◆ Next live training: Red Blue Purple AI · Sep 1 & 3, 2026 · Attacking AI · Sep 22 & 24, 2026
HomeConsultingExternal Network Penetration Testing
Consulting · Offensive Security Services

External Network Penetration Testing

Real Testing, Real Insights

Most "external penetration tests" are an automated vulnerability scan in a trench coat, a tool pointed at a list of IPs, lightly validated, and shipped as a report. Ours is a genuine, expert-led assessment of your entire internet-exposed attack surface: the assets you forgot you had, the appliances on your edge, and the identity provider guarding your front door, tested the way the intrusion sets actually breaching companies do, not the way a scanner does.

// attack-surface recon · edge & identity · misconfig at every layer
External network penetration testing
What We Test

Your whole attack surface, not a list of IPs.

"External" used to mean "scan these /24s." It doesn't anymore. Real intrusions start from the asset nobody remembered, the appliance on the edge, or the single sign-on nobody stress-tested. We find all of it, then test it at the web, cloud, and infrastructure layers, and every engagement is delivered by the same top-tier researchers start to finish. No bait-and-switch, no outsourced team you never meet.

01

Full-Surface Reconnaissance

We map everything an attacker can reach: subdomains, cloud assets, forgotten and acquired-company infrastructure, shadow IT. Recon is where breaches begin: and it's what elite bug-bounty hunters, our bench, do better than anyone.

02

CVE & Misconfiguration Analysis

Every asset we surface is tested for known-exploitable CVEs and the misconfigurations that don't have a CVE at all, across your web, cloud, and infrastructure layers.

03

Edge & Appliance Perimeter

The number-one way attackers get in today. We hunt your VPNs, gateways, and appliances specifically, cross-referenced against CISA's Known Exploited Vulnerabilities catalog.

04

Identity Perimeter

Your login is exposed to the whole internet, and modern SSO is a minefield of misconfiguration. We bypass IDP/SSO by design flaw, no stolen passwords required.

Arcanum specialty
05

Dark-Web Credential Exposure

We surface leaked credentials tied to your domains from breach data and the dark web, so you know what's already out there. Exposure only, validation and credential-stuffing live in our Red Team service.

06

Unauthenticated Web App Testing

When recon turns up web applications, we test them pre-authentication for initial-access flaws. Deep, credentialed testing is our dedicated Web Application Pentest.

The Edge

The edge is the front door.

For three years running, the fastest way into an enterprise hasn't been a phishing email, it's been the box bolted to the perimeter. CitrixBleed, Ivanti Connect Secure, Fortinet, Palo Alto GlobalProtect, MOVEit, every one a VPN, gateway, or file-transfer appliance a scanner quietly logged as "just another host." We hunt your edge specifically.

What we hunt

// your perimeter
  • SSL-VPNs and remote-access gateways
  • Mail, file-transfer, and management appliances
  • Exposed admin panels and device-management interfaces
  • Edge devices on end-of-life or unpatched firmware

How we test it

// KEV-aligned
  • Fingerprint every appliance, product, and version
  • Cross-reference CISA's Known Exploited Vulnerabilities catalog
  • Validate real, reachable exposure, not just a version banner
  • Prioritize the exposures attackers are exploiting right now
The Identity Perimeter

Identity is the new perimeter, and it's usually misconfigured.

Your login page is exposed to the entire internet, and modern SSO stacks are a minefield of subtle flaws. This is Arcanum's home turf: the same tradecraft we teach in our TBHM client-side expansion. We test your identity providers and single sign-on the way an attacker does: bypassing the login by design, with no valid password required.

Where SSO breaks

// by design flaw
  • Broken OAuth redirect_uri and response-mode handling
  • Missing or forgeable SAML signature validation
  • Weak federation and trust relationships
  • IdP-initiated flow abuse
  • Login and account-recovery logic bypasses

Why us

// home turf
  • The exact tradecraft in our TBHM client-side expansion
  • Honed on the top bug-bounty programs in the world
  • Most "network" pentests never touch your IdP: we start there
  • No valid password required: we bypass the login by design

Scope note: this is misconfiguration testing, bypassing broken logins by design. Credential-based attacks (spraying, stuffing, phishing) are part of our Cyber Red Teaming engagement.

What You Get

Deliverables that drive real remediation.

Every engagement ends with more than a PDF: you get the evidence, the context, and the support to actually fix what we find.

01

Detailed Technical Report

Every finding documented with clear reproduction steps, real-world impact, and the evidence to back it.

02

Executive Summary

Risk translated into business terms your leadership and board can act on.

03

Prioritized Remediation

Practical, ranked fixes tied to the real attack paths we walked, not a raw scanner dump.

04

Live Findings Debrief

A working session where we walk your team through the results and answer every question.

05

Complimentary Retest

Once you've remediated, we re-test the findings to confirm the fixes actually hold.

06

Knowledge Transfer

You learn how we found what we found, so your team gets stronger with every engagement.

Ready to see your network through an attacker's eyes?

Let's discuss how Arcanum can strengthen your external defenses.

Jason Haddix signature
Scope

Choosing the right engagement.

Our three external-facing services overlap but aren't interchangeable. Here's exactly what each covers, so you can scope the one you actually need.

External Network PentestYou are here Cyber Red Teaming Web Application Pentest
Reconnaissance
CVE & misconfiguration analysisinfra · cloud · web
Phishing & social engineering
Dependency confusion & hijacking
Leaked-credential analysisdark-web / breach dataExposure onlynot validatedStuffed & validated
Web-application testingUnauthenticatedUnauthenticatedcreds only to reach a goal *Full credentialedfull stack

* On a red team, web applications are only credential-tested when dark-web-sourced credentials are used to reach an agreed objective.