{"id":11856,"date":"2017-08-24T13:25:21","date_gmt":"2017-08-24T13:25:21","guid":{"rendered":"https:\/\/www.process.st\/templates\/penetration-testing\/"},"modified":"2024-02-28T20:45:51","modified_gmt":"2024-02-28T20:45:51","slug":"penetration-testing","status":"publish","type":"post","link":"https:\/\/www.process.st\/templates\/penetration-testing\/","title":{"rendered":"Penetration Testing"},"content":{"rendered":"<section id=\"introduction-to-penetration-testing\">\n<h2> Introduction to Penetration Testing: <\/h2>\n<div class=\"image-content\">\n<figure>\n   <a href=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/uQPo6GyJuKslDsGiYlZIHA.png\" alt=\"Penetration Testing - Process Street\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/uQPo6GyJuKslDsGiYlZIHA.png\" \/> <\/a><figcaption>\n     Penetration Testing - Process Street<br \/>\n   <\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"text-content\">\n<p>This <a href=\"https:\/\/www.process.st\" rel=\"nofollow noopener\" target=\"_blank\">Process Street<\/a> penetration testing checklist is engineered to give <strong>a documentation process for staff carrying out penetration testing<\/strong> on either their own networks and services or those of a client.&nbsp;<\/p>\n<p>Penetration testing is <strong>a method of locating vulnerabilities of information systems<\/strong> by playing the character of a cracker. The goal of the tester is to enter into a system and then burrow in as deep as possible. The deeper the tester can embed themselves and the more permanent their access can be, the more damage they can cause. A thorough pen-test aims to<strong> reveal these weaknesses so they can be closed as quickly as possible<\/strong> without having a real cracker expose them.&nbsp;<\/p>\n<p>This Process Street template aims to follow a standard pen-testing process, however, if there are further steps you wish to add or remove you are free to do so. You can simply add this template to your account and click to edit the template. The template is fully editable in order to meet the specific needs of your company.&nbsp;<\/p>\n<p>Throughout the template you will notice form fields where you can enter information as you run the checklist. All data entered into these form fields is stored in the <a href=\"https:\/\/www.process.st\/help\/docs\/template-overview\/\" rel=\"nofollow noopener\" target=\"_blank\">template overview<\/a> tab in a spreadsheet format. This data can then be exported as a CSV if you wish to keep an internal backup. You can add or remove form fields from the process in order to change the kind of data you're collecting.<\/p>\n<p>If you want to hear a little more about penetration testing, <strong>check out the video below<\/strong>:<\/p>\n<\/p><\/div>\n<div class=\"video-content\">\n<div class=\"iframe-container\">\n   <iframe src=\"https:\/\/www.youtube.com\/embed\/EaHbzk4TH8g?modestbranding=1&amp;showinfo=0\" frameborder=\"0\" allowfullscreen=\"true\"> <\/iframe>\n  <\/div>\n<div class=\"description\">\n    What is Penetration Testing?\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"record-the-details-of-the-test\">\n<h2> Record the details of the test <\/h2>\n<div class=\"text-content\">\n<p><strong>Use the form fields provided<\/strong> to record the details of the checklist.<\/p>\n<\/p><\/div>\n<div class=\"text-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Name of the person undertaking the testing <\/label><br \/>\n   <input type=\"text\" placeholder=\"Something will be typed here...\" disabled=\"disabled\" class=\"form-control\" \/>\n  <\/div>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Define the scope of the test <\/label><br \/>\n   <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled=\"disabled\" class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<div class=\"date-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Enter the date the test will commence <\/label> <\/p>\n<div class=\"date-container\">\n    <button type=\"button\" disabled=\"disabled\" class=\"btn btn-default\"> <i class=\"fa fa-calendar btn-icon\"><\/i> Date will be set here <\/button>\n   <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"list-the-testing-methods\">\n<h2> List the testing methods <\/h2>\n<div class=\"text-content\">\n<p><strong>Use the form field below<\/strong> to outline the different methods to be employed during this test.&nbsp;<\/p>\n<p>This will help to define what has been tested and what wasn't.&nbsp;<\/p>\n<p>For an in-depth analysis of the different methods available, <strong>watch the video below<\/strong>.<\/p>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Outline the methods to be employed <\/label><br \/>\n   <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled=\"disabled\" class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<div class=\"video-content\">\n<div class=\"iframe-container\">\n   <iframe src=\"https:\/\/www.youtube.com\/embed\/7NGT8AzFe38?modestbranding=1&amp;showinfo=0\" frameborder=\"0\" allowfullscreen=\"true\"> <\/iframe>\n  <\/div>\n<div class=\"description\">\n    Top Methods Pen Testers Use - SANS Pen Test Training\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"gather-network-and-domain-names\">\n<h2> Gather network and domain names <\/h2>\n<div class=\"text-content\">\n<p><strong>Use the form field below<\/strong> to record the different networks and domain names relevant to your exploration.