Security Assessments / External Network

See what the internet can reach.

An outside-in review of the systems and services exposed to the internet—mapped, investigated, and manually validated against the boundary you authorize.

AssessmentExternal Network
Testing boundaryAuthorized public systems

What could a capable attacker realistically discover or compromise?

The assessment follows the exposed perimeter from reachable hosts and services through credible weaknesses and material attack paths. The result is not a scanner export. It is a bounded answer about actual exposure.

01

Reachable systems

Hosts, ports, protocols, services, TLS endpoints, virtual hosts, and administrative surfaces.

02

Service exposure

Known vulnerabilities, unsafe configuration, obsolete software, default behavior, and unintended access.

03

Public web surface

Unauthenticated applications, APIs, documentation, exposed files, diagnostics, and obvious leakage.

04

Attack paths

Manual validation of credible weaknesses and synthesis of what becomes possible when exposures combine.

Testing stops at the authentication boundary. Credentials, roles, tenant separation, authenticated workflows, business logic, and source review belong in a Web Application Security Assessment.

Broad discovery. Narrow proof.

Coverage is comprehensive across the authorized perimeter. Validation stays minimal-impact and stops before proof would create avoidable operational risk.

  1. 01Lock the boundary

    Normalize the authorized addresses and FQDNs, resolve relationships, and establish the target list used for active testing.

  2. 02Map the perimeter

    Identify reachable services, protocols, versions, certificates, public applications, APIs, gateways, and administrative surfaces.

  3. 03Investigate exposure

    Correlate automated breadth with manual service-specific analysis, configuration review, and targeted protocol testing.

  4. 04Validate safely

    Establish the smallest reliable fact needed to support the judgment. Raw scanner output never becomes a finding by itself.

  5. 05Synthesize risk

    Connect related weaknesses, distinguish direct compromise from hygiene, and prioritize remediation by material risk reduction.

A report built for action.

Coverage and limitations stay visible. Every finding carries the evidence and reasoning required for your team to independently understand and address it.

Immediate

Critical notification

Validated Critical findings are communicated immediately rather than held for the final report.

Primary

Written report

Executive conclusion, tested coverage, limitations, evidence-backed findings, severity rationale, attack paths, and prioritized remediation.

Optional

Engineering readout

A focused discussion of material findings, attack paths, and remediation priorities when live discussion adds value.

Define the scope.

Each engagement receives a fixed scope and fixed quote before work begins. The quote reflects the authorized systems and services in scope.

To scope the workIPs + FQDNs

Provide the public IP addresses, CIDRs, and fully qualified domain names you are authorized to test, plus a responsible contact.

Related infrastructure outside that boundary is documented but not actively tested unless it is explicitly added to scope.

Discuss an assessment

What do you need assessed?

A brief outline is enough to start. We’ll follow up by email to discuss fit, scope, and timing.

Scope and a fixed quote are agreed before work begins.

Prefer email? mark@inferencesecurity.ai

A little about your system, what prompted the assessment, or a date you’re working toward.

For this conversation only.
No product updates unless you ask.

Submissions are handled by Formspree.