{"id":12612,"date":"2023-02-01T22:46:04","date_gmt":"2023-02-01T21:46:04","guid":{"rendered":"http:\/\/nfirjun2026.local\/?p=12612"},"modified":"2025-10-20T19:39:03","modified_gmt":"2025-10-20T17:39:03","slug":"remotely-performing-grey-box-infrastructure-pen-testing","status":"publish","type":"post","link":"https:\/\/www.cyber-security-online.nl\/en\/remotely-performing-grey-box-infrastructure-pen-testing\/","title":{"rendered":"Remotely performing Grey Box infrastructure pen testing"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-page\" data-elementor-id=\"12612\" class=\"elementor elementor-12612 elementor-12611\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-2aa78612 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"2aa78612\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-7556c138\" data-id=\"7556c138\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-inner-section elementor-element elementor-element-374ec56 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"374ec56\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-inner-column elementor-element elementor-element-67fb0af\" data-id=\"67fb0af\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-f580496 elementor-widget elementor-widget-text-editor\" data-id=\"f580496\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: bold;\">A large proportion of attacks on businesses start with hacked computers or employee accounts that are in the familiar office environment. Sometimes an employee accidentally installs something or his or her account is compromised. In addition, servers may be attacked on-site.  <\/span><span style=\"font-weight: bold;\">To test what might happen if this scenario occurs, it is necessary to place a computer within the network. Previously, NFIR&#8217;s ethical hackers would physically come to your office location for this; today, this is done remotely with a pen test box.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-inner-column elementor-element elementor-element-57b1408\" data-id=\"57b1408\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-f821c5f elementor-widget elementor-widget-image\" data-id=\"f821c5f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2023\/02\/image-8.png\" title=\"image (8)\" alt=\"A compact black mini-PC with the &quot;FIR&quot; logo designed for cyber security tasks, equipped with USB ports, an audio jack, power button and side ventilation.\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<div class=\"elementor-element elementor-element-73f7354 elementor-widget elementor-widget-heading\" data-id=\"73f7354\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">What's the PentestBox?<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5364155 elementor-widget elementor-widget-text-editor\" data-id=\"5364155\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The pentest box is a computer the size of a small breadbox that NFIR sends by parcel post. The box contains common tools that are also used by malicious hackers in practice. This computer is placed on the network by your administrator. Then NFIR&#8217;s ethical hackers log in here. They do this entirely remotely.  <span style=\"font-style: inherit; font-weight: inherit; color: var(--ast-global-color-3);\">This mobile mode of operation makes a grey box infrastructure pentest much more effective. There is no or less travel time, no need for space to be provided and also no need for anyone to remain on site to receive and supervise the ethical hackers.  <\/span><span style=\"font-style: inherit; font-weight: inherit; color: var(--ast-global-color-3);\">For the physical aspects of a grey box infrastructure pen test, such as testing your Wifi, printers or badge system, the ethical hackers do, of course, come on site. Often this is a visit of one or a few days.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-b07619b elementor-widget elementor-widget-heading\" data-id=\"b07619b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Is it safe to place the pentest box in a network?<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-de05b8d elementor-widget elementor-widget-text-editor\" data-id=\"de05b8d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The premise of any pen test is that the ethical hackers always try to have as little impact as possible on the environment being tested. The same principle applies to the use of the pentest box. It will be set up so that its use is safe. The pentest box contains an installation of Ubuntu 22.04 LTS Server, which is configured and kept up-to-date using Ansible. Both Ubuntu and Ansible are respected tools in the industry.  <span style=\"font-style: inherit; font-weight: inherit; color: var(--ast-global-color-3);\">To connect to your network, the pentest box connects to a Wireguard VPN from NFIR. Only pentest boxes and NFIR&#8217;s ethical hackers have access to this VPN. Other office staff and NFIR services reside in other VPNs that reside on physically different servers.  <\/span><span style=\"font-style: inherit; font-weight: inherit; color: var(--ast-global-color-3);\">Malicious actors with access to the pentest box&#8217;s network connection also encounter strong security. The services on the pentest box are only available through the VPN, and high standards are also used within the VPN. The ethical hackers connect via SSH with public-key authentication and the other services use random passwords of at least 20 characters. All these measures guarantee secure use of the pentest box.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-dd15e48 elementor-widget elementor-widget-heading\" data-id=\"dd15e48\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">To what extent is your homework facility technically resilient to hackers?<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-fb799ab elementor-widget elementor-widget-text-editor\" data-id=\"fb799ab\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>During a grey box infrastructure pen test, very sensitive data is often encountered. All output from the hacking tools on the pentest box is stored in a highly encrypted portion of the SSD (hard drive) in the pentest box. To do this, NFIR uses LUKS encryption with a 40-character key. The entire installation of the operating system, Ubuntu Server, can be rolled back to the state before starting the pentest box. This prevents information from ending up in system logs. After the pentest is completed, the remote pentest box is cleaned up. Important evidence is copied, then all data is removed from the encrypted part. Then NFIR restores the installation to the state before the pen test. In this way, it is possible to return the pentest box safely by parcel post.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-f1f1d2c elementor-section-full_width elementor-section-height-default elementor-section-height-default\" data-id=\"f1f1d2c\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-no\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-3e35d214\" data-id=\"3e35d214\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-3426212 elementor-cta--layout-image-left elementor-cta--mobile-layout-image-above elementor-cta--skin-classic elementor-animated-content elementor-bg-transform elementor-bg-transform-zoom-in elementor-widget elementor-widget-call-to-action\" data-id=\"3426212\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"call-to-action.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<a class=\"elementor-cta\" href=\"https:\/\/www.cyber-security-online.nl\/en\/contact\/?your-subject=Pentesten\">\n\t\t\t\t\t<div class=\"elementor-cta__bg-wrapper\">\n\t\t\t\t<div class=\"elementor-cta__bg elementor-bg\" style=\"background-image: url(https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2023\/02\/Kantoor-Rijswijk-28-768x473.jpg);\" role=\"img\" aria-label=\"Pentest NFIR\"><\/div>\n\t\t\t\t<div class=\"elementor-cta__bg-overlay\"><\/div>\n\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-cta__content\">\n\t\t\t\t\n\t\t\t\t\t\t\t\t\t<h2 class=\"elementor-cta__title elementor-cta__content-item elementor-content-item\">\n\t\t\t\t\t\tInterested in a penetration test?\t\t\t\t\t<\/h2>\n\t\t\t\t\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-cta__description elementor-cta__content-item elementor-content-item\">\n\t\t\t\t\t\tNFIR carries out high-quality pen tests on (web) applications, websites, networks and mobile applications.\t\t\t\t\t<\/div>\n\t\t\t\t\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-cta__button-wrapper elementor-cta__content-item elementor-content-item \">\n\t\t\t\t\t<span class=\"elementor-cta__button elementor-button elementor-size-md\">\n\t\t\t\t\t\tContact us about your pentest\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-ribbon\">\n\t\t\t\t<div class=\"elementor-ribbon-inner\">\n\t\t\t\t\tPentestbox\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\t\t<\/a>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4c05a92b elementor-widget elementor-widget-spacer\" data-id=\"4c05a92b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"spacer.