Pre-Engagement

Preparation for actual penetration test. Consists of

  • Scoping questionnaire.
  • Pre-engagement meeting
  • Kick-off meeting.

Before all these are discussed a Non-Disclosure Agreement must be signed. There exists a couple of types

TypeDescription
Unilateral NDAThis type of NDA obligates only one party to maintain confidentiality and allows the other party to share the information received with third parties.
Bilateral NDAIn this type, both parties are obligated to keep the resulting and acquired information confidential. This is the most common type of NDA that protects the work of penetration testers.
Multilateral NDAMultilateral NDA is a commitment to confidentiality by more than two parties. If we conduct a penetration test for a cooperative network, all parties responsible and involved must sign this document.
We must also present certain documents to be signed so that we have consent.
DocumentTiming for Creation
1. Non-Disclosure Agreement (NDA)After Initial Contact
2. Scoping QuestionnaireBefore the Pre-Engagement Meeting
3. Scoping DocumentDuring the Pre-Engagement Meeting
4. Penetration Testing Proposal (Contract/Scope of Work (SoW))During the Pre-engagement Meeting
5. Rules of Engagement (RoE)Before the Kick-Off Meeting
6. Contractors Agreement (Physical Assessments)Before the Kick-Off Meeting
7. ReportsDuring and after the conducted Penetration Test

Should be validated by a lawyer after they have been prepared.

Scoping Questionnaire

Clearly explains our services and may ask them to choose one of them. This questionnaire should also detail

  • How many expected live hosts?
  • How many IPs/CIDR ranges in scope?
  • How many Domains/Subdomains are in scope?
  • How many wireless SSIDs in scope?
  • How many web/mobile applications? If testing is authenticated, how many roles (standard user, admin, etc.)?
  • For a phishing assessment, how many users will be targeted? Will the client provide a list, or we will be required to gather this list via OSINT?
  • If the client is requesting a Physical Assessment, how many locations? If multiple sites are in-scope, are they geographically dispersed?
  • What is the objective of the Red Team Assessment? Are any activities (such as phishing or physical security attacks) out of scope?
  • Is a separate Active Directory Security Assessment desired?
  • Will network testing be conducted from an anonymous user on the network or a standard domain user?
  • Do we need to bypass Network Access Control (NAC)?

All this information will be summarized in the Scoping Document.

Pre-Engagement Meeting

DIscuss all relevant and essential components with the customer before the pentest to form a penetration testing proposal, or a contract or Scope of Work. Contract checklist:

CheckpointDescription
☐ NDANon-Disclosure Agreement (NDA) refers to a secrecy contract between the client and the contractor regarding all written or verbal information concerning an order/project. The contractor agrees to treat all confidential information brought to its attention as strictly confidential, even after the order/project is completed. Furthermore, any exceptions to confidentiality, the transferability of rights and obligations, and contractual penalties shall be stipulated in the agreement. The NDA should be signed before the kick-off meeting or at the latest during the meeting before any information is discussed in detail.
☐ GoalsGoals are milestones that must be achieved during the order/project. In this process, goal setting is started with the significant goals and continued with fine-grained and small ones.
☐ ScopeThe individual components to be tested are discussed and defined. These may include domains, IP ranges, individual hosts, specific accounts, security systems, etc. Our customers may expect us to find out one or the other point by ourselves. However, the legal basis for testing the individual components has the highest priority here.
☐ Penetration Testing TypeWhen choosing the type of penetration test, we present the individual options and explain the advantages and disadvantages. Since we already know the goals and scope of our customers, we can and should also make a recommendation on what we advise and justify our recommendation accordingly. Which type is used in the end is the client’s decision.
☐ MethodologiesExamples: OSSTMM, OWASP, automated and manual unauthenticated analysis of the internal and external network components, vulnerability assessments of network components and web applications, vulnerability threat vectorization, verification and exploitation, and exploit development to facilitate evasion techniques.
☐ Penetration Testing LocationsExternal: Remote (via secure VPN) and/or Internal: Internal or Remote (via secure VPN)
☐ Time EstimationFor the time estimation, we need the start and end dates for the penetration test. This provides a precise time window to perform the test and helps us plan our procedure. It is also vital to explicitly determine the duration of the time windows for each phase of the attack, such as Exploitation, Post-Exploitation, and Lateral Movement. These can be carried out during or outside regular working hours. When testing outside regular working hours, the focus is more on the security solutions and systems that should withstand our attacks.
☐ Third PartiesFor the third parties, it must be determined via which third-party providers our customer obtains services. These can be cloud providers, ISPs, and other hosting providers. Our client must obtain written consent from these providers describing that they agree and are aware that certain parts of their service will be subject to a simulated hacking attack. It is also highly advisable to require the contractor to forward the third-party permission sent to us so that we have actual confirmation that this permission has indeed been obtained.
☐ Evasive TestingEvasive testing is the test of evading and passing security traffic and security systems in the customer’s infrastructure. We look for techniques that allow us to find out information about the internal components and attack them. It depends on whether our contractor wants us to use such techniques or not.
☐ RisksWe must also inform our client about the risks involved in the tests and the possible consequences. Based on the risks and their potential severity, we can then set the limitations together and take certain precautions.
☐ Scope Limitations & RestrictionsIt is also essential to determine which servers, workstations, or other network components are essential for the client’s proper functioning and its customers. We will have to avoid these and must not influence them any further, as this could lead to critical technical errors that could also affect our client’s customers in production.
☐ Information HandlingHIPAA, PCI, HITRUST, FISMA/NIST, etc.
☐ Contact InformationFor the contact information, we need to create a list of each person’s name, title, job title, e-mail address, phone number, office phone number, and an escalation priority order.
☐ Lines of CommunicationIt should also be documented which communication channels are used to exchange information between the customer and us. This may involve e-mail correspondence, telephone calls, or personal meetings.
☐ ReportingApart from the report’s structure, any customer-specific requirements the report should contain are also discussed. In addition, we clarify how the reporting is to take place and whether a presentation of the results is desired.
☐ Payment TermsFinally, prices and the terms of payment are explained.

