Red Team · engagement type

External / perimeter assessment.

What an attacker on the internet sees when they look at your business. Port scan, service fingerprint, TLS posture, exposed admin panels, default credentials, public S3 buckets, GitHub-leaked secrets, employee email exposure check. Authorization required in writing before any tool runs.

What's in scope

What's NOT in scope

External-only is exactly that — nothing inside your network. No drop-box, no internal scanning, no AD enumeration, no employee phishing. Those are separate engagement types: Internal / assumed-breach, Social engineering with consent.

Deliverables

Pricing

Standard external assessment: from $1,200. Single domain or /27 IP range. 1 week elapsed time. Report + debrief.
External + internal combined (most-popular package): from $2,800. See the main pentest page for the full combo.
Verified nonprofit code TCG26FREE: External-only assessment available at no cost. Scope is reasonable; report still yours.