Saltar al contenido
02 · Auditoría02 · Auditing

Pentest de Infraestructura Externa (Black Box)External Infrastructure Penetration Testing (Black Box)

Simulación de ataque externo sin credenciales contra activos expuestos.Simulated external attack without credentials against exposed assets.

OSSTMM · PTESOSSTMM · PTES 2.1 · Auditorías Técnicas (Hacking Ético)2.1 · Technical Audits (Ethical Hacking)

¿Qué es este servicio?What is this service?

Es una simulación de ataque desde internet contra todo lo que la organización tiene expuesto, ejecutada sin credenciales ni información previa. Es la caja negra: se parte del nombre de dominio y se llega hasta donde se pueda llegar.

A simulated attack from the internet against everything the organisation has exposed, run without credentials or prior information. This is the black box: it starts from the domain name and goes as far as it can.

¿Para qué se usa?What is it used for?

Permite observar el perímetro tal como lo ve un atacante externo que no conoce nada de la entidad. Primero se descubre qué hay realmente publicado —que casi siempre es más de lo que la organización cree— y después se intenta explotar. El hallazgo más frecuente no es una vulnerabilidad exótica sino un servicio que nadie recordaba que estaba abierto.

It shows the perimeter as an external attacker with no prior knowledge of the entity sees it. The work first establishes what is genuinely published — almost always more than the organisation believes — and then attempts to exploit it. The most frequent finding is not an exotic vulnerability but a service nobody remembered was open.

Qué beneficios traeBenefits it delivers

  • Encuentra el activo olvidado: el ambiente de pruebas publicado, el panel de administración accesible, el subdominio de un proyecto que terminó hace dos años.
  • Prioriza con criterio de explotabilidad real y no solo con la puntuación del escáner, que sobrestima y subestima por igual.
  • Es el punto de partida natural: si el perímetro está mal, lo interno importa menos.
  • Sirve como evidencia ante clientes, aseguradoras y reguladores de que se prueba de forma periódica.
  • Finds the forgotten asset: the published test environment, the reachable admin panel, the subdomain from a project that ended two years ago.
  • Prioritises by real exploitability rather than the scanner score alone, which over- and under-rates in equal measure.
  • It is the natural starting point: if the perimeter is weak, internal matters less.
  • Serves as evidence to clients, insurers and regulators that testing happens periodically.

¿En qué momentos es obligatorio?When is it mandatory?

Costa RicaCosta Rica

  • No hay ley costarricense que obligue a hacer pentest con esa palabra.
  • Las entidades que procesan tarjetas quedan obligadas por PCI-DSS, que aplica en Costa Rica por vía contractual con la marca o el adquirente.
  • El Acuerdo CONASSIF 5-24 exige a las entidades supervisadas gestionar el riesgo tecnológico, y las pruebas de seguridad son la evidencia estándar de ese control.
  • No Costa Rican law mandates penetration testing by that name.
  • Organisations that process cards are bound by PCI-DSS, which applies in Costa Rica through the contract with the brand or acquirer.
  • CONASSIF Agreement 5-24 requires supervised entities to manage technology risk, and security testing is the standard evidence of that control.

InternacionalInternational

  • PCI-DSS lo exige de forma explícita en el requisito 11.4.3: pentest externo al menos cada doce meses y después de cualquier cambio significativo.
  • ISO 27001 exige gestionar las vulnerabilidades técnicas, y el pentest es una de las formas aceptadas de identificarlas.
  • DORA exige pruebas de resiliencia periódicas a las entidades financieras europeas.
  • PCI-DSS requires it explicitly in requirement 11.4.3: external penetration testing at least every twelve months and after any significant change.
  • ISO 27001 requires managing technical vulnerabilities, and penetration testing is an accepted way to identify them.
  • DORA requires periodic resilience testing from European financial entities.

Requisitos mínimosMinimum requirements

  • Autorización por escrito de quien tiene potestad sobre los activos. Sin esto no se empieza: es el límite entre una prueba y un delito.
  • Listado de rangos de IP y dominios en alcance, y de lo que queda explícitamente fuera.
  • Si hay activos en nube, avisar al proveedor cuando su política lo exija.
  • Un contacto técnico disponible durante la ventana de pruebas por si algo se cae.
  • Written authorisation from whoever has authority over the assets. Nothing starts without it: it is the line between a test and a crime.
  • A list of in-scope IP ranges and domains, and of what is explicitly out.
  • For cloud assets, notifying the provider where their policy requires it.
  • A technical contact available during the testing window in case something breaks.

Plazo típico de entregaTypical delivery time

1 a 3 semanas 1 to 3 weeks rango habitual del mercado usual market range

El rango habitual del mercado va de una a tres semanas según el tamaño del perímetro: entrega del informe entre cinco y quince días hábiles desde el cierre de las pruebas. Un perímetro pequeño se cubre en una semana; varios cientos de activos expuestos se van a tres o cuatro. El retest suele entregarse en tres a cinco días.

The usual market range runs from one to three weeks depending on perimeter size: report delivery five to fifteen working days after testing closes. A small perimeter is covered in a week; several hundred exposed assets stretch to three or four. The retest is usually delivered in three to five days.

NomenclaturaTerminology

Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.

Caja negraBlack box
Modalidad en la que el equipo atacante no recibe información ni credenciales previas. A mode in which the attacking team receives no prior information or credentials.
OSSTMMOSSTMM
Manual abierto de metodología de pruebas de seguridad, una de las referencias del sector. Open Source Security Testing Methodology Manual, one of the sector's references.
PTESPTES
Penetration Testing Execution Standard: estándar que define las fases de una prueba de intrusión. Penetration Testing Execution Standard, defining the phases of a penetration test.
Superficie de ataqueAttack surface
El conjunto de puntos por los que alguien podría intentar entrar. The set of points through which someone could attempt to get in.
PentestPentest
Prueba de intrusión: se ataca el sistema con autorización previa y por escrito, para encontrar lo que encontraría un atacante real. Penetration test: the system is attacked with prior written authorisation, to find what a real attacker would find.
CVSSCVSS
Escala estándar para puntuar la severidad de una vulnerabilidad, de 0 a 10. Standard scale for scoring vulnerability severity, from 0 to 10.
RoERoE
Reglas de compromiso: el documento que define qué se puede atacar, cuándo, con qué técnicas y a quién avisar. Rules of Engagement: the document defining what may be attacked, when, with which techniques and who to notify.
RetestRetest
Segunda prueba, después de que el cliente corrige, para verificar que la corrección funcionó. A second test after the client remediates, to verify the fix actually worked.