官术网_书友最值得收藏!

Enumerating your findings

Now that we have just finished using a bunch of information gathering tools to map out, probe, and discover the infrastructure we are working with, let us take that information and enumerate it into a logical and more structured documentation. We can then merge this information with the data we obtained from both the stakeholders meeting and the team interviews to create a solid documentation pack that will almost always guarantee us success in the upcoming phases of the penetration test. This information that we created will be included within the finalized penetration report not only to help present our findings, but also to verify what the organization currently has documented. Many times I have presented documents that were either more detailed than what the organization currently had, were newer than what they had, or just more complete. The more value we as penetration testers can show, the more times we will be called back for future engagements.

Organization is key to a successful project. The tools you use provide lots of great information of all types about the network and systems. When enumerating that information from various tools, make sure to keep items organized by some structure. This could be by system type or by information type; that decision is up to you. But you don't want to lose or miss valuable information because it was not where it should have been in your documentation.
主站蜘蛛池模板: 南京市| 无锡市| 苏尼特右旗| 英德市| 怀来县| 涪陵区| 洪雅县| 石阡县| 左贡县| 营山县| 平江县| 安阳市| 弋阳县| 济南市| 东乡| 简阳市| 九龙坡区| 徐水县| 洛浦县| 石林| 富平县| 弥渡县| 海宁市| 宁晋县| 天等县| 江山市| 巴塘县| 浮山县| 太和县| 永善县| 衡水市| 文成县| 海晏县| 新沂市| 星子县| 渝中区| 勐海县| 青田县| 新安县| 自治县| 九龙县|