1.8 Explain the techniques used in penetration testing Flashcards
White box
Known environment
Black box
Unknown environment
Gray box
Partially known environment
Rules of engagement (RoE)
PenTesting document defining means and manner which testing is to be performed/conducted.
-Include specifics on scope, types of tests, and depth/extent of testing
Lateral movement
When a pivot is successful and attacker gains level of remote control over another system
Persistence
Long-term access maintaining
Pivoting
Focus attack efforts on a new target once initial breach is successful
Exercise types
Red team
-Attackers in pentest exercise
Blue team
-Defenders pentest exercise
White team
-Referee
-Establish guidelines, RoE, etc.
Purple team
-A single team performing offensive and defensive penetration testing