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-spacer\">\n\t\t\t<div class=\"elementor-spacer-inner\"><\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-03e780a elementor-widget elementor-widget-accordion\" data-id=\"03e780a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"accordion.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-accordion\">\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h3 id=\"elementor-tab-title-4091\" class=\"elementor-tab-title\" data-tab=\"1\" role=\"button\" aria-controls=\"elementor-tab-content-4091\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">What is the difference between a pentest and a vulnerability scan<\/a>\n\t\t\t\t\t<\/h3>\n\t\t\t\t\t<div id=\"elementor-tab-content-4091\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"1\" role=\"region\" aria-labelledby=\"elementor-tab-title-4091\"><p>A vulnerability scan uses automated scans to discover known vulnerabilities. These vulnerabilities are then reported. It is an important first step in understanding potential weaknesses within a system. <br \/>A pentest goes one step further. During a pentest, not only are vulnerabilities identified, but they are actually exploited. This demonstrates what the actual consequence may be to a system or environment when compromised. The ethical hacker will use his experience and creativity to identify all the weaknesses of an environment, giving the organization a more realistic picture of the risks they face.<\/p>\n<h2 class=\"ogtitle\" style=\"font-size: 1em;\"><a href=\"https:\/\/www.cyber-security-online.nl\/en\/contact\/?your-subject=Pentesten\">Penetration test or vulnerability assessment? &#8211; Have a Pentest Performed &#8211; Contact NFIR Now <\/a><\/h2>\n<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h3 id=\"elementor-tab-title-4092\" class=\"elementor-tab-title\" data-tab=\"2\" role=\"button\" aria-controls=\"elementor-tab-content-4092\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">How long does a Pentest take?<\/a>\n\t\t\t\t\t<\/h3>\n\t\t\t\t\t<div id=\"elementor-tab-content-4092\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"2\" role=\"region\" aria-labelledby=\"elementor-tab-title-4092\"><p>Depending on the size of the job, a careful assessment is made as to whether multiple people should be put on a pentest to reduce the length of the job. The duration of a pentest can vary depending on the environment being tested and the complexity of the attack scenarios being used. Generally, a pentest covers a period of 2 to 4 weeks. This period includes not only the execution of the test itself, but also the preparation, analysis and explanation of the final report.<\/p>\n<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h3 id=\"elementor-tab-title-4093\" class=\"elementor-tab-title\" data-tab=\"3\" role=\"button\" aria-controls=\"elementor-tab-content-4093\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">When is a Pentest necessary?<\/a>\n\t\t\t\t\t<\/h3>\n\t\t\t\t\t<div id=\"elementor-tab-content-4093\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"3\" role=\"region\" aria-labelledby=\"elementor-tab-title-4093\"><p>A pentest (penetration test) is necessary because companies are often unaware of vulnerabilities in their network and systems. It is a controlled and authorized attempt to evaluate security through a simulated attack. The main reasons for a pentest include vulnerability identification, risk management, regulatory compliance, evaluation of new applications and changes, protection of customer data, and building trust with customers and stakeholders. Conducting regular pentests is essential to improve security and prepare for potential attacks.<\/p>\n<ul>\n<li>For example, a pen test is useful to:<br \/>Assess your current situation for vulnerabilities.<\/li>\n<li>Detect vulnerabilities before the release of new applications.<\/li>\n<li>Check weaknesses after changes to infrastructure or applications.<\/li>\n<li>Comply with corporate policies, standards and\/or legislation that require periodic security assessments.<\/li>\n<li>Test your Cybersecurity maturity against the detection methods you have implemented.<\/li>\n<\/ul>\n<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h3 id=\"elementor-tab-title-4094\" class=\"elementor-tab-title\" data-tab=\"4\" role=\"button\" aria-controls=\"elementor-tab-content-4094\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">What methodologies and standards are used during the execution of a Pentest?