&nbsp;<\/p>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Networks and domain names <\/label><br \/>\n   <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled=\"disabled\" class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"run-a-static-analysis\">\n<h2> Run a static analysis <\/h2>\n<div class=\"text-content\">\n<p>A <a href=\"https:\/\/www.veracode.com\/blog\/2013\/12\/static-testing-vs-dynamic-testing\" rel=\"nofollow noopener\" target=\"_blank\">static analysis<\/a> uses a program to perform a non-runtime assessment of a program's code.&nbsp;<\/p>\n<p>This provides an initial non-hands-on approach to find vulnerabilities&nbsp;when starting your research.&nbsp;<\/p>\n<p><strong>Record your notes<\/strong> on the static analysis below or <strong>watch the video<\/strong> for inspiration. &nbsp;<\/p>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Notes on static analysis <\/label><br \/>\n   <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled=\"disabled\" class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<div class=\"video-content\">\n<div class=\"iframe-container\">\n   <iframe src=\"https:\/\/www.youtube.com\/embed\/17ilENuMj58?modestbranding=1&amp;showinfo=0\" frameborder=\"0\" allowfullscreen=\"true\"> <\/iframe>\n  <\/div>\n<div class=\"description\">\n    Windows App Static Analysis\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"run-a-dynamic-analysis\">\n<h2> Run a dynamic analysis <\/h2>\n<div class=\"text-content\">\n<p>A dynamic analysis is similar to a static analysis except <strong>it takes place while the program is running<\/strong>.&nbsp;<\/p>\n<p>A dynamic test will monitor system memory, functional behavior, response time, and overall performance of the system.<\/p>\n<p>Though static analysis is in ways a more thorough approach, dynamic analysis is capable of exposing a subtle flaw or vulnerability too complicated for static analysis alone to reveal and can also be the more expedient method of testing.<\/p>\n<p><strong>Use the form field below<\/strong> to record your notes.<\/p>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Notes on dynamic analysis <\/label><br \/>\n   <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled=\"disabled\" class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"attempt-to-uncover-the-targets-vulnerabilities\">\n<h2> Attempt to uncover the target's vulnerabilities <\/h2>\n<div class=\"text-content\">\n<p>Whether you find vulnerabilities through your phishing approaches or within your static or dynamic approaches, the first step is to document these potential avenues to exploit.<\/p>\n<p>These weaknesses will have to be addressed in future. <strong>Record them now<\/strong> even if they do not lead to a major security breach as the test continues. &nbsp;<\/p>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Vulnerabilities found <\/label><br \/>\n   <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled=\"disabled\" class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"assess-how-much-immediate-damage-can-be-caused\">\n<h2> Assess how much immediate damage can be caused <\/h2>\n<div class=\"text-content\">\n<p>At this step, begin to try to exploit these weaknesses to see what information can be gleaned.&nbsp;<\/p>\n<p><strong>Use the form field below<\/strong> to record notes on what can or cannot be accessed at this moment in time.<\/p>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Summarize the potential damage which could be caused <\/label><br \/>\n   <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled=\"disabled\" class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"try-to-maintain-persistent-access\">\n<h2> Try to maintain persistent access <\/h2>\n<div class=\"text-content\">\n<p>Another key area to test is how embedded you can become within the network.&nbsp;<\/p>\n<p>Are you able to establish long term access?<\/p>\n<p>Are you able to retain access unnoticed?<\/p>\n<p><strong>Use the form field below<\/strong> to record your attempts at long term exploitation.<\/p>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Notes on persistent access <\/label><br \/>\n   <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled=\"disabled\" class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"compile-the-penetration-test-report\">\n<h2> Compile the penetration test report <\/h2>\n<div class=\"text-content\">\n<p>Once you have completed your penetration testing, compile your full report and <strong>upload it in the form field below<\/strong>.