Attempts to exploit vulnerabilities just as a threat actor would
Planning is perhaps the most important part of pentesting.
Who should perform the test? Each option has advantages and disadvantages.
- internal security personnel
- external consultants
- croudsourced pentesting
Rules of engagement: establish the limits or parameters of the penetration test in advance to avoid issues.
- Timing
- Scope
- Authorization
- Exploitation
- Communication
- Cleanup
- Reporting
Performing a Penetration Test
- Key ingredient: persistence
- Phase 1: reconnaissance
- Phase 2: penetration