Vantage Point Pentest

0 views
Skip to first unread message

Juanjo Pollreisz

unread,
Aug 3, 2024, 3:53:13 PM8/3/24
to cakoksomoun

We do this work not because we believe it is the best method of report delivery, but because we continue to serve an industry that mistakenly believes that a document is the best method to deliver security results. And since a document is the recognized standard for the final deliverable, consultancies try to differentiate themselves more in the sizzle of formatting than in the content of their reports.

But is the static report template really the thing differentiating one service provider from another? Are the formatting, branding, or even the different content included in the report really what separates a skilled, elite testing team from a lesser one? Are we delivering the value in the static document-based report that we think we are?

Our analysis clearly indicated that there are core components of technical testing reports with a high degree of adoption across the sample set. If one were to create a content framework from those data types that have > 50 percent adoption, it would look like this:

Maybe some testing organizations just have a greater degree of rigor around their testing and reporting. One may also point to differences in the consumer profile that these organizations are serving. However, we think the most likely root cause is that testing organizations are making trade-offs to address the fundamental limitation in document-based report delivery: signal-to-noise ratio.

Leaders of consulting and internal teams are forced to make subjective assessments as to whether any given data field provides enough value for enough consumers to offset the additional distraction that will inevitably be induced for some consumers. More often than not, testers will make the conservative decision to include additional data for fear of angering the minority of consumers who do believe the data is valuable. And this is why we have a communal archetype of the 300-page PDF report.

While the signal-to-noise problem may be the cardinal sin of document-based reporting, it is by no means the only one. In our interactions with report writers, we routinely hear a plethora of additional gripes with traditional document-based reporting:

We propose a new offensive testing primary deliverable: a dynamic report delivered electronically via web-based platform. An electronic report, not bound by a static document format, offers some obvious advantages. The information delivered can be easily tailored to the needs of every client, customers can access or interact with data throughout the testing process not just at the end, and, above all, the results are much more actionable.

Today we will review the various roles and responsibilities during a penetration test, from both the client and the Triaxiom vantage points. Every project is different and has its nuances, but for the sake of this article, we will assume that the project is a small external penetration test of 5 IP addresses for ACME, inc.

In this stylized example, we have detailed a pretty straightforward and small project. As a project increases in scope and/or complexity, more roles may be required such as a dedicated project manager, additional engineers, and various other client contacts such as developers, DBAs, etc. All parties play a vital role in ensuring the penetration test is executed to plan and on schedule. Ensuring that the roles and responsibilities are clearly defined throughout the project ensures clear lines of communication and no delays. For any project, the Rules of Engagement document we provide, review during the Project Initiation Meeting or Kick-Off Call, and have the client sign will contain all the relevant contact information.

Triaxiom is a PCI Certified Qualified Security Assessor (QSA) organization. As such, we are certified by the PCI Council to perform your QSA On Site Assessment for Level 1 Merchants or Service Providers. Our consultants have conducted countless PCI Compliance Assessments, filling out numerous Reports on Compliance and Self Assessment Questionnaires for organizations across a wide variety of industries.

Lower level merchants and service providers can leverage a Qualified Security Assessor (QSA) to assist them with determining their scope, what PCI requirements pertain to their organization, and assist with filling out their applicable Self Assessment Questionnaire (SAQ). Further, the SAQ will reflect that you had a QSA assist you, demonstrating to your clients and merchant bank that you had an unbiased third-party assess your compliance.

A formal risk assessment evaluates the threats to your organization, the vulnerabilities of your network, and the security controls you have in place to protect your network. A risk assessment correlates information from your security assessments and evaluates the overall risk to your organization to help drive strategic decisions.

