Service Enumeration

FTP (20, 21) standard: control channel on port 21, data channel on port 20 ftp is insecure, cleartext anonymous login may be active allowing read or read/write without creds tftp is an alternate...

Exploitation

Overview One fork after the assessment stage, requires utilizing the information from the two prior steps to prepare targeted attacks against the found endpoint. Attacks can be prioritized with...

Post-Exploitation

Overview Once exploitation succeeds, access tends to be granted as least-privilege (ie, a locked-down service account specifically used for running the web app). This stage essentially starts a...

OSINT

What is it? OSINT - or Open Source Intelligence - utilizes methods of gathering information passively from online sources, and not directly targeting an organization's infrastructure. Methodology...

Pre-Engagement

Overview Multiple documents should be reviewed during the pre-engagement period: Non-Disclosure Agreement (NDAs) NDAs can come in different types: unilateral, bilateral, multilateral. Each of...