<\/a>\n\t\t\t\t\t<\/h3>\n\t\t\t\t\t<div id=\"elementor-tab-content-4094\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"4\" role=\"region\" aria-labelledby=\"elementor-tab-title-4094\"><p>When performing a pentest, various international standards and methodologies are used to discover and classify vulnerabilities.<\/p>\n<p>Some of the key standards applicable to the assignment include:<\/p>\n<ul>\n<li><a href=\"http:\/\/www.pentest-standard.org\/index.php\/Main_Page\" target=\"_blank\" rel=\"noopener\">Penetration Testing Execution Standard (PTES)<\/a>: methodology for the purpose of infrastructure pen testing.<\/li>\n<li><a href=\"https:\/\/owasp.org\/www-project-web-security-testing-guide\/\" target=\"_blank\" rel=\"noopener\">OWASP WSTG<\/a>: Standard for the purpose of Web application pentesting.<\/li>\n<li><a href=\"https:\/\/owasp.org\/www-project-top-ten\/\" target=\"_blank\" rel=\"noopener\">OWASP Top 10<\/a>: The 10 most critical web application vulnerabilities.<\/li>\n<li><a href=\"https:\/\/owasp.org\/www-project-api-security\/\" target=\"_blank\" rel=\"noopener\">OWASP API Security Top 10<\/a>: The 10 most critical API vulnerabilities.<\/li>\n<li><a href=\"https:\/\/mas.owasp.org\/\" target=\"_blank\" rel=\"noopener\">OWASP MASTG<\/a>: Standard for the purpose of mobile application pentesting.<\/li>\n<li><a href=\"https:\/\/www.first.org\/cvss\/v3-1\/\" target=\"_blank\" rel=\"noopener\">Common Vulnerability Scoring System (CVSS)<\/a>: Used to classify the severity of vulnerabilities.<\/li>\n<\/ul>\n<p>By using these standards, a pentest can be performed in a structured and thorough manner, and the results can be reported in a clear and comparable way.<\/p>\n<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h3 id=\"elementor-tab-title-4095\" class=\"elementor-tab-title\" data-tab=\"5\" role=\"button\" aria-controls=\"elementor-tab-content-4095\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">Penetration tests by our certified experts<\/a>\n\t\t\t\t\t<\/h3>\n\t\t\t\t\t<div id=\"elementor-tab-content-4095\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"5\" role=\"region\" aria-labelledby=\"elementor-tab-title-4095\"><p>Our pentesters have a large amount of experience, a lot of creativity and up-to-date expertise. The NFIR pentesters have followed relevant training courses and obtained certifications such as OSCP. In addition, they have all received chief of police approval and signed confidentiality agreements.<\/p>\n<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h3 id=\"elementor-tab-title-4096\" class=\"elementor-tab-title\" data-tab=\"6\" role=\"button\" aria-controls=\"elementor-tab-content-4096\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">Black box or white box scenario?<\/a>\n\t\t\t\t\t<\/h3>\n\t\t\t\t\t<div id=\"elementor-tab-content-4096\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"6\" role=\"region\" aria-labelledby=\"elementor-tab-title-4096\"><p>A Black Box pentest means that no information about the environment is shared with the pen testers beforehand. With a pentest based on the White Box principle, all information about the environment is shared in advance. If you are having a pentest performed for the first time and want to get an overall picture of your security, it is useful to have a Black Box pen test performed.<\/p>\n<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h3 id=\"elementor-tab-title-4097\" class=\"elementor-tab-title\" data-tab=\"7\" role=\"button\" aria-controls=\"elementor-tab-content-4097\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">What do OWASP WSTG and OWASP MASTG stand for?<\/a>\n\t\t\t\t\t<\/h3>\n\t\t\t\t\t<div id=\"elementor-tab-content-4097\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"7\" role=\"region\" aria-labelledby=\"elementor-tab-title-4097\"><ul>\n<li><strong>OWASP WSTG<\/strong><\/li>\n<\/ul>\n<p>The Web Security Testing Guide (WSTG) project is the premier cybersecurity testing resource for Web application developers and security professionals. The WSTG is a comprehensive guide to testing the security of Web applications and Web services. Created through the combined efforts of cybersecurity professionals and dedicated volunteers, the WSTG provides a framework of best practices used by penetration testers and organizations around the world.