Penetration testers and security peeps of bluesy
What are your standard checks when looking at a new to you organisation?
What are your standard checks when looking at a new to you organisation?
Comments
- Externally exposed services (all MFA?)
- Bloodhound in Active Directory
- Scoutsuite for cloud assets
what about if your testing as if you are a new starter at that org, so you have basic access etc?
-Responder
-Digging through file shares
-Kerberoasting
Many of them have pet peeves that they know are bad but can't get the leverage to fix.
to get the resources to fit it
A tell-tale sign of a dysfunctional organization: "I'll probably get in trouble for saying this, but..."