Penetration testing (pen testing) is a simulated cyberattack that organizations use to identify and fix security vulnerabilities in their systems and networks. A critical part of any cybersecurity program, pen testing can help prevent costly and devastating data breaches.
Steps of Penetration Testing
The pen testing process typically consists of the following steps:
Penetration testing, also known as pen testing or ethical hacking, is a process of simulating an attack on a computer system, network, or web application to detect security flaws. The objective of this exercise is to detect and exploit vulnerabilities before a threat actor can do so, wreaking incalculable harm to your business.
The steps of penetration testing can be broken down into five main phases:
Ø Reconnaissance:
Ø Scanning
Ø Vulnerability assessment
Ø Exploitation
Ø Reporting
There are a few other important steps involved in penetration testing, such as planning, communication, and follow-up.
Penetration Testing Methodology
External testing
With the goal of gaining access and extracting valuable data, external penetration tests target the assets of a company that are visible on the internet, such as the web application, the company website, and email and domain name servers (DNS).
Internal testing
An application that is accessible through a firewall is tested internally by a tester who impersonates a hostile insider. It's not always the same as modelling a wayward employee. An employee whose credentials were compromised by phishing is a typical place to start.
Blind testing
A tester in a blind test is merely provided with the name of the targeted organization. This provides security personnel with an immediate view of how an actual application assault would go.
Double-blind testing
In a double-blind test, the simulated attack is unknown to the security staff in advance. They won't have time to strengthen their defenses before an attempted breach, much like in the real world.
Targeted testing
Here, security staff members and the tester collaborate and communicate with one another on their whereabouts. This is an excellent training exercise that gives a security team instant feedback from the perspective of a hacker.
Penetration Testing Checklist
The following is a general checklist of the steps involved in a penetration test:
Planning and reconnaissance
- Define the scope and goals of the test.
- Identify the target systems and networks.
- Gather intelligence on the target systems and networks.
- Develop a test plan.
Scanning
- Use automated tools to scan for vulnerabilities.
- Use manual tools to scan for vulnerabilities.
Vulnerability assessment
- Assess the severity and risk level of each vulnerability.
- Prioritize the vulnerabilities for remediation.
Exploitation
- Exploit the vulnerabilities that have been identified.
- Document the impact of the exploited vulnerabilities
Reporting
- Generate a report that documents the findings of the pentest.
- Include a list of the vulnerabilities that were found, their severity and risk level, and recommendations for remediation.
Conclusion
To say that penetration testing is the cornerstone of any cybersecurity program is not wrong. If organizations follow the steps outlined in this blog, they can detect and remediate security vulnerabilities in their systems and networks before attackers find a chink in the armor and inflict untold damage.
[출처] https://www.linkedin.com/pulse/penetration-testing-process-step-by-step-guide-amsatcyber-vdfif/



