Reachable systems
Hosts, ports, protocols, services, TLS endpoints, virtual hosts, and administrative surfaces.
Security Assessments / External Network
An outside-in review of the systems and services exposed to the internet—mapped, investigated, and manually validated against the boundary you authorize.
The assessment follows the exposed perimeter from reachable hosts and services through credible weaknesses and material attack paths. The result is not a scanner export. It is a bounded answer about actual exposure.
Hosts, ports, protocols, services, TLS endpoints, virtual hosts, and administrative surfaces.
Known vulnerabilities, unsafe configuration, obsolete software, default behavior, and unintended access.
Unauthenticated applications, APIs, documentation, exposed files, diagnostics, and obvious leakage.
Manual validation of credible weaknesses and synthesis of what becomes possible when exposures combine.
Coverage is comprehensive across the authorized perimeter. Validation stays minimal-impact and stops before proof would create avoidable operational risk.
Normalize the authorized addresses and FQDNs, resolve relationships, and establish the target list used for active testing.
Identify reachable services, protocols, versions, certificates, public applications, APIs, gateways, and administrative surfaces.
Correlate automated breadth with manual service-specific analysis, configuration review, and targeted protocol testing.
Establish the smallest reliable fact needed to support the judgment. Raw scanner output never becomes a finding by itself.
Connect related weaknesses, distinguish direct compromise from hygiene, and prioritize remediation by material risk reduction.
Coverage and limitations stay visible. Every finding carries the evidence and reasoning required for your team to independently understand and address it.
Validated Critical findings are communicated immediately rather than held for the final report.
Executive conclusion, tested coverage, limitations, evidence-backed findings, severity rationale, attack paths, and prioritized remediation.
A focused discussion of material findings, attack paths, and remediation priorities when live discussion adds value.
Each engagement receives a fixed scope and fixed quote before work begins. The quote reflects the authorized systems and services in scope.
Provide the public IP addresses, CIDRs, and fully qualified domain names you are authorized to test, plus a responsible contact.
Related infrastructure outside that boundary is documented but not actively tested unless it is explicitly added to scope.
Discuss an assessment
A brief outline is enough to start. We’ll follow up by email to discuss fit, scope, and timing.
Scope and a fixed quote are agreed before work begins.
Prefer email? mark@inferencesecurity.ai