External Network Penetration Testing
Your perimeter is scanned by attackers every day. Raxis tests it the way a real hacker would: manual, creative, and relentless.
Why Your External Network Is a Target
The pentester on your scope call is the one breaking in. And the one retesting your fix.
What We Test
A Raxis external penetration test goes far beyond a vulnerability scan. Our engineers follow the same path a real attacker would.
Reconnaissance and OSINT
We map your attack surface and hunt for exposed credentials, leaked data, and information that lowers the bar for attackers.
Full port and service enumeration
Every exposed host, port, and service is identified and fingerprinted.
Manual exploitation
We validate and exploit vulnerabilities by hand, chaining weaknesses to demonstrate real-world impact, not theoretical risk.
Password attacks
Password spraying and credential attacks against VPN, email, and login portals test your MFA, lockout, and password policies.
Unauthenticated web application testing
Exposed login pages, forms, and public content are probed for injection, authentication bypass, and information disclosure.
Cloud perimeter coverage
Internet-facing cloud assets and services are tested alongside traditional infrastructure.
Point-in-Time or Continuous
Both are performed manually by senior US-based Raxis engineers holding certifications such as OSCP and OSCE.
Scanning Isn’t Pentesting
Many low-cost “penetration tests” are automated scans with a new label. Ask any provider who will actually test your network, what they’ve found in past engagements, and to show a sample report. We regularly finish jobs other vendors couldn’t.
A Raxis clean report means your perimeter withstood a genuine attack, not just a scanner.
Testing From Where Attackers Live: The Internet
External tests launch from Raxis attack infrastructure across the internet, the same vantage point real attackers have. No hardware, no travel, and no agents to install; we just need your IP ranges and domains. Ready to see past the perimeter? Our Transporter device extends the same engagement to your internal network.

What You Get
Every Raxis external penetration test delivers everything you need to understand, fix, and prove your security posture. Track status, findings, and report delivery in real time with Raxis One.
Executive Summary
A concise summary written for leadership and auditors.
Technical Findings
Every finding includes a severity rating, reproduction steps, and clear remediation guidance.
Attack Storyboard
A step-by-step narrative shows exactly how we got in and how far we could go.
Included Retest
We verify your fixes and deliver a clean final report at no extra cost.
Findings We See in the Wild
These are real vulnerabilities our engineers find on external networks again and again.
Open Telnet and FTP
Services that require no credentials and allow malicious file uploads.
Exposed Admin Pages
Interfaces protected only by default credentials reveal device settings and customer data.
Weak Login Pages
Pages that confirm valid usernames and allow unlimited brute-force attempts.
Missing MFA
VPN and email portals where one guessed password becomes full access.
Forgotten Systems
Hosts running outdated software with public exploits available.
Leaked Credentials
Employee passwords exposed in public breach dumps that still work on live systems.
Raxis Hack Stories
Our stories are based on real events encountered by Raxis engineers; however, some details have been altered or omitted to protect our customers’ identities.
Looting The Shop
Pentesters usually prefer internal tests because modern perimeters are hard to crack. That’s the result most customers hope for: proof the controls work.
This engagement told a different story. Mapping a large internet-facing network, our team found dozens of hosts with open ports and discovered an obsolete operating system running unpatched software. A reverse shell gave them internal access. From there they escalated privileges, harvested credentials across the network, and pivoted to a domain controller, cracking more than half of the domain’s password hashes.
External access became domain admin. The real winner was the customer, who used the Raxis report to secure emergency budget for upgrades and remediation.
External Penetration Testing FAQ
Have questions about penetration testing? Want a quote or just a better sense of how we work? Reach out. We’ll answer your questions, walk you through our services, and put together a scope that fits your environment. No sales pressure, no obligation. Just a straightforward conversation with our team.

