All services

01

Black Box Penetration Test

External, zero-knowledge testing that mirrors how a determined attacker probes your perimeter without inside help. We work from nothing but your organisation name and agreed targets, mapping what is publicly reachable and attempting safe, controlled exploitation.

Black Box Penetration Test

Scope

  • External recon and OSINT against agreed domains and IP ranges
  • Web application, API, and network perimeter testing
  • Unauthenticated exploitation of public-facing assets
  • Credential exposure and leaked data checks
  • Safe, non-destructive proof-of-exploit for every confirmed finding

Deliverables

  • Executive summary written for non-technical stakeholders
  • Technical findings with CVSS ratings and reproduction steps
  • Prioritised remediation roadmap with effort estimates
  • Live debrief walkthrough with your engineering team
  • Free retest of critical and high findings

Typical timeline

1–3 days

Scope call & NDA

Free 30-minute call, mutual NDA, fixed-fee proposal.

5–10 business days

Testing window

Active testing with daily progress updates.

3–5 business days

Reporting

Draft report, QA review, and final delivery.

Within 30 days

Debrief & retest

Walkthrough session plus retest of critical findings.