Skip to main content
REF-INF-004

Infrastructure Penetration Testing

A simulated cyber attack conducted by ethical hackers to assess the security of IT systems and networks, covering network devices, servers, applications, and operating systems.

Definition

A simulated attack, run by the auditor.

Infrastructure penetration testing is a simulated cyber attack conducted to assess the security of an organization's IT systems and networks: identifying the vulnerabilities and weaknesses a malicious actor could exploit, and recommending the remediation that closes them.

Testing covers network devices, servers, applications, and operating systems, using a combination of manual and automated techniques. The assessment runs against your IP addresses to identify weaknesses in the targeted systems and the threats that apply to them, which also raises internal awareness of how likely an attack is and what it would actually reach.

Tooling is a mix of manual and automated work, with Metasploit among the primary tools used during testing.

Approach

Six phases.

1

Intelligence Gathering

Collect initial information from customer teams about target systems and environments.

2

Coordination

Agree assessment timelines and methodology with IT stakeholders.

3

Reconnaissance

Collect publicly available information, including operating system and service identification.

4

Vulnerability Assessment

Perform comprehensive vulnerability assessment activity against the designated targets.

5

Analysis

Analyze vulnerability data to understand exploitation vectors and business impact.

6

Exploitation

Attempt exploitation of confirmed vulnerabilities, coordinated with the customer on production testing schedules.

Executive Summary Detailed Report Risk Assessment Evidence of Testing Follow-up Support
A laptop on a server rack with console cables trailing down
Deliverables

What you receive.

01

Executive Summary

The testing methodology, findings, and recommendations at the level senior management and stakeholders need.

02

Detailed Report

The same ground in full: methodology, findings, and recommendations, with technical detail and supporting evidence.

03

Risk Assessment

The risk each identified vulnerability poses, and remediation prioritized by impact and likelihood of exploitation.

04

Remediation Recommendations

Recommended solutions for each weakness, with the timeline and the resources each one requires.

05

Evidence of Testing

Screenshots, logs, and detailed test case descriptions documenting what was run and what it returned.

06

Follow-up Support

Consultation while remediation is implemented, periodic follow-up testing, and on-demand retesting.

FAQ

Common questions.

Will testing disrupt our production systems?

Exploitation against production is coordinated with your team on an agreed testing schedule, and assessment timelines and methodology are settled with your IT stakeholders during the coordination phase before any testing begins.

What is in scope?

Network devices, servers, applications, and operating systems, scoped to the targets agreed at the start of the engagement.

How is this different from a Vulnerability Assessment?

A vulnerability assessment identifies and validates known weaknesses. Penetration testing goes further and attempts to exploit confirmed vulnerabilities, demonstrating what an attacker could actually achieve.

What do we receive?

An executive summary, a detailed report, a risk assessment, evidence of testing, and follow-up support after delivery.

Ready to scope Infrastructure Penetration Testing?

Request an Assessment
Request an Assessment Email Us