PENTRA — Network Module

External Network Security Assessment

PENTRA enables structured external network penetration testing — executing MITRE ATT&CK techniques against internet-facing infrastructure, with engineer-validated findings and a measurable Security Score per tactic.

MITRE ATT&CK Full Initial Access Coverage
360° External Attack Surface
100% Scope Coverage Enforced

PENTRA can be used by internal security teams as a platform or delivered as a fully managed service by Reacts — using the same structured methodology, technique library, and evidence-based execution model.

Map Your External Attack Surface Before an Attacker Does

External penetration testing evaluates internet-facing systems to identify exploitable entry points and initial access vectors.

Your external network is the first thing an adversary sees. Before attempting to cross the perimeter, a threat actor maps what is exposed — open ports, service versions, misconfigured applications, and authentication weaknesses. PENTRA identifies what is reachable, what is exploitable, and what can be used as a foothold into your internal environment — through the same structured, technique-level execution model used across all modules.

Unlike a vulnerability scan that reports open ports and CVE matches, PENTRA validates whether each identified weakness is actually exploitable and documents the attack path an adversary could follow from your external perimeter to an internal foothold.

Engagement Methodology

Phase Activities
Scoping & PlanningDefine external scope · Select MITRE ATT&CK initial access and reconnaissance techniques · Establish rules of engagement
ReconnaissanceEnumerate external services, exposed ports, and application endpoints · Identify technology stack and service versions · Map external attack surface
Controlled Technique ExecutionExecute MITRE ATT&CK techniques individually · Engineer validates each result before recording finding with evidence
Post-Exploitation ValidationValidate access depth achievable from external footholds · Document data exposure and internal pivot potential
ReportingGenerate on-demand reports — MITRE ATT&CK-mapped findings, attack path, severity distribution, remediation guidance
RetestValidate remediations and confirm reduction in residual risk

How PENTRA Structures This Engagement

This capability is delivered through the PENTRA platform using structured technique execution, human validation, and evidence-based reporting.

Learn how this capability fits into the full PENTRA platform →

MITRE ATT&CK External Library

Technique library for external network and initial access assessment — reconnaissance through exploitation.

Technique-Level Execution

Each technique executed individually with engineer validation at each step — no bulk automation.

Attack Path Builder

Documents the full exploitation chain from external perimeter to internal access — with evidence per step.

Real-Time Security Score

Security Score computed per tactic in real time — updated as techniques are validated and findings recorded.

Open Points Tracker

100% coverage before engagement close — no technique can be skipped without an explicit marking.

On-Demand Reports

On-demand reports with MITRE ATT&CK mapping per finding — at any stage of the engagement.

PT++: External Assessment with Blue Team Detection Validation

PT++ external engagements run simultaneous Red Team execution and Blue Team detection validation. As external attack techniques are executed, the Blue Team Portal streams live execution data to your SOC — who mark detection per technique and receive a measured Detection Rate per MITRE ATT&CK tactic. Particularly valuable for testing perimeter detection controls, IDS/IPS effectiveness, and SOC responsiveness to external attack patterns.

Capability Tags
External Attack Surface MappingOSINT · Port Scanning · Service Enumeration
Initial Access Technique ExecutionATT&CK Initial Access · Exploitation Techniques
Detection Validation (PT++ component)SOC Testing · Detection Rate per Tactic
Scope Coverage EnforcementTTP Coverage · Open Points Tracking
Metric What It Reflects
Security Score (per tactic)Validated by engineer — how well external controls resist each ATT&CK tactic
Detection Rate (PT++ only)Blue Team validated — how effectively the SOC detects external attack techniques
Scope Coverage100% — enforced before engagement close

Your external attack surface is visible to every attacker. Know what they see.

Talk to a Reacts engineer about a structured external network assessment.

What You Receive

Deliverable Description
Executive SummarySecurity Score per tactic, severity distribution, and key findings for CISO and board audiences.
Technical ReportAll findings mapped to MITRE ATT&CK TTPs · Evidence per finding · Attack path documentation · Remediation guidance
Blue Team Detection Report (PT++ only)Detection Rate per tactic · Evidence of detected and undetected techniques · Mitigation backlog
Delivery DiscussionPresentation of critical findings with the Reacts engineering team.

Prefer a Fully Managed Engagement?

Reacts delivers this capability as a managed service — executed by certified engineers and powered by the PENTRA platform.

Request a Managed Assessment

Frequently Asked Questions

External network penetration testing evaluates internet-facing systems to identify exploitable entry points an attacker could use to gain initial access to your environment.
PENTRA executes MITRE ATT&CK techniques related to reconnaissance, initial access, and exploitation against exposed services and internet-facing infrastructure — validating whether each identified weakness is actually exploitable.
A vulnerability scan reports open ports and known CVEs. PENTRA validates whether identified weaknesses are actually exploitable, documents the attack path, and provides engineer-confirmed evidence per finding — giving you a result you can act on and defend to auditors.
A PT++ external engagement pairs standard external penetration testing with simultaneous Blue Team detection validation. Your SOC receives a live feed of executed external attack techniques through the Blue Team Portal and marks detection per technique — producing a Detection Rate per tactic alongside the standard pentest report.

Validate Your External Security Posture