<\/p>\n<\/p><\/div>\n<div class=\"file-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Penetration test final report <\/label> <\/p>\n<div class=\"file-container\">\n    <button type=\"button\" disabled=\"disabled\" class=\"btn btn-default\"> <i class=\"fa fa-upload btn-icon\"><\/i> File will be uploaded here <\/button>\n   <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"send-the-penetration-test-report\">\n<h2> Send the penetration test report <\/h2>\n<div class=\"text-content\">\n<p><strong>Use the email widget below<\/strong> to send this report to the relevant people.&nbsp;<\/p>\n<p>You can use the variables options to enter information into the email automatically.&nbsp;<\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"sources\">\n<h2> Sources: <\/h2>\n<div class=\"text-content\">\n<ul>\n<li><a href=\"https:\/\/www.sans.org\/reading-room\/whitepapers\/auditing\/conducting-penetration-test-organization-67\" rel=\"nofollow noopener\" target=\"_blank\">Conducting a Penetration Test on an Organization - SANS Institute<\/a><\/li>\n<li><a href=\"https:\/\/www.incapsula.com\/web-application-security\/penetration-testing.html\" rel=\"nofollow noopener\" target=\"_blank\">What is Penetration Testing - Incapsula<\/a><\/li>\n<li><a href=\"http:\/\/www.pentest-standard.org\/index.php\/Main_Page\" rel=\"nofollow noopener\" target=\"_blank\">The Penetration Testing Execution Standard - Pentest-Standard<\/a><\/li>\n<li><a href=\"http:\/\/media.techtarget.com\/searchNetworking\/Downloads\/GrayHatHacking_4.pdf\" rel=\"nofollow noopener\" target=\"_blank\">Chapter 4: Pen-Testing Process - Gray Hat Hacking [PDF]<\/a><\/li>\n<li><a href=\"http:\/\/www.csoonline.com\/article\/2944967\/network-security\/10-steps-to-managing-a-successful-network-penetration-test.html\" rel=\"nofollow noopener\" target=\"_blank\">10 Steps to Managing a Successful Network Penetration Test - CSO Online<\/a><\/li>\n<\/ul><\/div>\n<\/section>\n<section id=\"related-checklists\">\n<h2> Related Checklists: <\/h2>\n<div class=\"text-content\">\n<ul>\n<li><a href=\"https:\/\/www.process.st\/templates\/privileged-password-management\/\" rel=\"nofollow\">Privileged Password Management<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/network-administrator-daily-tasks\/\" rel=\"nofollow\">Network Administrator Daily Tasks<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/network-security-audit-checklist\/\" rel=\"nofollow\">Network Security Audit Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/firewall-audit-checklist\/\" rel=\"nofollow\">Firewall Audit Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/vpn-configuration\/\" rel=\"nofollow\">VPN Configuration<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/setup-apache-server\/\" rel=\"nofollow\">Apache Server Setup<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/email-server-security\/\" rel=\"nofollow\">Email Server Security<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/penetration-testing\/\" rel=\"nofollow\">Penetration Testing<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/inventory-management-process\/\" rel=\"nofollow noopener\" target=\"_blank\">Inventory Management Process<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/network-security-management\/\" rel=\"nofollow noopener\" target=\"_blank\">Network Security Management<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/client-data-backup-best-practices\/\" rel=\"nofollow noopener\" target=\"_blank\">Client Data Backup Best Practices<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/computer-maintenance-guide\/\" rel=\"nofollow noopener\" target=\"_blank\">Computer Maintenance Guide<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/ubuntu-server-setup-process\/\" rel=\"nofollow noopener\" target=\"_blank\">Server Setup Process<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/virtual-private-server-setup\/\" rel=\"nofollow noopener\" target=\"_blank\">Virtual Private Server Setup<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/it-support-process\/\" rel=\"nofollow noopener\" target=\"_blank\">IT Support Process<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/helpdesk-management\/\" rel=\"nofollow noopener\" target=\"_blank\">Helpdesk Management<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/server-maintenance-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">Server Maintenance<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/server-security-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">Server Security<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/information-security-incident-response\/\" rel=\"nofollow noopener\" target=\"_blank\">Information Security Incident Response<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/sql-server-audit-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">SQL Server Audit Checklist<\/a><\/li>\n<\/ul><\/div>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>Introduction to Penetration Testing: Penetration Testing - Process Street This Process Street penetration testing checklist is engineered to give a documentation process for staff carrying out penetration testing on either their own networks and services or those of a client.