Network Risk Assessment Services

Internal and external network penetration testing services

An Internal or an External Network Penetration Assessment involves simulating real-world attacks to provide a current view of vulnerabilities and threats to the client's network infrastructure.

  • These assessments begin with a discovery process that utilizes Nexpose, as well as, publicly available tools and utilities to develop a baseline profile of accessible services, ports and systems as targets for further internal or external penetration testing.
  • Once a baseline of information is gathered, Rapid7 uses Metasploit Pro, as well as a number of tools to perform a more in-depth analysis including manual probing to:
    • Test identified components to gain access to the network
      • Network devices such as firewalls, routers, and switches.
      • Network services such as web, dns, email, ftp, etc.
    • Determine possible impact or extent of access by attempting to exploit vulnerabilities.

Internal or External Penetration Testing services provide you with:

  • An understanding of real-world risks posed to the organization from the perspective of an attacker, going beyond the limitations of automated scanning.
  • A prioritized risk rating (DREAD framework) that takes multiple business-driven criteria into account.
  • Direct communication with an offensive security expert with years of industry experience and with direct access to the product team of the most widely used internal and external penetration testing framework.