C
Cryndel
Offensive Security
Confidential
External Security Assessment
Example Corp — public web perimeter
- Client
- Example Corp
- Engagement
- External web application assessment
- Window
- 2026-01-15
- Report version
- 1.0
- Authorization
- Signed rules of engagement on file
- Prepared for
- Example Corp Security Team
1 — Executive summary
Cryndel performed an external, read-only assessment of Example Corp's public web perimeter. Testing was unauthenticated and non-exploitative: reconnaissance, fingerprinting, TLS inspection, and detection-only scanning.
This is example data illustrating the report format. Replace this engagement folder with your own.
Severity uses CVSS v3.1 base scores computed from each finding's vector.
2 — Scope
| Host | Hosting | Role |
| example.com, www | CDN | Marketing site |
| app.example.com | Cloud | Web application |
All targets owned by the client; authorization verified. Excluded DoS, brute force, and data modification.
3 — Methodology
External-assessment phases of PTES / OWASP WSTG: passive recon, service and TLS fingerprinting, and detection-only scanning throttled to ~5 req/s per host.
4 — Findings
F-001
Content-Security-Policy not set
Medium
- CVSS v3.1
- 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
- Affected
- app.example.com
- Description
No CSP header is returned, removing a key defense-in-depth control against cross-site scripting and content injection.
- Evidence
$ curl -sI https://app.example.com/ | grep -i content-security
(no output)
- Remediation
- Define a CSP in report-only mode, tune per application, then enforce.
- Status
- Open
F-002
Example informational item
Informational
- Affected
- example.com
- Description
Placeholder informational finding showing how non-scored items render.
- Remediation
- No action required.
- Status
- Closed — not a vulnerability
5 — Next phases
- Authenticated testing with provided test accounts.
- Deep service and TLS scan on origins not behind a CDN/WAF.