C
Cryndel
Offensive Security
Confidential

External Security Assessment

Example Corp — public web perimeter
Client
Example Corp
Engagement
External web application assessment
Window
2026-01-15
Report version
1.0
Authorization
Signed rules of engagement on file
Prepared for
Example Corp Security Team

1 — Executive summary

Cryndel performed an external, read-only assessment of Example Corp's public web perimeter. Testing was unauthenticated and non-exploitative: reconnaissance, fingerprinting, TLS inspection, and detection-only scanning.

This is example data illustrating the report format. Replace this engagement folder with your own.

0
Critical
0
High
1
Medium
0
Low
1
Informational

Severity uses CVSS v3.1 base scores computed from each finding's vector.

2 — Scope

HostHostingRole
example.com, wwwCDNMarketing site
app.example.comCloudWeb application
All targets owned by the client; authorization verified. Excluded DoS, brute force, and data modification.

3 — Methodology

External-assessment phases of PTES / OWASP WSTG: passive recon, service and TLS fingerprinting, and detection-only scanning throttled to ~5 req/s per host.

4 — Findings

F-001

Content-Security-Policy not set

Medium
CVSS v3.1
4.3  CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Affected
app.example.com
Description

No CSP header is returned, removing a key defense-in-depth control against cross-site scripting and content injection.

Evidence
$ curl -sI https://app.example.com/ | grep -i content-security
(no output)
Remediation
Define a CSP in report-only mode, tune per application, then enforce.
Status
Open
F-002

Example informational item

Informational
Affected
example.com
Description

Placeholder informational finding showing how non-scored items render.

Remediation
No action required.
Status
Closed — not a vulnerability

5 — Next phases