Skip to content
Penetration testing
  • External network penetration testing
  • Internal network penetration testing
  • Web application penetration testing
  • API penetration testing
  • Mobile application penetration testing
  • Wireless penetration testing
  • Cloud security assessment
  • Social engineering and phishing simulation
Security assurance
  • Essential Eight assessment
  • Configuration review and benchmarking
  • Remediation support and retesting
Managed security
  • Vulnerability management
  • Continuous application scanning
  • SIEM monitoring
  • EDR monitoring
All services on one page
Industries How we work About Blog
1300 AURIAN Contact
Menu
Penetration testing
  • Penetration testing services
  • External network penetration testing
  • Internal network penetration testing
  • Web application penetration testing
  • API penetration testing
  • Mobile application penetration testing
  • Wireless penetration testing
  • Cloud security assessment
  • Social engineering and phishing simulation
Security assurance
  • Security assurance and compliance services
  • Essential Eight assessment
  • Configuration review and benchmarking
  • Remediation support and retesting
Managed security
  • Managed security services
  • Vulnerability management
  • Continuous application scanning
  • SIEM monitoring
  • EDR monitoring
  • All services
  • Industries
  • How we work
  • About
  • Blog
Call 1300 AURIAN Contact
  1. Services
  2. Penetration testing
  3. External network penetration testing

Penetration testing

External network penetration testing

We test your internet-facing perimeter the way an unauthenticated attacker would, then report every way in and how to close it.

Scope a test Call 1300 AURIAN

Who this is for

  • You are exposing something new to the internet

    A new portal, a new office, or a migration has changed what the outside world can reach, and you want it tested before an attacker finds it.

  • Your cyber insurer has asked for evidence of testing

    Renewal now depends on showing that your perimeter has been tested by an independent party in the last twelve months.

  • It has been a year, or more, since the last test

    The perimeter changes constantly as certificates renew, services move and staff come and go. An annual external test keeps the record current.

What our external network penetration test covers

Internet Web application API Perimeter Cloud tenancy Email Office network Workstation Identity Wireless Crown jewels Servers INTERNET: CHECKS INCLUDE Attack surface discovery: DNS, certificates and cloud footprint Exposed services and management interfaces Credential exposure in breaches and paste sites Software versions and known weaknesses on exposed hosts WEB APPLICATION: NOT IN SCOPE HERE Covered by web application penetration testing. Click to open that service. API: NOT IN SCOPE HERE Covered by API penetration testing. Click to open that service. PERIMETER: CHECKS INCLUDE VPN and remote-access appliances, including authentication Firewall rule exposure and TLS configuration Subdomain takeover and forgotten hosts Edge web servers and portals, unauthenticated CLOUD TENANCY: NOT IN SCOPE HERE Covered by cloud security assessment. Click to open that service. EMAIL: CHECKS INCLUDE SPF, DKIM and DMARC policy and alignment Exposed mail services and webmail Spoofing and relay tests against your domains OFFICE NETWORK: NOT IN SCOPE HERE Covered by internal network penetration testing. Click to open that service. WORKSTATION: NOT IN SCOPE HERE Covered by essential Eight assessment. Click to open that service. IDENTITY: NOT IN SCOPE HERE Covered by internal network penetration testing. Click to open that service. WIRELESS: NOT IN SCOPE HERE Covered by wireless penetration testing. Click to open that service. CROWN JEWELS: NOT IN SCOPE HERE Covered by internal network penetration testing. Click to open that service. SERVERS: NOT IN SCOPE HERE Covered by configuration review and benchmarking. Click to open that service. Internet Web application Perimeter API Email Cloud tenancy Office network Workstation Wireless Identity Crown jewels Servers INTERNET: CHECKS INCLUDE Attack surface discovery: DNS, certificates and cloud footprint Exposed services and management interfaces Credential exposure in breaches and paste sites Software versions and known weaknesses on exposed hosts WEB APPLICATION: NOT IN SCOPE HERE Covered by web application penetration testing. Click to open that service. PERIMETER: CHECKS INCLUDE VPN and remote-access appliances, including authentication Firewall rule exposure and TLS configuration Subdomain takeover and forgotten hosts Edge web servers and portals, unauthenticated API: NOT IN SCOPE HERE Covered by API penetration testing. Click to open that service. EMAIL: CHECKS INCLUDE SPF, DKIM and DMARC policy and alignment Exposed mail services and webmail Spoofing and relay tests against your domains CLOUD TENANCY: NOT IN SCOPE HERE Covered by cloud security assessment. Click to open that service. OFFICE NETWORK: NOT IN SCOPE HERE Covered by internal network penetration testing. Click to open that service. WORKSTATION: NOT IN SCOPE HERE Covered by essential Eight assessment. Click to open that service. WIRELESS: NOT IN SCOPE HERE Covered by wireless penetration testing. Click to open that service. IDENTITY: NOT IN SCOPE HERE Covered by internal network penetration testing. Click to open that service. CROWN JEWELS: NOT IN SCOPE HERE Covered by internal network penetration testing. Click to open that service. SERVERS: NOT IN SCOPE HERE Covered by configuration review and benchmarking. Click to open that service.

