SlideShare a Scribd company logo
1 of 15
Module 2 – PenTest
Overview
 Penetration Testing Methodologies
 Penetration Test Management (ISSAF)
 PenTest Project Management
 Engineer Assessment Effort
Heorot.net
Penetration Testing
Methodologies
 ISSAF
○ http://www.oissg.org/issaf
 OSSTMM
○ http://www.isecom.org/osstmm/
 NIST SP 800-42
○ http://csrc.nist.gov/publications/PubsSPs.html
Heorot.net
Penetration Testing
Methodologies
 ISSAF
 Peer-Reviewed
 Contains two separate documents
○ Management (ISSAF0.2.1A)
○ Penetration Testing (ISSAF0.2.1B)
 Checklists for Auditing / Hardening Systems
 Tool-Centric
Heorot.net
Penetration Testing
Methodologies
 ISSAF
 Advantages
○ Does not assume previous knowledge
○ Provides examples of pentest tool use
○ “In the weeds”
 Disadvantages
○ Out of date quickly
○ Pentest tool examples are not extensive
○ Last update: May 2006
Heorot.net
Penetration Testing
Methodologies
 OSSTMM
 Peer-Reviewed
 Most popular methodology
 Assessments are discussed at a high-level
 Includes unique technology (RFID, Infrared)
 Extensive templates
Heorot.net
Penetration Testing
Methodologies
 OSSTMM
 Advantages
○ More flexibility for Pentesters
○ Frequent updates
 Disadvantages
○ Steeper learning curve
 Tool and OS knowledge necessary beforehand
○ Latest version requires paid subscription
Heorot.net
Penetration Testing
Methodologies
 NIST SP 800-42
 Federal Publication
 Least comprehensive methodology
 Tools-oriented
 NIST publications rarely get updated
 If you can't use anything else, at least use
something
Heorot.net
Penetration Test
Management
 ISSAF
 Phase I – Planning
 Phase II – Assessment
 Phase III – Treatment
 Phase IV – Accreditation
 Phase V – Maintenance
Use a Project Manager
Heorot.net
PenTest Project Management
 Phase I – Planning
 Information Gathering
 Project Chartering
 Resource Identification
 Budgeting
 Bidding & Estimating (Called “Cash Flow”)
 Work Breakdown Structure (WBS)
 Project Kick-Off
Heorot.net
PenTest Project Management
 Phase II – Assessment
 Inherent Risk Assessment
 Controls Assessment
○ Legal & Regulatory Compliance
○ Information Security Policy
○ Information Security Organization and Mgmt.
○ Enterprise Information Systems Security and
Controls  (Penetration Testing)
○ Security Operations Management
○ Business Continuity Management
Heorot.net
PenTest Project Management
 Phase III – Treatment
 See Risk Treatment Plan
 Phase IV – Accreditation
 Context Establishment
 Evaluation
 Reporting
 Certification
 Phase V – Maintenance
Heorot.net
PenTest Project Management
 Phase II – Assessment
 Inherent Risk Assessment
 Controls Assessment
○ Legal & Regulatory Compliance
○ Information Security Policy
○ ...etc.
Each assessment is broken down further...
Heorot.net
PenTest Project Management
 Phase II – Assessment
 Project Management Documents
○ Engagement Scope
○ Communications Plan
○ Issue Escalation Plan
○ Scheduling
○ Responsibility Matrix
○ Deliverables
Heorot.net
Engineer Assessment Effort
 Phase II – Assessment
 Scheduling (Engineering Effort)
○ Information Gathering
○ Network Mapping
○ Vulnerability Identification
○ Penetration
○ Gaining Access & Privilege Escalation
○ Enumerating Further
○ Compromise Remote Users/Sites
○ Maintaining Access
○ Cover the Tracks
Heorot.net
Module 2 – Conclusion
 Penetration Testing Methodologies
 Penetration Test Management (ISSAF)
 PenTest Project Management
 Engineer Assessment Effort
Heorot.net

More Related Content

Similar to Pentest

Corporate Public Investigations
Corporate Public InvestigationsCorporate Public Investigations
Corporate Public Investigations
CTIN
 
