Red Teaming types : An introduction
In general Red Teams are used in two ways
Let us first look at how external
Red Teaming may function
External
independent pen testing teams can be engaged in different capacities depending
on a clients requirements, these can include but are not limited to:
●
External independent testing i.e from external point of view third party team will test it up
●
Internal in-house team
●
Physical
○ Testing
physical access to buildings, this includes to staff areas, infrastructure eg. cafeterias,parking lots etc
○
Social Engineering/impersonation/phishing
○
Lockpicking yes
○
Security control evasion
●
Social Engineering
○
Phishing attacks
○
Impersonation
○
Tailgating
○
Drop Attack
●
Network Infrastructure
○
Firewall bypass
○
Router testing/configuration
○
DNS footprinting
○
Proxy Servers
○
Vulnerability exploits
○
Configuration
●
Web application compromise and exploitation – physical and
Cloud
●
Wireless
○
Configuration
○
Unauthorised access points
○
Default passwords
○
Encryption protocols
●
Application testing – databases, - physical and Cloud
●
Operating system build standards
○
Server
○
Desktop
○
Mobile
●
IOT
Comments
Post a Comment