Handbook

External shadowing introduction

Updated 28 Sept 2026People✎ Suggest a change
On this page

Hey [name], you've got an external engagement coming up. A few technical areas worth brushing up on beforehand so you're walking in with context rather than figuring it out on the fly.

Technical areas worth brushing up on

External engagements are mostly about attack surface, what's exposed to the internet and what can be found or reached from outside the network:

  • OSINT and recon basics, WHOIS lookups, DNS enumeration, and subdomain discovery using tools like amass, Sublist3r, or crt.sh
  • Shodan and Censys, get comfortable searching for exposed services tied to a client's IP ranges or ASN, it's often the fastest way to find something interesting
  • Commonly exposed external services and their usual weak points, VPN gateways (Fortinet, Ivanti/Pulse Secure, Citrix), RDP, and mail services like Exchange or OWA
  • Version and CVE research, checking exposed service banners and versions against known vulnerabilities
  • Password attacks against external facing logins, password spraying in particular, along with an understanding of lockout policies and why spraying is usually safer than brute forcing
  • SSL/TLS basics, what a weak cipher or expired cert actually means and why it's worth flagging even when it's not the headline finding
  • Email security fundamentals, SPF, DKIM, and DMARC, and how misconfigurations here tie into spoofing and phishing risk even outside a dedicated social engineering test
  • Cloud exposure, keep an eye out for misconfigured or public cloud assets, S3 buckets, Azure blobs, that kind of thing, external recon increasingly turns these up

Internal tools

We use internal tools such as nessus and Baskerville for external engagements. If you haven't used it yet, reach out to your buddy and get them to walk you through it before you start.


You don't need to be fluent in all of this before your first external job, just enough of a mental map that nothing is completely new when it comes up on site. If anything feels shaky, flag it to your buddy beforehand rather than guessing your way through it.