εξελιξη πληροφοριακων συστηματων στη διαχειρiση καινοτομιας
εξελιξη πληροφοριακων συστηματων στη διαχειρiση καινοτομιαςεξελιξη πληροφοριακων συστηματων στη διαχειρiση καινοτομιας
εξελιξη πληροφοριακων συστηματων στη διαχειρiση καινοτομιας
Manolis Vavalis
 
Roger Sloan Resume
Roger Sloan ResumeRoger Sloan Resume
Roger Sloan Resume
Roger Sloan
 
· THE INDUSTRY AND THE COMPANY AND ITS PRODUCT(S) OR SERVICE(S)A.docx
· THE INDUSTRY AND THE COMPANY AND ITS PRODUCT(S) OR SERVICE(S)A.docx· THE INDUSTRY AND THE COMPANY AND ITS PRODUCT(S) OR SERVICE(S)A.docx
· THE INDUSTRY AND THE COMPANY AND ITS PRODUCT(S) OR SERVICE(S)A.docx
oswald1horne84988
 
Project PlanGroup 2The Data Center Project PlanProj.docx
Project PlanGroup 2The Data Center Project PlanProj.docxProject PlanGroup 2The Data Center Project PlanProj.docx
Project PlanGroup 2The Data Center Project PlanProj.docx
briancrawford30935
 
08252016 John D Resume ITIL PMP CISSP CSM CISA1
08252016 John D Resume ITIL PMP CISSP CSM CISA108252016 John D Resume ITIL PMP CISSP CSM CISA1
08252016 John D Resume ITIL PMP CISSP CSM CISA1
jjdoylecomcast
 
Implementation Plan TemplateCMGT445 Version 61University .docx
Implementation Plan TemplateCMGT445 Version 61University .docxImplementation Plan TemplateCMGT445 Version 61University .docx
Implementation Plan TemplateCMGT445 Version 61University .docx
bradburgess22840
 

Similar to Pentest (20)

Rapid Software Development Process
Rapid Software Development ProcessRapid Software Development Process
Rapid Software Development Process
 
Corporate Public Investigations
Corporate Public InvestigationsCorporate Public Investigations
Corporate Public Investigations
 
εξελιξη πληροφοριακων συστηματων στη διαχειρiση καινοτομιας
εξελιξη πληροφοριακων συστηματων στη διαχειρiση καινοτομιαςεξελιξη πληροφοριακων συστηματων στη διαχειρiση καινοτομιας
εξελιξη πληροφοριακων συστηματων στη διαχειρiση καινοτομιας
 
Establishing An Enterprise and Project Management.pptx
Establishing An Enterprise and Project Management.pptxEstablishing An Enterprise and Project Management.pptx
Establishing An Enterprise and Project Management.pptx
 
Roger Sloan Resume
Roger Sloan ResumeRoger Sloan Resume
Roger Sloan Resume
 
OOAD - System Analysis and Design
OOAD - System Analysis and Design OOAD - System Analysis and Design
OOAD - System Analysis and Design
 
· THE INDUSTRY AND THE COMPANY AND ITS PRODUCT(S) OR SERVICE(S)A.docx
· THE INDUSTRY AND THE COMPANY AND ITS PRODUCT(S) OR SERVICE(S)A.docx· THE INDUSTRY AND THE COMPANY AND ITS PRODUCT(S) OR SERVICE(S)A.docx
· THE INDUSTRY AND THE COMPANY AND ITS PRODUCT(S) OR SERVICE(S)A.docx
 
Certified Red Team Physical Pentest.pdf
Certified Red Team Physical Pentest.pdfCertified Red Team Physical Pentest.pdf
Certified Red Team Physical Pentest.pdf
 
Enterprise Project Management Essential #3
Enterprise Project Management Essential #3Enterprise Project Management Essential #3
Enterprise Project Management Essential #3
 
Enterprise Architecture - An Introduction
Enterprise Architecture - An Introduction Enterprise Architecture - An Introduction
Enterprise Architecture - An Introduction
 
