Penetration testing (Pentest)
General information about pentests
Penetration testing prevents economic and reputational losses by verifying or building effective information protection for the company.
Testing reveals and checks system vulnerabilities that can occur due to software and hardware errors, improper settings and operational flaws, etc. Testing also clearly demonstrates the relevance of identified vulnerabilities and significance of potential damage for the client company.
What you get from the pentest service:
Pentest stages
Initialization
Stage outcomes:
● A working group is formed and approved
● The scope and parameters of testing, possible risks and limitations, a work schedule, and communication regulations are defined and approved
Data collection from open sources of information (passive collection of information)
Stage outcomes:
A non-interactive study of the infrastructure to be tested has been performed. Information about this infrastructure has been collected from open sources and systematized. Preparations have been made for the active information collection stage.
Active collection of information
Instrumental analysis of external perimeter security for the IP address ranges from:
● Resource detection
● Vulnerability detection
● Vulnerability analysis
● Access (checking for vulnerabilities)
Analysis of results and reporting
Stage outcomes:
A documented report containing identified vulnerabilities, results and vulnerability relevance, as well as recommendations for managing risks associated with identified vulnerabilities.
Demonstration and discussion of results
Stage outcome:
A documented report containing identified vulnerabilities, results and vulnerability relevance, as well as recommendations for managing risks associated with identified vulnerabilities.