Based on the Contract checkist and the information shared in scoping, the Penetration Testing Proposal and the Rules of Engagement are created. Here is a checklist.

CheckpointContents
☐ IntroductionDescription of this document.
☐ ContractorCompany name, contractor full name, job title.
☐ Penetration TestersCompany name, pentesters full name.
☐ Contact InformationMailing addresses, e-mail addresses, and phone numbers of all client parties and penetration testers.
☐ PurposeDescription of the purpose for the conducted penetration test.
☐ GoalsDescription of the goals that should be achieved with the penetration test.
☐ ScopeAll IPs, domain names, URLs, or CIDR ranges.
☐ Lines of CommunicationOnline conferences or phone calls or face-to-face meetings, or via e-mail.
☐ Time EstimationStart and end dates.
☐ Time of the Day to TestTimes of the day to test.
☐ Penetration Testing TypeExternal/Internal Penetration Test/Vulnerability Assessments/Social Engineering.
☐ Penetration Testing LocationsDescription of how the connection to the client network is established.
☐ MethodologiesOSSTMM, PTES, OWASP, and others.
☐ Objectives / FlagsUsers, specific files, specific information, and others.
☐ Evidence HandlingEncryption, secure protocols
☐ System BackupsConfiguration files, databases, and others.
☐ Information HandlingStrong data encryption
☐ Incident Handling and ReportingCases for contact, pentest interruptions, type of reports
☐ Status MeetingsFrequency of meetings, dates, times, included parties
☐ ReportingType, target readers, focus
☐ RetestingStart and end dates
☐ Disclaimers and Limitation of LiabilitySystem damage, data loss
☐ Permission to TestSigned contract, contractors agreement

Kick-Off Meeting

After signing all contractual documents, where all parties concerned will go over how the test will take place. Usually, no Denial of Service testing is done.

During an external pentest if a critical vulnerability is identified, the pentest will be paused and a vulnerability notification will be generated.

During an internal pentest, we would alert the client if a system becomes unresponsive, we find evidence of illegal activity or the presence of an external threat actor in the network has been found.

Pentests may leave log entries and alarms, may lock some users or even negatively impact their network.

Contractors Agreeement

If physical pentesting is involved, an additional contractors agreement is required. Completely different laws apply here. This agreement involves

Checkpoint
☐ Introduction
☐ Contractor
☐ Purpose
☐ Goal
☐ Penetration Testers
☐ Contact Information
☐ Physical Addresses
☐ Building Name
☐ Floors
☐ Physical Room Identifications
☐ Physical Components
☐ Timeline
☐ Notarization
☐ Permission to Test

Information Gathering

OSINT

Process for finding publicly available information on a target company or individuals.

Infrastructure Enumeration

Try to overview the company’s position on the internet and intranet. Develop an understanding of how their infrastructure is structued. Determine the company’s security measures.

Service Enumeration

Identify services that allow us to interact with the host or server over the network. Find what version and what information it provides to us.

Host Enumeration

Identify which OS is running on the host or server, which services it uses, versions, etc.

Vulnerability Assessment

Types of analyses.

Analysis TypeDescription
DescriptiveDescriptive analysis is essential in any data analysis. On the one hand, it describes a data set based on individual characteristics. It helps to detect possible errors in data collection or outliers in the data set.
DiagnosticDiagnostic analysis clarifies conditions’ causes, effects, and interactions. Doing so provides insights that are obtained through correlations and interpretation. We must take a backward-looking view, similar to descriptive analysis, with the subtle difference that we try to find reasons for events and developments.
PredictiveBy evaluating historical and current data, predictive analysis creates a predictive model for future probabilities. Based on the results of descriptive and diagnostic analyses, this method of data analysis makes it possible to identify trends, detect deviations from expected values at an early stage, and predict future occurrences as accurately as possible.
PrescriptivePrescriptive analytics aims to narrow down what actions to take to eliminate or prevent a future problem or trigger a specific activity or process.