External surface
We test for
- Web apps and APIs, exposed services
- Authentication and authorization
- Subdomains, endpoints, integration APIs
- Dependencies and known vulnerabilities
- Initial-access paths
We map your authorized internet-facing surface and exploit what we find to establish a real foothold.
