- Advanced Infrastructure Penetration Testing
- Chiheb Chebbi
- 249字
- 2021-06-24 19:12:51
Intelligence gathering
The intelligence gathering stage is when the pentester searches for all available information about the organization from public sources. At the end of this phase, he will have a clear view of the network (domain name, IP ranges, TCP/UDP services, and authentication mechanisms), the systems (user/group names, system banners, and system architecture), and organizational information (employee details, press releases, and location). It depends on the type of pentesting (black, white, or gray). Implementing a good intelligence gathering methodology will facilitate the work in later steps.
The fuel of intelligence gathering is to get publicly available information from different sources. Intelligence gathering is not important in information security and penetration testing, but it is vital for national security, and as many concepts are inspired by the military strategies, in the cyber security field intelligence gathering is also inspired by the battlefields. But in a penetration testing context, all the techniques in this phase should be legal because good intentions do not mean breaking the law, that is why, we said publicly available information. If it is not, the case will be considered as industrial espionage. According to International Trade Commission estimates, current annual losses to US industries due to corporate espionage to be over $70 billion.
Intelligence gathering not only helps improve the security position of the organization, but it gives managers an eagle eye on the competition, and it results in better business decisions. Basically every intelligence gathering operation basically is done following a structured methodology.
- pcDuino開發(fā)實戰(zhàn)
- Learning OpenDaylight
- Linux實戰(zhàn)
- Kali Linux滲透測試全流程詳解
- 開源安全運(yùn)維平臺OSSIM疑難解析:入門篇
- Application Development in iOS 7
- Linux服務(wù)器配置與管理
- INSTANT Galleria Howto
- 從實踐中學(xué)習(xí)Windows滲透測試
- Linux操作系統(tǒng)案例教程(第2版)
- OpenHarmony開發(fā)與實踐:基于紅莓RK2206開發(fā)板
- BuddyPress Theme Development
- Mastering Eclipse Plug-in Development
- Mastering AWS CloudFormation
- 從零開始學(xué)Windows 7