Topic route / 10

External pentest

Organisation intelligence, attributed asset discovery, trust-boundary mapping, change monitoring, and the narrow active checks that turn perimeter observations into defensible evidence.

Recommended order

Start here, then go deeper.

Move from the organisation graph to attributed scope, customer-controlled supplier trust, current application mapping, and finally the identity boundary where narrow active testing can begin.

  1. 01
    Part 1 · Organisation graphThe External Perimeter Is a Graph. The Port List Is Only One View.

    Modern external pentesting starts by proving how domains, companies, certificates, identity systems, cloud services, and third parties relate. Active scanning then verifies the small part of that graph that is both relevant and authorized.

    14 min ↗
  2. 02
    Part 2 · AttributionThe Domain Resolved. Ownership Was Still a Hypothesis.

    A defensible external pentest does not turn company names, CT records, shared IPs, or acquisition news into targets. It separates association, current control, and written scope—then records the evidence for each decision.

    14 min ↗
  3. 03
    Part 3 · Supplier trustThe Vendor Was Out of Scope. The Trust Boundary Was Not.

    A third-party platform may be excluded from testing while the customer-controlled trust decisions around it remain assessable: identity claims, callbacks, webhooks, custom domains, delivery paths, and data flows.

    16 min ↗
  4. 04
    Part 4 · Application mappingThe Service Was Observed. The Application Was Still Unknown.

    Passive internet data can reveal a live service without proving its current owner, hostname, virtual host, application, or business purpose. A defensible external pentest turns that observation into a bounded application model before testing for vulnerabilities.

    16 min ↗
  5. 05
    Part 5 · Identity boundaryThe Login Page Was Public. The Identity Boundary Was Somewhere Else.

    A public login page is only the visible start of an identity system. External pentesting must map the issuer, callback, token policy, account binding, tenant and role conversion, and local session before testing authorization.

    17 min ↗
Full topic archive

Every matching record.

Methods and named-vulnerability research remain visually and editorially separate.

Field notes 5

Pentest · Sep 11, 2026

The Login Page Was Public. The Identity Boundary Was Somewhere Else.

A public login page is only the visible start of an identity system. External pentesting must map the issuer, callback, token policy, account binding, tenant and role conversion, and local session before testing authorization.

17 min read ↗
Pentest · Sep 10, 2026

The Service Was Observed. The Application Was Still Unknown.

Passive internet data can reveal a live service without proving its current owner, hostname, virtual host, application, or business purpose. A defensible external pentest turns that observation into a bounded application model before testing for vulnerabilities.

16 min read ↗
Pentest · Sep 9, 2026

The Vendor Was Out of Scope. The Trust Boundary Was Not.

A third-party platform may be excluded from testing while the customer-controlled trust decisions around it remain assessable: identity claims, callbacks, webhooks, custom domains, delivery paths, and data flows.

16 min read ↗
Pentest · Sep 8, 2026

The Domain Resolved. Ownership Was Still a Hypothesis.

A defensible external pentest does not turn company names, CT records, shared IPs, or acquisition news into targets. It separates association, current control, and written scope—then records the evidence for each decision.

14 min read ↗
Pentest · Aug 29, 2026

The External Perimeter Is a Graph. The Port List Is Only One View.

Modern external pentesting starts by proving how domains, companies, certificates, identity systems, cloud services, and third parties relate. Active scanning then verifies the small part of that graph that is both relevant and authorized.

14 min read ↗