Planning and Reconnaissance
The first phase of penetration testing involves planning the engagement and gathering information about the target.
Planning
- Define scope and rules of engagement
- Identify target systems and applications
- Determine testing methodology
- Obtain written authorization
Reconnaissance
- Passive - WHOIS, DNS, search engines, social media
- Active - Port scanning, service enumeration, banner grabbing
- OSINT - Open Source Intelligence gathering
Tools
- Nmap, Shodan, theHarvester, Maltego