How to Prepare for Your External Pentest

How to Prepare for Your External Pentest
Share:

Scheduling a penetration test means you are not waiting around for a breach to tell you where security gaps might exist within your environment. However, what a lot of organizations do not realize is that the preparation and communication before a network penetration test is just as important as the testing itself.

External Penetration Test

An external penetration tests internet-facing assets to look for vulnerabilities from the perspective of an attacker. This also includes Open-Source Intelligence (OSINT) by gathering publicly available information about your organization to analyze what could be learned about your company without ever touching the network.

Pre-Engagement Requirements

Kick-off (KO) calls provide value not only to your organization but also to the consultant you will be working with and who will be conducting the testing. A poorly prepared engagement can lead to issues arising such as scope confusion, delays in testing and missing findings. So here are two pre-engagement items that will help ensure a successful call.

Know Your Scope Before the Attacker Does

Knowing what and where your external assets are makes a huge difference when deciding what to consider in scope for the engagement. Start by building an asset inventory that includes all public-facing IP addresses that you want to test against and think about what your goal is for the assessment. If you're unsure of your full scope, that is fine, but it is not something you should be trying to figure out the day before testing begins.

Use your kickoff (KO) call with the team as an opportunity to ask questions. A finalized scope is required at least one week before testing begins, so there is enough time to properly validate scope and start testing on time.

The Fellowship of the Informed

Communication is important at every stage of the engagement. Having a designated point of contact on your side is essential for keeping the engagement running smoothly. Whether it's a connection issue preventing the consultant from reaching in-scope assets, or a critical vulnerability that requires immediate attention, you want someone available who can respond in a timely manner. Without a direct point of contact, small issues can stall the engagement leading to delays or testing dates being shifted.

You should have one main point of contact and a secondary if the consultant cannot reach the first individual. But that does not mean you can't include other team members who need to be informed of the active testing to the KO call or email communications.

External Penetration Breakdown

Understanding what happens during the engagement is a good way to also know your scope when looking at what public facing assets you want to tested. An external penetration test follows a structured methodology that moves through several distinct phases of testing. We have broken testing into 4 areas to highlight the key testing phases in a non-exhaustive manner.

High-Level Phases of Testing

Reconnaissance: We gather information about your environment from external sources using Open-Source Intelligence (OSINT) techniques. This includes collecting client information that could be leveraged in later phases of testing.

Discovery: Manual and automated scanning is performed against in-scope hosts to identify open ports and service. Mapping the network to create a broad picture of the attack surface.

Validation & Exploitation: Potential vulnerabilities identified are validated to remove false positives before leveraging them to attempt gaining unauthorized access. Unless it is an explicit part of the scope, denial-of-service (DoS) exploitation should not be performed, as the goal is to avoid any disruption of day-to-day business operations.

Reporting: Everything discovered throughout the engagement is documented in a detailed report, including vulnerabilities, exploitation paths, remediation recommendations, and narrative. Which is a step-by-step first-person account of the testing engagement.

Reading Your Report and Prioritizing Remediation

Reports are a big part of testing as they bring everything together detailing vulnerabilities and the impact they have on your organization. However, Secure Ideas does not just provide you with findings but also a detailed narrative. The narrative includes network discovery, service enumeration, OSINT, and expanded detail on vulnerabilities creating a story of your network and overall security posture.

When reviewing your report Secure Ideas recommends prioritizing any Critical or High vulnerabilities for remediation, However, it should be notated that if any critical vulnerabilities are identified during testing, the consultant assigned to the project will reach out to bring them to your attention.

Ready to schedule your external penetration test?

Our team will walk you through scoping, scheduling, and everything you need to prepare. The kick-off call is where it all starts.

Get Started