I will perform internal or external network vapt
Cyber Security Consulting
About this Gig
Protect your business with a professional External Or Internal Network vulnerability assessment designed to identify security weaknesses before they become incidents.
With 10+ years of hands-on cybersecurity experience, I will assess your authorized internal or External infrastructure, including Windows and Linux hosts, servers, workstations, network devices, and exposed services.
What you receive:
- Scope and asset review
- Safe network discovery and vulnerability scanning
- Authenticated scanning when credentials are provided
- Manual validation to reduce false positives
- CVE, CWE, CVSS severity, evidence, and affected assets
- Clear remediation guidance and prioritized action plan
- Executive summary and detailed technical PDF report
- Optional remediation retest
Testing is non-destructive and limited to systems you own or are explicitly authorized to assess. Exploitation, credential attacks, malware, disruption, phishing, and unauthorized access are excluded.
Please message me before ordering so we can confirm asset count, subnets, VPN or jump-host access, maintenance window, and deliverables. Larger or segmented environments require a custom offer.
My Portfolio
FAQ
Is written authorization required?
Yes. We only assess systems owned by the buyer or systems for which the buyer has explicit written permission. Unauthorized access requests will be rejected.
Is this penetration testing or ethical hacking?
This Gig is primarily a defensive vulnerability assessment. It includes discovery, safe scanning, configuration checks and manual validation. Exploitation, password attacks, phishing, malware and disruptive testing are excluded.
What counts as one asset?
Each unique server, workstation, virtual machine, firewall, router, switch, appliance or other addressable device is counted as one asset.
What is authenticated vulnerability scanning?
Authenticated scanning uses temporary authorized credentials to check installed software, patches and local security configurations. It normally provides more accurate results than external service scanning alone.
How will you access my internal network?
The buyer must provide an approved VPN, temporary jump server or another authorized method. Access arrangements must be confirmed before the order begins.
What will the final report contain?
The report contains an executive summary, methodology, scope, limitations, asset inventory, validated vulnerabilities, severity ratings, CVE and CWE references, evidence, affected assets and prioritized remediation guidance.
Will you remove false positives?
The Gig includes remediation recommendations, but configuration changes and patch deployment are not included. Remediation implementation can be discussed as a separate service.
Is a retest included?
Standard includes retesting of up to 10 remediated findings. Premium includes one full remediation retest. Retesting must be requested within the stated post-delivery period.
Can you assess a larger corporate network?
Yes. Networks containing more than 75 assets, multiple sites, sensitive production systems or complex segmentation require a custom offer and an agreed rules-of-engagement document.
What are the out-of-scope activities for this gig?
The following activities are excluded unless separately reviewed and explicitly approved: Denial-of-service or stress testing, Exploitation of vulnerabilities, Password spraying or credential attacks, Phishing and other social-engineering activities, Malware, ransomware or persistence testing, etc.