<\/p>\n<ul>\n<li><strong>OWASP MASTG<\/strong><\/li>\n<\/ul>\n<p>The OWASP Mobile Application Security Testing guide is a mobile app security standard and comprehensive testing guide that covers the processes, techniques and tools used during a mobile app security test, as well as a comprehensive set of test cases that allow testers to deliver consistent and complete results.<\/p>\n<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h3 id=\"elementor-tab-title-4098\" class=\"elementor-tab-title\" data-tab=\"8\" role=\"button\" aria-controls=\"elementor-tab-content-4098\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">What does the PTES standard stand for?<\/a>\n\t\t\t\t\t<\/h3>\n\t\t\t\t\t<div id=\"elementor-tab-content-4098\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"8\" role=\"region\" aria-labelledby=\"elementor-tab-title-4098\"><p>The Penetration Testing Execution Standard (PTES) consists of several main components. These cover everything about a penetration test, namely:<\/p>\n<ol>\n<li>The initial communication and reasoning behind a pentest;<\/li>\n<li>The information gathering and threat modelling phases, where testers work behind the scenes to gain a better understanding of the tested organisation;<\/li>\n<li>Vulnerability assessment, exploitation and post-exploitation, which addresses the technical security expertise of the testers and combines it with the business insight of the assignment;<\/li>\n<li>Reporting, which captures the entire process in a way that makes sense to the customer and provides them with the most value.<\/li>\n<\/ol>\n<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h3 id=\"elementor-tab-title-4099\" class=\"elementor-tab-title\" data-tab=\"9\" role=\"button\" aria-controls=\"elementor-tab-content-4099\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">What does the CVSS standard stand for?<\/a>\n\t\t\t\t\t<\/h3>\n\t\t\t\t\t<div id=\"elementor-tab-content-4099\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"9\" role=\"region\" aria-labelledby=\"elementor-tab-title-4099\"><p>The Common Vulnerability Scoring System (CVSS) standard provides an open framework for disclosing the characteristics and consequences of software and hardware security vulnerabilities. The quantitative model is designed to ensure consistent and accurate measurement while allowing users to see the underlying vulnerability characteristics used to generate the scores.<\/p>\n<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t<script type=\"application\/ld+json\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"What is the difference between a pentest and a vulnerability scan\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"<p>A vulnerability scan uses automated scans to discover known vulnerabilities. These vulnerabilities are then reported. It is an important first step in understanding potential weaknesses within a system. <br \\\/>A pentest goes one step further. During a pentest, not only are vulnerabilities identified, but they are actually exploited. This demonstrates what the actual consequence may be to a system or environment when compromised. The ethical hacker will use his experience and creativity to identify all the weaknesses of an environment, giving the organization a more realistic picture of the risks they face.<\\\/p>\\n<h2 class=\\\"ogtitle\\\" style=\\\"font-size: 1em;\\\"><a href=\\\"https:\\\/\\\/www.cyber-security-online.nl\\\/en\\\/contact\\\/?your-subject=Pentesten\\\">Penetration test or vulnerability assessment? &#8211; Have a Pentest Performed &#8211; Contact NFIR Now <\\\/a><\\\/h2>\\n\"}},{\"@type\":\"Question\",\"name\":\"How long does a Pentest take?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"<p>Depending on the size of the job, a careful assessment is made as to whether multiple people should be put on a pentest to reduce the length of the job. The duration of a pentest can vary depending on the environment being tested and the complexity of the attack scenarios being used. Generally, a pentest covers a period of 2 to 4 weeks. This period includes not only the execution of the test itself, but also the preparation, analysis and explanation of the final report.<\\\/p>\\n\"}},{\"@type\":\"Question\",\"name\":\"When is a Pentest necessary?