&nbsp; Penetration testing is a method of locating vulnerabilities of information systems by playing the character [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":11857,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"ep_exclude_from_search":false,"cover_icon_emoji":"","cover_icon_url":"","tasks_count":"13","template_description":"Run this Penetration Testing process when you need to expose vulnerabilities in an information system.","template_id":"tz-SeaY1LrNM5P2qv4VCzw","task_0":"Introduction to Penetration Testing:","task_slug_0":"introduction-to-penetration-testing","task_1":"Record the details of the test","task_slug_1":"record-the-details-of-the-test","task_2":"List the testing methods","task_slug_2":"list-the-testing-methods","task_3":"Gather network and domain names","task_slug_3":"gather-network-and-domain-names","task_4":"Run a static analysis","task_slug_4":"run-a-static-analysis","task_5":"Run a dynamic analysis","task_slug_5":"run-a-dynamic-analysis","task_6":"Attempt to uncover the target's vulnerabilities","task_slug_6":"attempt-to-uncover-the-targets-vulnerabilities","task_7":"Assess how much immediate damage can be caused","task_slug_7":"assess-how-much-immediate-damage-can-be-caused","task_8":"Try to maintain persistent access","task_slug_8":"try-to-maintain-persistent-access","task_9":"Compile the penetration test report","task_slug_9":"compile-the-penetration-test-report","task_10":"Send the penetration test report","task_slug_10":"send-the-penetration-test-report","task_11":"Sources:","task_slug_11":"sources","task_12":"Related Checklists:","task_slug_12":"related-checklists","task_13":"","task_slug_13":"","task_14":"","task_slug_14":"","task_15":"","task_slug_15":"","task_16":"","task_slug_16":"","task_17":"","task_slug_17":"","task_18":"","task_slug_18":"","task_19":"","task_slug_19":"","task_20":"","task_slug_20":"","task_21":"","task_slug_21":"","task_22":"","task_slug_22":"","task_23":"","task_slug_23":"","task_24":"","task_slug_24":"","task_25":"","task_slug_25":"","task_26":"","task_slug_26":"","task_27":"","task_slug_27":"","task_28":"","task_slug_28":"","task_29":"","task_slug_29":"","task_30":"","task_slug_30":"","task_31":"","task_slug_31":"","task_32":"","task_slug_32":"","task_33":"","task_slug_33":"","task_34":"","task_slug_34":"","task_35":"","task_slug_35":"","task_36":"","task_slug_36":"","task_37":"","task_slug_37":"","task_38":"","task_slug_38":"","task_39":"","task_slug_39":"","task_40":"","task_slug_40":"","task_41":"","task_slug_41":"","task_42":"","task_slug_42":"","task_43":"","task_slug_43":"","task_44":"","task_slug_44":"","task_45":"","task_slug_45":"","task_46":"","task_slug_46":"","task_47":"","task_slug_47":"","task_48":"","task_slug_48":"","task_49":"","task_slug_49":"","task_50":"","task_slug_50":"","task_51":"","task_slug_51":"","task_52":"","task_slug_52":"","task_53":"","task_slug_53":"","task_54":"","task_slug_54":"","task_55":"","task_slug_55":"","task_56":"","task_slug_56":"","task_57":"","task_slug_57":"","task_58":"","task_slug_58":"","task_59":"","task_slug_59":"","task_60":"","task_slug_60":"","task_61":"","task_slug_61":"","task_62":"","task_slug_62":"","task_63":"","task_slug_63":"","task_64":"","task_slug_64":"","task_65":"","task_slug_65":"","task_66":"","task_slug_66":"","task_67":"","task_slug_67":"","task_68":"","task_slug_68":"","task_69":"","task_slug_69":"","task_70":"","task_slug_70":"","task_71":"","task_slug_71":"","task_72":"","task_slug_72":"","task_73":"","task_slug_73":"","task_74":"","task_slug_74":"","task_75":"","task_slug_75":"","task_76":"","task_slug_76":"","task_77":"","task_slug_77":"","task_78":"","task_slug_78":"","task_79":"","task_slug_79":"","task_80":"","task_slug_80":"","task_81":"","task_slug_81":"","task_82":"","task_slug_82":"","task_83":"","task_slug_83":"","task_84":"","task_slug_84":"","task_85":"","task_slug_85":"","task_86":"","task_slug_86":"","task_87":"","task_slug_87":"","task_88":"","task_slug_88":"","task_89":"","task_slug_89":"","task_90":"","task_slug_90":"","task_91":"","task_slug_91":"","task_92":"","task_slug_92":"","task_93":"","task_slug_93":"","task_94":"","task_slug_94":"","task_95":"","task_slug_95":"","task_96":"","task_slug_96":"","task_97":"","task_slug_97":"","task_98":"","task_slug_98":"","task_99":"","task_slug_99":"","footnotes":""},"categories":[42,7,1],"tags":[],"class_list":["post-11856","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-internal-audit","category-miscellaneous","category-uncategorized"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/posts\/11856","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/comments?post=11856"}],"version-history":[{"count":0,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/posts\/11856\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/media\/11857"}],"wp:attachment":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/media?parent=11856"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/categories?post=11856"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/tags?post=11856"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}