External penetration testing

Threat emulation schedule with dates, sources, statuses, and a vulnerabilities list with severity and fix status.

An external penetration test attacks everything your organization exposes to the internet: public IP ranges, VPN and mail gateways, DNS, and every web application or API reachable without being on your network. The difficult part is rarely the attacking. It is knowing what is actually exposed this week, because a perimeter changes faster than the inventory that describes it.

For teams whose internet-facing surface grows without asking permission

Organizations where an engineer can publish a subdomain, a storage bucket or a preview environment without a security review in the way.

Security teams who suspect their asset inventory is a year behind reality and would rather measure the gap than argue about it.

Companies carrying acquisitions, retired brands or old campaign domains that still resolve to something live.

User interface with sections titled 'Strikers assigned' showing two profile pictures and their details, and an 'Export' panel with options to include Findings Summary, Assessment Updates, and Compliance Checklist, with a Download button.
[ THE PERIMETER MOVES ]

Finding it, mapping it, and proving you can get through it

Three things get sold against each other for the same budget line, and they are not substitutes. A scanner checks known issues on assets you already listed. Attack surface management finds assets you had not listed and tells you they exist. An external penetration test does the discovery and then tries to get in, which is the only one of the three that produces evidence rather than inventory.

What you are trying to learn
Vulnerability scan
Attack surface management
External penetration test
A new subdomain appears on Tuesday
Invisible unless someone adds it to the target list
Discovered and added to the inventory
Discovered, then actually attacked
Depth on any single asset
Known signatures and versions
Fingerprinting and exposure classification
Exploitation, chaining, and proof it worked
Authorization and business logic
Not covered
Not covered
Covered, because a person is testing it
What you receive
A list of known issues to triage
An inventory with exposure ratings
Proven ways in, with evidence and impact
Answers “are we exposed?”
Partly, and only for what you pointed it at
Yes, in inventory terms
Yes, in attacker terms — which is the version an executive asked for
How it should be run
Continuously, as hygiene
Continuously, as the map
Continuously, as the proof

The three are complements, not alternatives. The mistake worth avoiding is buying only the first two and reporting the result as though someone had tried to break in.

How discovery actually works

Certificate transparency and passive DNS
Every public TLS certificate is logged, and those logs are searchable. Internal-sounding hostnames routinely appear there months before anyone thinks of them as public. Passive DNS history adds the names that used to resolve and sometimes still do.
Subdomain and host enumeration
Brute-forcing and permuting names against the organization's domains, then resolving what answers. This is where staging, uat, old, backup and vpn-test tend to surface — environments built for a week and never taken down.
Cloud and netblock attribution
Working out which addresses and cloud resources actually belong to you, including those inherited through acquisitions or spun up on a team's own account. Ownership ambiguity is the single most common reason an exposed asset survives for years.
Fingerprinting what answers
Identifying the technology, version and role behind each live service. This is where the target list stops being a list of addresses and becomes a set of hypotheses about where a way in is likely to exist.
Leaked credentials and exposed artefacts
Public repositories, published build artefacts, misconfigured storage and credential dumps. A valid password needs no exploit, and remote access without a second factor turns a leak straight into an entry point.

What belongs in an external scope

Public address ranges and everything answering in them
Not only the hosts you meant to publish. Management interfaces, monitoring dashboards and database ports left open to the world are found on external tests far more often than anyone expects.
VPN concentrators and remote access
The most valuable target on any perimeter, because success there requires no exploit and grants network position immediately. Firmware age and whether a second factor is genuinely enforced are the two questions that matter.
Mail and DNS
Sender authentication records, relay behaviour, zone transfer exposure and registrar hygiene. These rarely produce a dramatic finding on their own and they shape how convincing an attack against your people can be.
Public web applications and APIs
Everything reachable without being on the network, including the API that has no front end and was never written down. If the application is central to the business it deserves its own dedicated application test as well.
The environments nobody claims
Forgotten development and staging systems, decommissioned marketing sites, storage left readable, and assets inherited through an acquisition. These are usually unpatched, unmonitored and connected to something that matters.

Frequently asked questions

What is external penetration testing?

Authorized attack simulation against everything your organization exposes to the internet, performed from outside your network with no prior access. It covers discovery of what is exposed, identification of weaknesses on those assets, and exploitation to prove which of them lead somewhere. The output is a set of demonstrated ways in, ranked by what they reach, rather than a catalogue of theoretical issues.

How is external testing different from internal testing?

External testing starts with no access and asks what a stranger can reach and break. Internal testing starts with the assumption that someone is already inside and asks how far they get. They find different classes of problem: external work tends to surface exposure and inventory failures, internal work tends to surface trust, segmentation and directory failures. Programs that run only one are usually surprised by the other.

What should be in an external scope?

Public IP ranges, VPN and remote access, mail and DNS, all internet-reachable web applications and APIs, and cloud-hosted endpoints. The more useful instruction is to let the tester perform discovery first and then agree the scope against what they find, because the assets missing from your list are exactly the ones that have been unmonitored longest.

How often should the perimeter be tested?

More often than most compliance schedules require, because the perimeter changes on the cadence of your deployments rather than on the cadence of your audit. An annual test is a photograph of one day, and it will not contain the subdomain that appeared in March. This is the specific mismatch that continuous testing exists to close.

