
7 Minute Security · 2026-05-29 · 30 min
Hey friends! Today we're going deep on external network pentesting - something I realize we've barely touched in however many episodes we've done. I'm currently in a long stretch of back-to-back external assessments, so it felt like a good time to talk about it. Here's what we get into: Scoping headaches - why the old "count your public IPs and multiply by a big hourly rate" approach drives me crazy, and how we actually scope external tests to be fair to everyone Web apps in scope or not? - this needs its own conversation before the test starts, and skipping it causes pain later Testing under real conditions - the debate around whether to request an allowlist vs.