Our best practice gap analysis is an interview based review of your information security program. We use the Center for Internet Security (CIS) Top 20 Critical Security Controls to comprehensively review all aspects of your information security program. Some of the areas covered include:

When you suspect you have been breached, knowing exactly how it happened and what was affected can be difficult to discern. Our certified engineers can assist you with the incident response process, ensuring the malware is removed and normal business operations are restored. Moreover, our root-cause analysis will attempt to determine how the breach was possible and steps to take to prevent it from happening again. Moreover, we will evaluate the malware including:

Comprehensive security policies written by security professionals. Our policies are designed to meet your compliance needs while optimizing your business requirements. Some of the policies we can help with include:

Developing a secure IoT solution depends on a number of security considerations. This assessment will evaluate the IoT device and its associated infrastructure against common attacks. It can include an evaluation of the edge device, the gateway, the cloud infrastructure, and/or any mobile applications. Our engineers will evaluate your IoT Device utilizing the OWASP IoT Framework Assessment methodology.

A firewall audit is a manual inspection of your firewall using the Center for Internet Security (CIS) benchmark and device-specific best practices. In addition, our engineer will review the firewall rules, searching for overly specific rules, proper rule sequencing, or other gaps in your security posture. Finally, the firewall audit will include network scanning to validate its effectiveness.

A host compliance audit involves the manual inspection of a workstation, server, or network device using the Center for Internet Security (CIS) benchmark and device-specific security best practices. This assessment will identify the security holes in your system and provide specific actions to take to harden the device.

Vulnerability scanning is a regular, automated process that identifies the potential points of compromise on a network. A vulnerability scan detects and classifies system weaknesses in computers, networks and communications equipment and predicts the effectiveness of countermeasures. Our engineers will conduct this scan for you and use our expertise to remove false positives and produce a risk-prioritized report.

A physical penetration test is an assessment of the physical security of your premises. Our engineers will attempt to gain access to your facility by identifying weaknesses and/or using social engineering. Once inside, our engineers will attempt to gather sensitive information, gain access to sensitive areas such as the data center, and attempt to gain internal network access.

An external penetration test emulates an attacker trying to break into your network from the outside. The goal of the engineer performing this assessment is to breach the perimeter and prove they have internal network access. This test includes:

An internal penetration test emulates an attacker on the inside of your network. This could be either an attacker who is successful in breaching the perimeter through another method or a malicious insider. The goal of the engineer in this module is to gain root and/or domain administrator level access on the network, and gain access to sensitive files. Activities include:

A web application penetration test is an in-depth penetration test on both the unauthenticated and authenticated portions of your website. The engineer will test for all of the OWASP Top-10 critical security flaws, as well as a variety of other potential vulnerabilities based on security best practice. Activities include:

Moonlighter will be part of Hack-A-Sat 4, an annual challenge supported by Aerospace, the U.S. Air Force, and the U.S. Space Force, where finalists will get the chance to hack the CubeSat in orbit during DEF CON, a convention for hackers held in August. With a growing space-based economy and increasing competition in the space environment, Myrick said Moonlighter is a critical tool for strengthening cyber security in space.

In addition to Moonlighter, five student-developed CubeSats are also launching on SpaceX CRS-28. These CubeSats are part of the Canadian CubeSat Project, which was created to increase student engagement in science, technology, engineering, and mathematics and prepare the future space industry workforce.

SpaceX CRS-28 is targeted for launch no earlier than June 3 at 12:35 p.m. EDT. This mission will include multiple ISS National Lab-sponsored payloads. To learn more about all ISS National Lab-sponsored research on this mission, please visit our launch page.

About the International Space Station (ISS) National Laboratory: The International Space Station (ISS) is a one-of-a-kind laboratory that enables research and technology development not possible on Earth. As a public service enterprise, the ISS National Lab allows researchers to leverage this multiuser facility to improve life on Earth, mature space-based business models, advance science literacy in the future workforce, and expand a sustainable and scalable market in low Earth orbit. Through this orbiting national laboratory, research resources on the space station are available to support non-NASA science, technology and education initiatives from U.S. government agencies, academic institutions, and the private sector. The Center for the Advancement of Science in Space, Inc. (CASIS) manages the ISS National Lab, under Cooperative Agreement with NASA, facilitating access to its permanent microgravity research environment, a powerful vantage point in low Earth orbit, and the extreme and varied conditions of space. To learn more about the ISS National Lab, visit www.ISSNationalLab.org.

c80f0f1006
Reply all
Reply to author
Forward
0 new messages