官术网_书友最值得收藏!

Intelligence gathering

The intelligence gathering stage is when the pentester searches for all available information about the organization from public sources. At the end of this phase, he will have a clear view of the network (domain name, IP ranges, TCP/UDP services, and authentication mechanisms), the systems (user/group names, system banners, and system architecture), and organizational information (employee details, press releases, and location). It depends on the type of pentesting (black, white, or gray). Implementing a good intelligence gathering methodology will facilitate the work in later steps.

The fuel of intelligence gathering is to get publicly available information from different sources. Intelligence gathering is not important in information security and penetration testing, but it is vital for national security, and as many concepts are inspired by the military strategies, in the cyber security field intelligence gathering is also inspired by the battlefields. But in a penetration testing context, all the techniques in this phase should be legal because good intentions do not mean breaking the law, that is why, we said publicly available information. If it is not, the case will be considered as industrial espionage. According to International Trade Commission estimates, current annual losses to US industries due to corporate espionage to be over $70 billion.

Intelligence gathering not only helps improve the security position of the organization, but it gives managers an eagle eye on the competition, and it results in better business decisions. Basically every intelligence gathering operation basically is done following a structured methodology.

主站蜘蛛池模板: 大同市| 临湘市| 禹城市| 恩施市| 隆尧县| 城步| 绥宁县| 张家口市| 雅江县| 开封市| 两当县| 怀集县| 手游| 济南市| 隆子县| 分宜县| 赫章县| 沙河市| 河南省| 金堂县| 弥渡县| 高尔夫| 米脂县| 嘉荫县| 穆棱市| 灵石县| 绥中县| 德惠市| 宜宾县| 那曲县| 济源市| 嘉荫县| 广元市| 连江县| 象山县| 星座| 台东县| 陆良县| 桐庐县| 涞源县| 营山县|