Bishop Fox
Bishop Fox Internal Penetration Testing Methodology
Pages
7
Time to read
7 mins
Publication
Language
English
Pages
7
Time to read
7 mins
Publication
Language
English
This document is a technical report detailing Bishop Fox's internal penetration testing methodology. It outlines the processes, methodologies, and deliverables associated with their penetration testing engagements. The report begins with a pre-assessment phase, where the organization’s assets are identified, and the scope of testing is confirmed. The discovery phase follows, which involves local traffic observation, domain controller queries, and network service enumeration to identify potential vulnerabilities. The internal penetration test phase includes various attack techniques such as local network protocol attacks and information retrieval attacks. Finally, the analysis and reporting phase documents the findings, providing an executive report and a detailed assessment report that includes vulnerability analysis and remediation recommendations. The methodology emphasizes a thorough understanding of internal security controls and the identification of weaknesses that could be exploited by adversaries.