Pentest on Demand — Black Box & Grey Box
Pentest on Demand
Annual penetration tests made sense when infrastructure changed slowly. Today, cloud environments evolve daily, new services appear overnight, and attackers do not wait for your next audit cycle. ExternalScan’s pentest on demand lets you trigger a targeted security assessment directly from the platform — backed by automated discovery and validated by a certified human pentester — whenever you need it.
What is Pentest as a Service?
Pentest as a Service (PTaaS) replaces the traditional point-in-time engagement model with a continuous, platform-integrated approach to penetration testing. Instead of scheduling a separate annual audit with a separate tool and waiting weeks for a static PDF report, PTaaS lets security teams request tests on demand, receive findings in a live dashboard, and track remediation in the same workflow as their other security operations.
ExternalScan’s pentest on demand is built on this model. Because your asset inventory is already continuously maintained by the platform, every engagement starts from a complete and current picture of your perimeter — not a scope document assembled months in advance. Findings land alongside your continuous monitoring alerts, and retesting happens within the same tool rather than requiring a new engagement.
The shift PTaaS enables:
- From annual to on-demand — trigger a test when your infrastructure changes, before a product launch, or after a significant architectural shift, not on an arbitrary calendar cycle
- From isolated to integrated — findings are tracked in the same platform as your EASM data, connected to the same integrations (Jira, Slack, ServiceNow) your teams already use
- From static to continuous — continuous monitoring watches for regressions after fixes, extending the value of each engagement beyond the point-in-time report
Black box or grey box: choose your perspective
Both methodologies are available. The right choice depends on what you are trying to learn.
| Black Box | Grey Box | |
|---|---|---|
| Attacker perspective | External attacker with no prior knowledge | Trusted partner with partial context |
| Starting point | Public-facing assets discovered automatically by ExternalScan | Defined scope with provided architecture, credentials, or access |
| What is tested | Exposure visible from the Internet | Specific systems or services you want assessed in depth |
| Best for | Realistic threat simulation, full attack surface validation | Focused assessments of APIs, authentication flows, or internal-facing services |
| Human pentester | Validates and escalates automated findings | Performs targeted manual tests using provided context |
Both modes benefit from ExternalScan’s live asset inventory: the pentester starts with a complete, up-to-date picture of your perimeter rather than a stale scope document.
How it works
1. Submit a request via the platform
Select the assets from your ExternalScan inventory, choose black box or grey box, and describe the scope. For grey box engagements, you provide the additional context (test credentials, architecture notes, specific entry points) directly in the request.
2. Automated reconnaissance and scanning
ExternalScan’s engine runs reconnaissance against the selected scope: service enumeration, port scanning, TLS analysis, technology fingerprinting, and vulnerability probing across 30+ security categories. Results are collected and ranked before the pentester begins.
3. Certified pentester assigned
A certified security expert (OSCP, OSWE, or equivalent) reviews the automated results, eliminates false positives, and performs targeted manual tests — chaining findings into realistic attack paths, testing authentication and authorisation logic, and probing surfaces that automation alone cannot reach.
4. Report delivery and remediation tracking
You receive a prioritised report with confirmed, exploitable findings, proof-of-concept evidence, and actionable remediation guidance. Findings are tracked directly in your ExternalScan dashboard alongside your continuous monitoring alerts. Retesting is available once fixes are deployed.
What is covered
Pentest scope is drawn from your ExternalScan asset inventory and can include:
- Web applications and APIs — injection, authentication bypass, broken access control, SSRF, and business logic flaws
- Network services and exposed ports — default credentials, unpatched services, protocol weaknesses
- TLS and cryptographic configuration — certificate validity, cipher suites, protocol versions
- Cloud-hosted services — storage exposure, metadata endpoints, misconfigured access policies
- Information disclosure — sensitive data in HTTP responses, error messages, headers, and DNS records
- Email and DNS security — SPF, DKIM, DMARC misconfigurations that enable phishing or spoofing
Coverage follows established methodologies: OWASP Testing Guide, PTES, and OSSTMM.
On-demand versus traditional penetration testing
| Traditional pentest | ExternalScan on demand |
|---|---|
| Annual or semi-annual schedule | Triggered when your infrastructure changes or risk warrants it |
| Weeks of scoping and scheduling | Request submitted through the platform in minutes |
| Static scope agreed months in advance | Scope drawn from your live, continuously updated asset inventory |
| Results delivered in a standalone PDF | Findings tracked in your ExternalScan dashboard alongside ongoing monitoring |
| Manual retest requires a new engagement | Continuous monitoring watches for regressions after fixes |
| Separate context from your security operations | Integrated with your EASM data, alerts, and integrations |
Compliance and certifications
Pentesters hold recognised certifications including OSCP, OSWE, GPEN, and GWAPT. Engagements are scoped to avoid destructive actions and are safe to run against production environments. Reports are formatted to support compliance requirements including DORA, NIS2, and PCI DSS.
Get started
Ready to test your defences?
Book a demo and our security team will walk you through how to set up your first pentest on demand, from scoping to reporting, using your ExternalScan asset inventory as the foundation.