Professional Red Teaming by Jacob G. Oakley

Professional Red Teaming by Jacob G. Oakley

Author:Jacob G. Oakley
Language: eng
Format: epub
ISBN: 9781484243091
Publisher: Apress


Types of Findings

Now to cover the meat of the report, which includes the findings themselves and how best to communicate them to the customer. It is important to understand there are different types of findings and they can be nuanced in the way they are portrayed to the customer. The most obvious finding is a vulnerability in a piece of installed software that was exploited by the assessors to manipulate or impact the target. Many times, however, findings are not this technical in nature; they can be misconfigurations or lack of configurations that enable successful attack activity. Many times it is also inappropriate to proof of concept a vulnerability by successful exploitation and thus disclosure of findings that were identified but not leveraged is still very useful to the customer. Findings of a less technical nature, such as lack of policy or procedural implementations can also allow assessors to compromise portions of the organization.



Download



Copyright Disclaimer:
This site does not store any files on its server. We only index and link to content provided by other sites. Please contact the content providers to delete copyright contents if any and email us, we'll remove relevant links or contents immediately.