Every engagement begins by defining testing objectives, scope, and access for the pen testing team. Depending on the engagement, testers may receive user accounts, limited admin access, architecture information, application documentation, or other approved resources.
Our team of ethical hackers will evaluate authentication controls, authorization mechanisms, privilege management processes, network segmentation, application security controls, cloud environments, APIs, and trust relationships between systems. We attempt to identify weaknesses that could allow an attacker to escalate privileges, move laterally, access sensitive data, or bypass security controls.
Where appropriate, vulnerabilities are safely exploited to validate risk and determine the potential impact on business operations. Testing is conducted in accordance with agreed-upon rules of engagement to minimize operational disruption.
After testing, you get a detailed report with executive summaries, technical findings, risk ratings, attack scenarios, and steps to fix any issues.
Below are the exact steps in a typical gray box penetration test:
- Define the scope: Tanner and the client work together to identify the systems, applications, accounts, networks, cloud environments, and testing goals.
- Establish the tester’s starting point: The client shares the agreed amount of information or access, such as limited credentials, network details, application documents, or architecture information.
- Perform reconnaissance and enumeration: The testing team looks for systems, services, relationships, permissions, and possible ways an attacker could get in.
- Identify vulnerabilities: Tanner uses both automated tools and manual testing to find weaknesses.
- Attempt exploitation: If allowed by the rules, testers try to exploit the vulnerabilities to see what impact they could have in real situations.
- Test privilege escalation and lateral movement: The team checks if an attacker could use their first access to gain more privileges or reach other systems.
- Document findings and attack paths: Tanner explains each vulnerability and shows how they could work together to create a serious security risk.
- Provide remediation guidance: The final report highlights the most important findings and gives the client clear steps to lower their risk.