Is external penetration testing the same as attack surface management?

No, and they work well together. Attack surface management is the discovery and inventory function: it tells you what exists and how exposed it looks. External penetration testing takes that inventory and tries to break it, which is what turns an exposure rating into evidence. Buying only the inventory and reporting it as an assessment is a common and avoidable mistake.

Can external testing be done without disrupting production?

Yes, with the usual precautions: denial-of-service testing excluded by default, destructive actions agreed in advance, an escalation contact available during testing, and fragile systems flagged so they are handled carefully. Most external testing is read-heavy and unremarkable from the outside. The exceptions are worth naming in the rules of engagement rather than discovering live.

[ RELATED ]

The perimeter is one half of the network scope. Continuous discovery is where this page leads next.

Our solution architecture

A centralized platform that combines continuous asset monitoring, autonomous threat emulation, and expert remediation support—powered by AI agents, human validation, and a dedicated governance team.

ALWAYS-ON PLATFORM

More than a test. A strategic layer for real security.

Our AI is powered by a proprietary data layer built from thousands of hours of pentesting and real-world validations. Strike combines autonomous execution and expert human validation to uncover complex risks, reduce noise, and prioritize actionable findings.

In-depth continuous testing

Strikers uncover high-impact vulnerabilities across multi-technology environments (web apps, APIs, mobile, cloud, and more).

AI-led retesting on-demand

Validate fixes instantly, without waiting for the next testing cycle.

Real-time fixing

coming soon

AI agents guide your team step-by-step through remediation to accelerate resolution.

Step-by-step Threat emulation creation

Easily scope, launch, and track your Threat emulation with full transparency.

Human triaging & peer review

Every finding is validated by security experts to ensure accuracy and impact.

Full visibility

Track every finding with complete transparency through security expert work logs and real-time notifications.

Seamless integrations

Connect directly with Slack, Teams and Jira to streamline collaboration with your security and development teams.

Vulnerability Manager

Visualize, manage, and retest vulnerabilities in one platform, with full context on severity, sources, and remediation.

Compliance-ready reporting

Automatically generate up-to-date reports aligned with PCI DSS, HIPAA, ISO 27001, SOC 2, and more.

Ongoing partnership

Weekly check-ins with a dedicated Customer Success Manager, plus personalized onboarding and strategic planning.

More than an offensive security platform, Strike operates as a continuous validation layer for environments that never stop changing.

Boost your experience with Hybrid Testing Booster

Continuous Hybrid Testing

Emulated, deep stealth-based attacks executed by creative, unconventional security experts. Find out how real attackers would breach your systems, and stop them before they do.

Testimonial

Trusted by security teams that lead

"Product was great! The team was exceptional when addressing our sense of urgency with regards to an important timeline, and they were able to deliver effectively and finding important vulnerabilities within our systems."

Gartner 4
Gartner review, Head of Engineering, Banking

"Good option for agile testing, especially if GTM timelines are tight. This is especially important when the release train comes with a lot of new products and releases, making it hard to keep the pace in a traditional ad-hoc business model."

Gartner 3
Gartner review, Product Security Leader Cybersecurity, Hardware

“Strike provides continuous pentesting for our critical web and mobile features. Each month they help us validate new functionalities in production, delivering relevant vulnerabilities and strong value for money. We are very satisfied with their innovative and customer-centric approach.”

Gartner 2
Gartner review, Chief Information Security Officer, Retail

"Strike team was fast and provided the exact solution we needed for our use case. We decided to go for Strike because they provide a pen-testing suite that fits the way we work in terms of speed and communication. Highly recommended!"

Gartner review
Gartner 1
Gartner Review, Chief Technical Officer, Banking

"We greatly value our partnership with Strike. Their exceptional penetration testing services and effective communication have significantly enhanced our cybersecurity, ensuring the safety and trust of our customers' financial information."

Ozan Özgür Özyüksel
Information Security Officer, Plum

"The management of communication channels and the centralization of interactions with the team made the experience much more agile and effective. Having everything in one place was a huge advantage and allowed us to complete the pentest within just a few weeks."

Miguel Langone
CTO at Horizon

“Working with Strike is extremely important to us, especially because they deliver quality work over our products in a continuous way, and provide constant follow-up when it comes to managing the already found vulnerabilities. Moreover, they are constantly making improvements in their SaaS platform so we can have the best experience possible. In case we have a problem, they listen and help us. That’s invaluable.”

Ileana Barrionuevo
Sr AppSec Red Team, NaranjaX

“Working with Strike was an excellent experience for us. We were able to create our own pentests and change their scope each month. The Strikers are world-class professionals who provide us with relevant findings quickly and efficiently. Also, automated tools like Phishing Monitor are really interesting for our company, because they help us spot fake domains trying to impersonate PedidosYa.”

Eduardo Gimenez
CISO, Pedidos Ya

“For us at pier, security is the most important aspect, not only on the surface but throughout our entire product. When we reached out to Strike, we were looking for someone that could test & find vulnerabilities across our entire stack. We are very happy that we have found the right partner to achieve that, and we are looking forward to continuing this important work together.”

Andras Hejj
CEO & CTO, Pier

Human expertise.
AI power.
Superior security.

Whether you’re scaling fast, closing enterprise deals, or just tired of noisy reports, we’ll help you build a security stack that moves faster than your threats.

Book a Demo