Sadchap02
Sadchap02Sadchap02
Sadchap02
 
ATT&CKing Threat Management
ATT&CKing Threat ManagementATT&CKing Threat Management
ATT&CKing Threat Management
 
Project PlanGroup 2The Data Center Project PlanProj.docx
Project PlanGroup 2The Data Center Project PlanProj.docxProject PlanGroup 2The Data Center Project PlanProj.docx
Project PlanGroup 2The Data Center Project PlanProj.docx
 
08252016 John D Resume ITIL PMP CISSP CSM CISA1
08252016 John D Resume ITIL PMP CISSP CSM CISA108252016 John D Resume ITIL PMP CISSP CSM CISA1
08252016 John D Resume ITIL PMP CISSP CSM CISA1
 
An Introduction to Project management(project management tutorials)
An Introduction to Project management(project management tutorials)An Introduction to Project management(project management tutorials)
An Introduction to Project management(project management tutorials)
 
New ways of working: Measuring the impacts on knowledge work productivity
New ways of working: Measuring the impacts on knowledge work productivityNew ways of working: Measuring the impacts on knowledge work productivity
New ways of working: Measuring the impacts on knowledge work productivity
 
Implementation Plan TemplateCMGT445 Version 61University .docx
Implementation Plan TemplateCMGT445 Version 61University .docxImplementation Plan TemplateCMGT445 Version 61University .docx
Implementation Plan TemplateCMGT445 Version 61University .docx
 
PMBOK_Slides.pdf
PMBOK_Slides.pdfPMBOK_Slides.pdf
PMBOK_Slides.pdf
 
Unit 1 DSS
Unit 1 DSSUnit 1 DSS
Unit 1 DSS
 
PMP Preparation - 06 Time Management
PMP Preparation - 06 Time ManagementPMP Preparation - 06 Time Management
PMP Preparation - 06 Time Management
 

Recently uploaded

pdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdfpdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
JOHNBEBONYAP1
 
Indian Escort in Abu DHabi 0508644382 Abu Dhabi Escorts
Indian Escort in Abu DHabi 0508644382 Abu Dhabi EscortsIndian Escort in Abu DHabi 0508644382 Abu Dhabi Escorts
Indian Escort in Abu DHabi 0508644382 Abu Dhabi Escorts
Monica Sydney
 
哪里办理美国迈阿密大学毕业证(本硕)umiami在读证明存档可查
哪里办理美国迈阿密大学毕业证(本硕)umiami在读证明存档可查哪里办理美国迈阿密大学毕业证(本硕)umiami在读证明存档可查
哪里办理美国迈阿密大学毕业证(本硕)umiami在读证明存档可查
ydyuyu
 
一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样
一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样
一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样
ayvbos
 
Russian Escort Abu Dhabi 0503464457 Abu DHabi Escorts
Russian Escort Abu Dhabi 0503464457 Abu DHabi EscortsRussian Escort Abu Dhabi 0503464457 Abu DHabi Escorts
Russian Escort Abu Dhabi 0503464457 Abu DHabi Escorts
Monica Sydney
 
Russian Call girls in Abu Dhabi 0508644382 Abu Dhabi Call girls
Russian Call girls in Abu Dhabi 0508644382 Abu Dhabi Call girlsRussian Call girls in Abu Dhabi 0508644382 Abu Dhabi Call girls
Russian Call girls in Abu Dhabi 0508644382 Abu Dhabi Call girls
Monica Sydney
 
一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制
一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制
一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制
pxcywzqs
 
PowerDirector Explination Process...pptx
PowerDirector Explination Process...pptxPowerDirector Explination Process...pptx
PowerDirector Explination Process...pptx
galaxypingy
 

Recently uploaded (20)

pdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdfpdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
 
2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs
2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs
2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs
 
Indian Escort in Abu DHabi 0508644382 Abu Dhabi Escorts
Indian Escort in Abu DHabi 0508644382 Abu Dhabi EscortsIndian Escort in Abu DHabi 0508644382 Abu Dhabi Escorts
Indian Escort in Abu DHabi 0508644382 Abu Dhabi Escorts
 
哪里办理美国迈阿密大学毕业证(本硕)umiami在读证明存档可查
哪里办理美国迈阿密大学毕业证(本硕)umiami在读证明存档可查哪里办理美国迈阿密大学毕业证(本硕)umiami在读证明存档可查
哪里办理美国迈阿密大学毕业证(本硕)umiami在读证明存档可查
 
best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...
best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...
best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...
 
