Most "external penetration tests" are an automated vulnerability scan in a trench coat, a tool pointed at a list of IPs, lightly validated, and shipped as a report. Ours is a genuine, expert-led assessment of your entire internet-exposed attack surface: the assets you forgot you had, the appliances on your edge, and the identity provider guarding your front door, tested the way the intrusion sets actually breaching companies do, not the way a scanner does.
"External" used to mean "scan these /24s." It doesn't anymore. Real intrusions start from the asset nobody remembered, the appliance on the edge, or the single sign-on nobody stress-tested. We find all of it, then test it at the web, cloud, and infrastructure layers, and every engagement is delivered by the same top-tier researchers start to finish. No bait-and-switch, no outsourced team you never meet.
We map everything an attacker can reach: subdomains, cloud assets, forgotten and acquired-company infrastructure, shadow IT. Recon is where breaches begin: and it's what elite bug-bounty hunters, our bench, do better than anyone.
Every asset we surface is tested for known-exploitable CVEs and the misconfigurations that don't have a CVE at all, across your web, cloud, and infrastructure layers.
The number-one way attackers get in today. We hunt your VPNs, gateways, and appliances specifically, cross-referenced against CISA's Known Exploited Vulnerabilities catalog.
Your login is exposed to the whole internet, and modern SSO is a minefield of misconfiguration. We bypass IDP/SSO by design flaw, no stolen passwords required.
We surface leaked credentials tied to your domains from breach data and the dark web, so you know what's already out there. Exposure only, validation and credential-stuffing live in our Red Team service.
When recon turns up web applications, we test them pre-authentication for initial-access flaws. Deep, credentialed testing is our dedicated Web Application Pentest.
For three years running, the fastest way into an enterprise hasn't been a phishing email, it's been the box bolted to the perimeter. CitrixBleed, Ivanti Connect Secure, Fortinet, Palo Alto GlobalProtect, MOVEit, every one a VPN, gateway, or file-transfer appliance a scanner quietly logged as "just another host." We hunt your edge specifically.
Your login page is exposed to the entire internet, and modern SSO stacks are a minefield of subtle flaws. This is Arcanum's home turf: the same tradecraft we teach in our TBHM client-side expansion. We test your identity providers and single sign-on the way an attacker does: bypassing the login by design, with no valid password required.
Scope note: this is misconfiguration testing, bypassing broken logins by design. Credential-based attacks (spraying, stuffing, phishing) are part of our Cyber Red Teaming engagement.
Every engagement ends with more than a PDF: you get the evidence, the context, and the support to actually fix what we find.
Every finding documented with clear reproduction steps, real-world impact, and the evidence to back it.
Risk translated into business terms your leadership and board can act on.
Practical, ranked fixes tied to the real attack paths we walked, not a raw scanner dump.
A working session where we walk your team through the results and answer every question.
Once you've remediated, we re-test the findings to confirm the fixes actually hold.
You learn how we found what we found, so your team gets stronger with every engagement.
Let's discuss how Arcanum can strengthen your external defenses.
Our three external-facing services overlap but aren't interchangeable. Here's exactly what each covers, so you can scope the one you actually need.
| External Network PentestYou are here | Cyber Red Teaming | Web Application Pentest | |
|---|---|---|---|
| Reconnaissance | ● | ● | — |
| CVE & misconfiguration analysisinfra · cloud · web | ● | ● | ● |
| Phishing & social engineering | — | ● | — |
| Dependency confusion & hijacking | — | ● | — |
| Leaked-credential analysisdark-web / breach data | Exposure onlynot validated | Stuffed & validated | — |
| Web-application testing | Unauthenticated | Unauthenticatedcreds only to reach a goal * | Full credentialedfull stack |
* On a red team, web applications are only credential-tested when dark-web-sourced credentials are used to reach an agreed objective.