
- The Baby
Internal Penetration Test
This assesses the threat of both deliberate and accidental breaches from hackers and malicious or negligent insiders with access to your systems. Often deemed low-risk, internal attacks can actually pose a substantial threat to an organisation.
External Network Penetration Test
External network penetration testing is a type of penetration testing that focuses on evaluating the security of a network infrastructure. This test identifies the vulnerabilities of your computer systems through their exposure to the Internet.
Web Application Penetration Test
A web application penetration test is a type of security assessment that involves identifying and exploiting vulnerabilities in web-based applications. The correct choice of test if you wish to ensure that your websites, webshops, intranets, extranets and web-based applications are secure.
Mobile Application Penetration Test
A mobile application penetration test is an assessment of security that aims to identify and exploit vulnerabilities found in mobile applications. The primary goal of this testing is to assess the security posture of a mobile application and to identify vulnerabilities that could be exploited by attackers to gain unauthorized access to sensitive data or systems. We would recommend this test to evaluate your mobile apps and the web services that they communicate with.
PENETRATION TESTING PHASES
- Planning and Scooping
- Reconnaissance
- Vulnerability Scanning
- Exploitation
- Post-exploitation
- Reporting
What is a penetration test?
A penetration test is an assurance service where the actions of a malicious attacker are simulated to test the effectiveness of security controls on networks, applications, devices, and services. The aim of a penetration test is to identify as many vulnerabilities as possible on a given scope. Although a variety of tools are used, at Dionach penetration testing is predominantly a manual exercise using the skills of the qualified penetration tester.
How long does a penetration test take?
That’s a difficult question to answer as it purely comes down to the scope of the exercise. A small scope of a network with very few exposed services, or a simple brochure website with limited functionality may be 3 days or even less. Larger, more complex applications or large networks may take significantly longer. A larger testing requirement of multiple applications and networks may take a number of weeks. As part of the scoping process, Dionach will ensure they fully understand what the scope of your test is, and what you are looking to achieve through the test, taking into account your budget, so that the optimum number of days is allocated.
One thing to note, is that although a specific number of days may be quoted for your test, this relates to the overall accumulation of time used, rather than a consecutive number of days. For example, a 5-day test could take place over a 2-week period, depending on the nature of the network or application. Any specific timeline requirements or deadlines within your project should be highlighted at the point of scoping / scheduling to ensure we can plan around those.