一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样
一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样
一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样
 
Russian Escort Abu Dhabi 0503464457 Abu DHabi Escorts
Russian Escort Abu Dhabi 0503464457 Abu DHabi EscortsRussian Escort Abu Dhabi 0503464457 Abu DHabi Escorts
Russian Escort Abu Dhabi 0503464457 Abu DHabi Escorts
 
Power point inglese - educazione civica di Nuria Iuzzolino
Power point inglese - educazione civica di Nuria IuzzolinoPower point inglese - educazione civica di Nuria Iuzzolino
Power point inglese - educazione civica di Nuria Iuzzolino
 
20240509 QFM015 Engineering Leadership Reading List April 2024.pdf
20240509 QFM015 Engineering Leadership Reading List April 2024.pdf20240509 QFM015 Engineering Leadership Reading List April 2024.pdf
20240509 QFM015 Engineering Leadership Reading List April 2024.pdf
 
Russian Call girls in Abu Dhabi 0508644382 Abu Dhabi Call girls
Russian Call girls in Abu Dhabi 0508644382 Abu Dhabi Call girlsRussian Call girls in Abu Dhabi 0508644382 Abu Dhabi Call girls
Russian Call girls in Abu Dhabi 0508644382 Abu Dhabi Call girls
 
一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制
一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制
一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制
 
Best SEO Services Company in Dallas | Best SEO Agency Dallas
Best SEO Services Company in Dallas | Best SEO Agency DallasBest SEO Services Company in Dallas | Best SEO Agency Dallas
Best SEO Services Company in Dallas | Best SEO Agency Dallas
 
APNIC Policy Roundup, presented by Sunny Chendi at the 5th ICANN APAC-TWNIC E...
APNIC Policy Roundup, presented by Sunny Chendi at the 5th ICANN APAC-TWNIC E...APNIC Policy Roundup, presented by Sunny Chendi at the 5th ICANN APAC-TWNIC E...
APNIC Policy Roundup, presented by Sunny Chendi at the 5th ICANN APAC-TWNIC E...
 
Microsoft Azure Arc Customer Deck Microsoft
Microsoft Azure Arc Customer Deck MicrosoftMicrosoft Azure Arc Customer Deck Microsoft
Microsoft Azure Arc Customer Deck Microsoft
 
Real Men Wear Diapers T Shirts sweatshirt
Real Men Wear Diapers T Shirts sweatshirtReal Men Wear Diapers T Shirts sweatshirt
Real Men Wear Diapers T Shirts sweatshirt
 
Nagercoil Escorts Service Girl ^ 9332606886, WhatsApp Anytime Nagercoil
Nagercoil Escorts Service Girl ^ 9332606886, WhatsApp Anytime NagercoilNagercoil Escorts Service Girl ^ 9332606886, WhatsApp Anytime Nagercoil
Nagercoil Escorts Service Girl ^ 9332606886, WhatsApp Anytime Nagercoil
 
APNIC Updates presented by Paul Wilson at ARIN 53
APNIC Updates presented by Paul Wilson at ARIN 53APNIC Updates presented by Paul Wilson at ARIN 53
APNIC Updates presented by Paul Wilson at ARIN 53
 
PowerDirector Explination Process...pptx
PowerDirector Explination Process...pptxPowerDirector Explination Process...pptx
PowerDirector Explination Process...pptx
 
20240510 QFM016 Irresponsible AI Reading List April 2024.pdf
20240510 QFM016 Irresponsible AI Reading List April 2024.pdf20240510 QFM016 Irresponsible AI Reading List April 2024.pdf
20240510 QFM016 Irresponsible AI Reading List April 2024.pdf
 
