External attack surface assessment
Discovery of everything your organisation exposes to the internet, known and forgotten, with each exposure verified by hand.
Infrastructure and cloud
External and internal penetration testing of networks and Active Directory: from an exposed service or a single workstation to control of the domain.
Infrastructure and cloud
The external test answers one question: what can someone on the internet reach, and what happens when they do. The internal test answers another: what can someone do who is already inside, with the workstation of an employee and nothing else.
Inside most corporate networks the distance from an ordinary user to a domain administrator is a few steps: a password in a file share, a service account with too many rights, a certificate template that anyone may request. We find those steps and show the path.
01Scope
02Approach
We identify hosts and services, including those reachable under addresses and names that are missing from your inventory.
Services are checked for known vulnerabilities and weak configuration. Every candidate is verified by hand before it is reported.
Verified weaknesses are exploited under the rules of engagement to obtain a foothold and to prove impact.
From the foothold we move towards the agreed objectives, using the techniques catalogued in MITRE ATT&CK, and record each step.
Accounts, files and changes created during the test are removed and listed in the report.
03
04
05Standards
Planning, rules of engagement and conduct of technical testing.
NIST
PTESv1.0
Phases of an engagement, from pre-engagement to reporting.
PTES Team
Operational security testing of networks and channels.
ISECOM
Catalogue of adversary techniques used to plan operations and to report detection coverage.
The MITRE Corporation
Severity score and vector of every finding.
FIRST
06Questions
Yes. We connect through a VPN you provide or through a small device or virtual machine placed in your network. The starting position is the same as on site.
No. Techniques that risk availability are excluded by the rules of engagement or executed only in a window you approve. The purpose is to prove access, not to cause damage.
A scan lists possible weaknesses. A penetration test proves which of them can be used, combines them and shows where an attacker ends up. PCI DSS and other frameworks treat the two as separate requirements for that reason.
08Request
Reference
Keep the reference: we name it in all further communication with you.
We never ask for payment, passwords or remote access in the first reply.