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"<p>A pentest (penetration test) is necessary because companies are often unaware of vulnerabilities in their network and systems. It is a controlled and authorized attempt to evaluate security through a simulated attack. The main reasons for a pentest include vulnerability identification, risk management, regulatory compliance, evaluation of new applications and changes, protection of customer data, and building trust with customers and stakeholders. Conducting regular pentests is essential to improve security and prepare for potential attacks.<\\\/p>\\n<ul>\\n<li>For example, a pen test is useful to:<br \\\/>Assess your current situation for vulnerabilities.<\\\/li>\\n<li>Detect vulnerabilities before the release of new applications.<\\\/li>\\n<li>Check weaknesses after changes to infrastructure or applications.<\\\/li>\\n<li>Comply with corporate policies, standards and\\\/or legislation that require periodic security assessments.<\\\/li>\\n<li>Test your Cybersecurity maturity against the detection methods you have implemented.<\\\/li>\\n<\\\/ul>\\n\"}},{\"@type\":\"Question\",\"name\":\"What methodologies and standards are used during the execution of a Pentest?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"<p>When performing a pentest, various international standards and methodologies are used to discover and classify vulnerabilities.<\\\/p>\\n<p>Some of the key standards applicable to the assignment include:<\\\/p>\\n<ul>\\n<li><a href=\\\"http:\\\/\\\/www.pentest-standard.org\\\/index.php\\\/Main_Page\\\" target=\\\"_blank\\\" rel=\\\"noopener\\\">Penetration Testing Execution Standard (PTES)<\\\/a>: methodology for the purpose of infrastructure pen testing.<\\\/li>\\n<li><a href=\\\"https:\\\/\\\/owasp.org\\\/www-project-web-security-testing-guide\\\/\\\" target=\\\"_blank\\\" rel=\\\"noopener\\\">OWASP WSTG<\\\/a>: Standard for the purpose of Web application pentesting.<\\\/li>\\n<li><a href=\\\"https:\\\/\\\/owasp.org\\\/www-project-top-ten\\\/\\\" target=\\\"_blank\\\" rel=\\\"noopener\\\">OWASP Top 10<\\\/a>: The 10 most critical web application vulnerabilities.<\\\/li>\\n<li><a href=\\\"https:\\\/\\\/owasp.org\\\/www-project-api-security\\\/\\\" target=\\\"_blank\\\" rel=\\\"noopener\\\">OWASP API Security Top 10<\\\/a>: The 10 most critical API vulnerabilities.<\\\/li>\\n<li><a href=\\\"https:\\\/\\\/mas.owasp.org\\\/\\\" target=\\\"_blank\\\" rel=\\\"noopener\\\">OWASP MASTG<\\\/a>: Standard for the purpose of mobile application pentesting.<\\\/li>\\n<li><a href=\\\"https:\\\/\\\/www.first.org\\\/cvss\\\/v3-1\\\/\\\" target=\\\"_blank\\\" rel=\\\"noopener\\\">Common Vulnerability Scoring System (CVSS)<\\\/a>: Used to classify the severity of vulnerabilities.<\\\/li>\\n<\\\/ul>\\n<p>By using these standards, a pentest can be performed in a structured and thorough manner, and the results can be reported in a clear and comparable way.<\\\/p>\\n\"}},{\"@type\":\"Question\",\"name\":\"Penetration tests by our certified experts\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"<p>Our pentesters have a large amount of experience, a lot of creativity and up-to-date expertise. The NFIR pentesters have followed relevant training courses and obtained certifications such as OSCP. In addition, they have all received chief of police approval and signed confidentiality agreements.<\\\/p>\\n\"}},{\"@type\":\"Question\",\"name\":\"Black box or white box scenario?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"<p>A Black Box pentest means that no information about the environment is shared with the pen testers beforehand. With a pentest based on the White Box principle, all information about the environment is shared in advance. If you are having a pentest performed for the first time and want to get an overall picture of your security, it is useful to have a Black Box pen test performed.<\\\/p>\\n\"}},{\"@type\":\"Question\",\"name\":\"What do OWASP WSTG and OWASP MASTG stand for?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"<ul>\\n<li><strong>OWASP WSTG<\\\/strong><\\\/li>\\n<\\\/ul>\\n<p>The Web Security Testing Guide (WSTG) project is the premier cybersecurity testing resource for Web application developers and security professionals. The WSTG is a comprehensive guide to testing the security of Web applications and Web services. Created through the combined efforts of cybersecurity professionals and dedicated volunteers, the WSTG provides a framework of best practices used by penetration testers and organizations around the world.