20240507 QFM013 Machine Intelligence Reading List April 2024.pdf
20240507 QFM013 Machine Intelligence Reading List April 2024.pdf20240507 QFM013 Machine Intelligence Reading List April 2024.pdf
20240507 QFM013 Machine Intelligence Reading List April 2024.pdf
 

Pentest

  • 1. Module 2 – PenTest Overview  Penetration Testing Methodologies  Penetration Test Management (ISSAF)  PenTest Project Management  Engineer Assessment Effort Heorot.net
  • 2. Penetration Testing Methodologies  ISSAF ○ http://www.oissg.org/issaf  OSSTMM ○ http://www.isecom.org/osstmm/  NIST SP 800-42 ○ http://csrc.nist.gov/publications/PubsSPs.html Heorot.net
  • 3. Penetration Testing Methodologies  ISSAF  Peer-Reviewed  Contains two separate documents ○ Management (ISSAF0.2.1A) ○ Penetration Testing (ISSAF0.2.1B)  Checklists for Auditing / Hardening Systems  Tool-Centric Heorot.net
  • 4. Penetration Testing Methodologies  ISSAF  Advantages ○ Does not assume previous knowledge ○ Provides examples of pentest tool use ○ “In the weeds”  Disadvantages ○ Out of date quickly ○ Pentest tool examples are not extensive ○ Last update: May 2006 Heorot.net
  • 5. Penetration Testing Methodologies  OSSTMM  Peer-Reviewed  Most popular methodology  Assessments are discussed at a high-level  Includes unique technology (RFID, Infrared)  Extensive templates Heorot.net
  • 6. Penetration Testing Methodologies  OSSTMM  Advantages ○ More flexibility for Pentesters ○ Frequent updates  Disadvantages ○ Steeper learning curve  Tool and OS knowledge necessary beforehand ○ Latest version requires paid subscription Heorot.net
  • 7. Penetration Testing Methodologies  NIST SP 800-42  Federal Publication  Least comprehensive methodology  Tools-oriented  NIST publications rarely get updated  If you can't use anything else, at least use something Heorot.net
  • 8. Penetration Test Management  ISSAF  Phase I – Planning  Phase II – Assessment  Phase III – Treatment  Phase IV – Accreditation  Phase V – Maintenance Use a Project Manager Heorot.net
  • 9. PenTest Project Management  Phase I – Planning  Information Gathering  Project Chartering  Resource Identification  Budgeting  Bidding & Estimating (Called “Cash Flow”)  Work Breakdown Structure (WBS)  Project Kick-Off Heorot.net
  • 10. PenTest Project Management  Phase II – Assessment  Inherent Risk Assessment  Controls Assessment ○ Legal & Regulatory Compliance ○ Information Security Policy ○ Information Security Organization and Mgmt. ○ Enterprise Information Systems Security and Controls  (Penetration Testing) ○ Security Operations Management ○ Business Continuity Management Heorot.net
  • 11. PenTest Project Management  Phase III – Treatment  See Risk Treatment Plan  Phase IV – Accreditation  Context Establishment  Evaluation  Reporting  Certification  Phase V – Maintenance Heorot.net
  • 12. PenTest Project Management  Phase II – Assessment  Inherent Risk Assessment  Controls Assessment ○ Legal & Regulatory Compliance ○ Information Security Policy ○ ...etc. Each assessment is broken down further... Heorot.net
  • 13. PenTest Project Management  Phase II – Assessment  Project Management Documents ○ Engagement Scope ○ Communications Plan ○ Issue Escalation Plan ○ Scheduling ○ Responsibility Matrix ○ Deliverables Heorot.net
  • 14. Engineer Assessment Effort  Phase II – Assessment  Scheduling (Engineering Effort) ○ Information Gathering ○ Network Mapping ○ Vulnerability Identification ○ Penetration ○ Gaining Access & Privilege Escalation ○ Enumerating Further ○ Compromise Remote Users/Sites ○ Maintaining Access ○ Cover the Tracks Heorot.net
  • 15. Module 2 – Conclusion  Penetration Testing Methodologies  Penetration Test Management (ISSAF)  PenTest Project Management  Engineer Assessment Effort Heorot.net