800-115 Applicability: Applies when two or more confirmed in-scope observations create a credible initial-access sequence. Limit: The chain stops at the agreed proof point; Damocles does not establish persistence, pivot internally or assume unvalidated prerequisites. |
| Third-party ownership boundaries | Damocles reconciles discovered names, addresses and services with ownership records and stops active interaction when written authority cannot be established. | Perimeter configuration and ownership reviewer Assessment requires approved public targets, dedicated identities where required, perimeter exports and ownership records, selected specifically for third-party ownership boundaries. | Evidence records the host, port, protocol, response, configuration or ownership evidence relevant to third-party ownership boundaries. | Technical Guide to Information Security Testing and Assessment SP 800-115 Applicability: Applies to Third-party ownership boundaries when the described public service or boundary is authorised and present. Limit: The conclusion is limited to the sampled third-party ownership boundaries; internet observation is point-in-time; disruptive, destructive and unauthorised assets remain excluded. |
| Disruptive and credential-attack exclusions | Damocles records and applies scan-rate, credential-attempt, exploitation, destructive-action and denial-of-service boundaries before testing begins and whenever a stopping condition is reached. | Unauthenticated internet attacker Assessment requires approved public targets, dedicated identities where required, perimeter exports and ownership records, selected specifically for disruptive and credential-attack exclusions. | Evidence records the host, port, protocol, response, configuration or ownership evidence relevant to disruptive and credential-attack exclusions. | Technical Guide to Information Security Testing and Assessment SP 800-115 Applicability: Applies to Disruptive and credential-attack exclusions when the described public service or boundary is authorised and present. Limit: The conclusion is limited to the sampled disruptive and credential-attack exclusions; internet observation is point-in-time; disruptive, destructive and unauthorised assets remain excluded. |
| Framework and controls | Mapping type | What Damocles assesses | Evidence produced | Applicability and limits |
|---|---|---|---|---|
| Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 SC-7 | Directly assessed | Tests representative externally reachable services and perimeter paths from an unauthenticated internet position and reconciles observed exposure with supplied boundary policy where available. | Public attack-surface inventory, host-and-service evidence, reachable management surfaces and validated path results. | Applies: Applies to authorised public ranges, hostnames, services and perimeter evidence included in scope. Limit: Tests only the sampled external position and approved targets; it does not establish all boundary architecture, alternate paths or continuous enforcement. |
| Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 AC-17 | Directly assessed | Where remote access is included, tests portal or gateway authentication, MFA, session establishment, assigned access and revocation with dedicated identities. | Authentication and MFA outcomes, session evidence, post-connect connectivity, revocation results and supplied gateway evidence. | Applies: Applies only when remote-access services, dedicated identities and expected post-connect access are included. Limit: Does not establish every remote-access method, identity, device posture, administration process or continuous control operation. |
| Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 SC-8 | Directly assessed | Tests externally available TLS and security-sensitive protocol versions, certificates and legacy behaviour within agreed safety limits. | Negotiated protocol observations, certificate chain details, affected endpoint records and configuration comparison where supplied. | Applies: Applies to encrypted or security-sensitive protocols exposed by authorised public targets. Limit: Point-in-time endpoint testing does not establish every internal transport path or the organisation's complete cryptographic key-management process. |
| Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 CA-8 | Supporting evidence | Performs an authorised external penetration test and records exposure, controlled exploit confirmation, initial-access paths and stopping conditions. | Rules of engagement, attack-surface register, host/service evidence, validated initial-access paths, findings and retest records where included. | Applies: Relevant where the customer uses external penetration testing within a broader assessment program. Limit: Does not establish testing frequency, enterprise coverage, assessor governance or completeness of the broader program. |
| Information Security Manual June 2026 ISM-2118 | Supporting evidence | Provides scoped external penetration-test evidence that can support an organisation's security-assurance testing program. | Authorised scope, public exposure evidence, validated findings, remediation guidance and retest results where included. | Applies: Relevant where the organisation uses the engagement within its vulnerability-assessment and penetration-testing program. Limit: A single engagement does not establish required testing cadence, full asset coverage or compliance with ISM-2118. |
| Prudential Standard CPS 234 Information Security effective 1 July 2019 CPS 234 paragraph 27 | Supporting evidence | Produces scoped external network penetration-testing evidence that may support an APRA-regulated entity's systematic testing of information-security control effectiveness. | Governed scope, public attack-surface and host/service evidence, findings, remediation guidance and retest results where included. | Applies: Relevant only where the customer determines that the assessed internet-facing systems and evidence are applicable to its assurance or compliance scope. For APRA-regulated entities, the customer determines how the engagement contributes to its broader systematic control-testing program. Limit: A scoped engagement does not by itself establish the customer's systematic testing program, testing frequency, full control population, specialist independence, governance, reporting or compliance with other CPS 234 requirements. |
