External Network Penetration Test
Budget: ₹37,500 – ₹75,000 INR
I want a thorough penetration test against my organisation’s external-facing infrastructure with the sole objective of uncovering every exploitable vulnerability before anyone else does. The scope is limited to the public IP ranges and cloud assets I will provide; nothing on the internal network is in play this time.
You are free to use the standard toolkit—Nmap, Nessus, Burp Suite, Metasploit, custom scripts—so long as the testing remains non-disruptive and fully documented. OWASP and PTES methodology are both acceptable; feel free to blend them if it yields deeper coverage.
Deliverables I need:
• An executive-level summary that highlights critical findings in plain language.
• A detailed technical report listing each vulnerability, proof-of-concept evidence, risk ratings, and clear remediation steps.
• A retest plan so I can verify fixes after the initial round.
I will provide written authorisation, the exact IP addresses, preferred testing windows, and a point of contact for any urgent findings. Successful completion means the final report is actionable, reproducible, and maps every discovered issue to its corresponding CVE or CWE where applicable.
You are free to use the standard toolkit—Nmap, Nessus, Burp Suite, Metasploit, custom scripts—so long as the testing remains non-disruptive and fully documented. OWASP and PTES methodology are both acceptable; feel free to blend them if it yields deeper coverage.
Deliverables I need:
• An executive-level summary that highlights critical findings in plain language.
• A detailed technical report listing each vulnerability, proof-of-concept evidence, risk ratings, and clear remediation steps.
• A retest plan so I can verify fixes after the initial round.
I will provide written authorisation, the exact IP addresses, preferred testing windows, and a point of contact for any urgent findings. Successful completion means the final report is actionable, reproducible, and maps every discovered issue to its corresponding CVE or CWE where applicable.