<\\\/p>\\n<ul>\\n<li><strong>OWASP MASTG<\\\/strong><\\\/li>\\n<\\\/ul>\\n<p>The OWASP Mobile Application Security Testing guide is a mobile app security standard and comprehensive testing guide that covers the processes, techniques and tools used during a mobile app security test, as well as a comprehensive set of test cases that allow testers to deliver consistent and complete results.<\\\/p>\\n\"}},{\"@type\":\"Question\",\"name\":\"What does the PTES standard stand for?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"<p>The Penetration Testing Execution Standard (PTES) consists of several main components. These cover everything about a penetration test, namely:<\\\/p>\\n<ol>\\n<li>The initial communication and reasoning behind a pentest;<\\\/li>\\n<li>The information gathering and threat modelling phases, where testers work behind the scenes to gain a better understanding of the tested organisation;<\\\/li>\\n<li>Vulnerability assessment, exploitation and post-exploitation, which addresses the technical security expertise of the testers and combines it with the business insight of the assignment;<\\\/li>\\n<li>Reporting, which captures the entire process in a way that makes sense to the customer and provides them with the most value.<\\\/li>\\n<\\\/ol>\\n\"}},{\"@type\":\"Question\",\"name\":\"What does the CVSS standard stand for?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"<p>The Common Vulnerability Scoring System (CVSS) standard provides an open framework for disclosing the characteristics and consequences of software and hardware security vulnerabilities. The quantitative model is designed to ensure consistent and accurate measurement while allowing users to see the underlying vulnerability characteristics used to generate the scores.<\\\/p>\\n\"}}]}<\/script>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>A large proportion of attacks on businesses start with hacked computers or employee accounts that are in the familiar office environment. Sometimes an employee accidentally [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":2716,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_seopress_titles_title":"Find out how secure your network is with the NFIR Pentest.","_seopress_titles_desc":"Find out how secure your network is with the NFIR Pentest. Professional ethical hackers can remotely test your network and detect vulnerabilities. Please feel free to contact us for more information!","_seopress_robots_index":"","_seopress_robots_follow":"","_seopress_robots_imageindex":"","_seopress_robots_snippet":"","_seopress_robots_primary_cat":"none","_seopress_robots_breadcrumbs":"","_seopress_robots_freeze_modified_date":"","_seopress_robots_custom_modified_date":"","_seopress_robots_canonical":"","_seopress_social_fb_title":"","_seopress_social_fb_desc":"","_seopress_social_fb_img":"","_seopress_social_fb_img_attachment_id":0,"_seopress_social_fb_img_width":0,"_seopress_social_fb_img_height":0,"_seopress_social_twitter_title":"","_seopress_social_twitter_desc":"","_seopress_social_twitter_img":"","_seopress_social_twitter_img_attachment_id":0,"_seopress_social_twitter_img_width":0,"_seopress_social_twitter_img_height":0,"_seopress_redirections_value":"","_seopress_redirections_enabled":"","_seopress_redirections_enabled_regex":"","_seopress_redirections_logged_status":"both","_seopress_redirections_param":"","_seopress_redirections_type":301,"_seopress_analysis_target_kw":"","_seopress_news_disabled":"","_seopress_video_disabled":"","_seopress_video":[],"_seopress_pro_schemas_manual":[],"_seopress_pro_rich_snippets_disable_all":"","_seopress_pro_rich_snippets_disable":[],"_seopress_pro_schemas":[],"site-sidebar-layout":"default","site-content-layout":"default","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"default","adv-header-id-meta":"","stick-header-meta":"default","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[29],"tags":[],"class_list":["post-12612","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-media-en"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/posts\/12612","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/comments?post=12612"}],"version-history":[{"count":0,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/posts\/12612\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/media\/2716"}],"wp:attachment":[{"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/media?parent=12612"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/categories?post=12612"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/tags?post=12612"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}