We enumerate everything your organisation exposes to the internet, then test each service for the weaknesses an attacker would use first.

  • Exposed services on every in-scope public IP address and hostname
  • Remote access and VPN endpoints, including authentication and known bypasses
  • Mail security records and their enforcement, covering SPF, DKIM and DMARC
  • DNS configuration, zone data exposure and subdomain takeover through dangling records
  • Exposed management interfaces, admin panels and forgotten staging systems
  • TLS configuration, certificate validity and protocol downgrade exposure
  • Credentials exposed in past breaches and paste sites for your domains
  • Web applications and APIs discovered on the perimeter, tested to an agreed depth

How we test it

Every external network penetration test is performed by a senior Aurian consultant, following the Penetration Testing Execution Standard and NIST SP 800-115. Automated tooling has its place for coverage across a large address range, but it is the consultant who decides what is worth pursuing, confirms that a weakness is real rather than a scanner’s guess, and joins one finding to the next.

We begin outside your systems entirely, mapping what your organisation exposes from public sources: DNS records, certificate transparency logs, breach and paste data, and search engines. That reconnaissance often finds the forgotten staging server or the subdomain nobody remembers, which are exactly the systems an attacker looks for. From there we enumerate the live services behind each address, identify versions and technologies, and test each one by hand.

Where a weakness is exploitable, we prove it safely and stop short of anything that would affect availability. We do not run denial-of-service testing unless you specifically ask for it. Throughout the engagement you have a named contact, and we tell you about any critical finding the day we confirm it rather than holding it for the report. When the report is delivered and you have remediated, we retest the findings rated high or above so the final record shows what was found and what was closed.

Standards PTES, NIST SP 800-115, OWASP WSTG

  1. 01 Reconnaissance

    We map your internet footprint from public sources: DNS, certificate transparency logs, breach data and search engines, without touching your systems.

  2. 02 Enumeration

    We identify the live services, versions and technologies behind each exposed address and build the list of things worth testing.

  3. 03 Exploitation

    A consultant tests each service by hand, confirming real weaknesses and chaining them where one leads to another, with tooling used only for coverage.

  4. 04 Reporting and retest

    You receive the report ranked by severity. Once you have remediated, a retest of the findings rated high or above confirms what is closed and the report is updated. Retesting is quoted with the test or booked afterwards.

What you receive

Every finding in an Aurian report looks like this: what we found, the evidence, what it means for you, and what to change.

Extreme AUR-2026-014 Sample finding, fictional environment

Expired VPN appliance exposes a known authentication bypass

Affected asset
vpn.example.com.au (203.0.113.42)
Rating
Extreme Likely 4 × Critical 6 = 24

Description

The remote access appliance is running firmware three major versions behind current and is affected by a published authentication bypass. An attacker on the internet can reach the internal network without valid credentials by sending a crafted request to the session endpoint.

Evidence

$ curl -sk https://203.0.113.42/dana-na/../dana/html5acc/guacamole/ \
    -H "Host: vpn.example.com.au"
HTTP/1.1 200 OK
Server: MAG-VPN 9.1R2 (build 4711)   # 9.1R18 is current
X-Session: created uid=0 sslvpn-admin

The response confirms an authenticated session was created for an administrative user without any credentials being supplied.