| Prudential Practice Guide CPG 234 Information Security published June 2019 Framework-level context | Contextual | Produces scoped external network penetration-testing evidence consistent with CPG 234 guidance that testing techniques should be selected for the control and risk being assessed. | Governed scope, public attack-surface and host/service evidence, findings, remediation guidance and retest results where included. | Applies: Relevant only where the customer determines that the assessed internet-facing systems and evidence are applicable to its assurance or compliance scope. APRA-regulated customers determine how this evidence contributes to their broader assurance program. Limit: CPG 234 is prudential guidance rather than a standalone certification target; this mapping does not claim assessment of the complete guidance or customer compliance. |
| ISO/IEC 27001 2022 with Amendment 1:2024 Framework-level context | Contextual | Produces scoped external network penetration-testing evidence that may support customer assurance activities organised around ISO/IEC 27001 where the assessed systems and behaviours are relevant. | Governed scope, public attack-surface and host/service evidence, findings, remediation guidance and retest results where included. | Applies: Relevant only where the customer determines that the assessed internet-facing systems and evidence are applicable to its assurance or compliance scope. Limit: Licensed ISO/IEC 27001 control or requirement identifiers and text are intentionally withheld. The engagement does not establish ISO/IEC 27001 certification, attestation or whole-framework conformity. |
| ISO/IEC 27002 2022 Framework-level context | Contextual | Produces scoped external network penetration-testing evidence that may support customer assurance activities organised around ISO/IEC 27002 where the assessed systems and behaviours are relevant. | Governed scope, public attack-surface and host/service evidence, findings, remediation guidance and retest results where included. | Applies: Relevant only where the customer determines that the assessed internet-facing systems and evidence are applicable to its assurance or compliance scope. Limit: Licensed ISO/IEC 27002 control or requirement identifiers and text are intentionally withheld. The engagement does not establish ISO/IEC 27002 certification, attestation or whole-framework conformity. |
| Payment Card Industry Data Security Standard 4.0.1 Framework-level context | Contextual | Produces scoped external network penetration-testing evidence that may support customer assurance activities organised around PCI DSS where the assessed systems and behaviours are relevant. | Governed scope, public attack-surface and host/service evidence, findings, remediation guidance and retest results where included. | Applies: Relevant only where the customer determines that the assessed internet-facing systems and evidence are applicable to its assurance or compliance scope. Limit: Licensed PCI DSS control or requirement identifiers and text are intentionally withheld. The engagement does not establish PCI DSS certification, attestation or whole-framework conformity. |
Assurance boundary: Damocles maps assessed coverage and findings to agreed security frameworks and control objectives. This provides traceable technical evidence that may support risk, assurance and audit activities. A penetration test does not by itself certify an organisation, establish complete compliance with a framework or confirm the effectiveness of controls outside the authorised scope.
Records authorised scope and rules of engagement produced from the authorised External network penetration testing work.
Records coverage matrix produced from the authorised External network penetration testing work.
Records retest and residual-risk record produced from the authorised External network penetration testing work.
Records public attack-surface register produced from the authorised External network penetration testing work.
Records host and service evidence produced from the authorised External network penetration testing work.
Records initial-access path record produced from the authorised External network penetration testing work.
A prioritised report with validated attack paths, reproducible evidence, remediation guidance and retest results.
The exact techniques depend on the authorised target set and service behaviour.
Weak, bypassable or exposed authentication on public services and administrative interfaces.
Known or misconfigured service behaviour that can provide code execution, file access or unauthorised control.
Default access, unsafe interfaces, unintended files, administrative functions or trust assumptions visible externally.
Paths through remote access, gateways or externally accessible infrastructure that could create an internal foothold.
Exposed information that materially assists credential attacks, target selection or follow-on exploitation.
Multiple smaller weaknesses combined to produce a meaningful initial-access or privilege outcome.
The proposal records the approved ranges, systems, source addresses, testing window, exclusions and evidence requirements.
Assess a defined set of public systems such as remote access, customer portals or perimeter infrastructure.
Assess an approved range of internet-facing infrastructure and exposed services.
Test after firewall, remote-access, hosting or major service changes.
Repeat testing on an agreed cadence with trend and remediation context retained across engagements.
Evidence is written for the infrastructure and security teams responsible for the perimeter.
Material internet-facing attack paths and the likely consequence of successful exploitation.
Approved targets, discovered exposed services and the tested conditions relevant to the assessment.
Reproducible evidence, affected target, attack condition, impact and remediation guidance.
Where weaknesses combine, a clear explanation of how an external foothold could be obtained.
Fix order based on exploitability, exposure, business impact and dependency.
Verification of agreed fixes where retesting is included.
Damocles can reproduce agreed external findings after remediation and record whether the original attack path is resolved, reduced or still exploitable.
Material changes to public scope, new services or major architecture are treated as new testing scope rather than silently folded into a limited retest.
The commercial scope comes first. Delivery is then controlled through written authority, agreed safety boundaries and a clear retest path.
Confirm targets, ownership, attacker perspective, accounts, exclusions, timing, contacts and prohibited activity.
Perform the authorised manual and technical testing required to prove or disprove the attack paths in scope.
Provide evidence, impact, affected scope, remediation priorities and a technical walkthrough with the people responsible for the fix.
Reproduce agreed findings after remediation and record whether they are resolved, reduced or still exploitable.
We will define the minimum useful external scope, testing window, safety controls, deliverables and retest allowance.