Planning and Reconnaissance

The first phase of penetration testing involves planning the engagement and gathering information about the target.

Planning

  • Define scope and rules of engagement
  • Identify target systems and applications
  • Determine testing methodology
  • Obtain written authorization

Reconnaissance

  • Passive - WHOIS, DNS, search engines, social media
  • Active - Port scanning, service enumeration, banner grabbing
  • OSINT - Open Source Intelligence gathering

Tools

  • Nmap, Shodan, theHarvester, Maltego