Impact

The appliance sits at the boundary of the internal network. A working bypass gives an attacker the same reach as a remote employee, and from there the internal network is in play. This is the single most valuable target on most perimeters, which is why it is tested first.

Remediation

Update the appliance to the current firmware, which closes the bypass, then rotate all local and administrative credentials because the device may already have been reached. Restrict the management interface to named administrative addresses, and enable multi-factor authentication on all remote access.

References

  • OWASP WSTG, testing for weak authentication
  • ASD, remote access hardening guidance
  • Executive summary written for the board and the insurer, in plain language
  • Technical findings ranked by severity, each with evidence and a fix
  • Remediation guidance your own engineers can apply without calling us
  • A debrief call to walk your team through the findings and the priorities

Common findings

What this kind of engagement typically surfaces, so you can recognise your own environment.

  • Exposed management and admin interfaces

    Router, firewall, hypervisor and application admin panels reachable from the internet, often with default or reused credentials.

  • Unpatched perimeter services

    VPN concentrators, mail gateways and load balancers running firmware with published, exploitable weaknesses.

  • Weak mail authentication

    SPF set to soft-fail, DKIM absent, or DMARC in monitor mode, so an attacker can spoof your domain in phishing that targets your own staff and customers.

  • Subdomain takeover

    DNS records pointing at deprovisioned cloud services an attacker can re-register and serve content from under your name.

  • Credentials exposed in past breaches

    Staff passwords from unrelated breaches that still work against your remote access because they were never rotated.

  • Weak TLS configuration

    Deprecated protocols and cipher suites still enabled, and certificates that have expired or cover the wrong names.

Frequently asked questions

How long does an external network penetration test take?

It depends on the number of live hosts and services in scope: typically three to five days of testing, with the report following. We give you a fixed timeframe after scoping.

Will the test disrupt our services?

External testing is designed to be safe against production. We do not run denial-of-service testing unless you ask for it, and we agree a contact and a window before we start so anything unexpected can be stopped at once.

Do you need any access from us?

No credentials are needed for the unauthenticated test. We need the list of IP addresses and domains that are yours, and written authorisation to test them. If any addresses are hosted by a third party, we help you obtain their permission first.

How often should we run one?

At least annually, and after any significant change to what you expose: a new service, a new office, a cloud migration or a merger. Many clients pair the annual test with continuous vulnerability management in between.

What is the difference between this and a vulnerability scan?

A scan lists known weaknesses automatically. This test confirms which are real, chains them into a path, and shows what an attacker actually reaches. We offer scanning too, inside managed vulnerability management.

Related services

Internal network penetration testing

Internal penetration testing from a foothold on your network: Active Directory attack paths, credential hygiene and segmentation, tested to domain admin.

Web application penetration testing

Web application penetration testing against the OWASP Testing Guide: authentication, access control, injection and business logic, tested by hand.

Vulnerability management

Managed vulnerability management: continuous scanning of external and internal assets, results validated and ranked by a consultant, reported monthly.

Penetration testing services

Scope a test with a senior consultant

Tell us what you need to know about your environment. We reply within one business day.

Scope a test Call 1300 AURIAN

Aurian Security is an Australian penetration testing and security assurance firm. Senior consultants perform every engagement, for clients across the country.

Penetration testing

  • External network penetration testing
  • Internal network penetration testing
  • Web application penetration testing
  • API penetration testing
  • Mobile application penetration testing
  • Wireless penetration testing
  • Cloud security assessment
  • Social engineering and phishing simulation

Assurance and managed

  • Security assurance
  • Essential Eight assessment
  • Configuration review and benchmarking
  • Remediation support and retesting
  • Managed security
  • Vulnerability management
  • Continuous application scanning
  • SIEM monitoring
  • EDR monitoring

Company

  • About Aurian
  • How we work
  • Industries
  • Blog
  • Contact
  • Privacy policy
526/368 Sussex St, Sydney NSW 2000 1300 AURIAN (1300 287 426) sales@aurian.com.au

© 2026 Aurian Security Pty Ltd. ACN 639 930 528.

This site is static, loads no third-party trackers, and publishes a security.txt.