1
00:00:06,660 --> 00:00:09,090
- In this lesson, 27.2,
we're gonna be talking

2
00:00:09,090 --> 00:00:11,520
about penetration testing concepts.

3
00:00:11,520 --> 00:00:15,090
And we're gonna follow this
up with our next lesson, 27.3,

4
00:00:15,090 --> 00:00:18,150
which is also gonna be
about penetration testing.

5
00:00:18,150 --> 00:00:20,580
Now, the objective of
penetration testing is

6
00:00:20,580 --> 00:00:23,757
to evaluate the security
of a target by identifying.

7
00:00:23,757 --> 00:00:27,480
And attempting to exploit
vulnerabilities or weaknesses,

8
00:00:27,480 --> 00:00:31,170
improper configurations,
and hidden points of entry.

9
00:00:31,170 --> 00:00:33,450
Now, very often penetration
testing will be referred

10
00:00:33,450 --> 00:00:34,953
to as ethical hacking.

11
00:00:36,570 --> 00:00:38,280
Now, penetration testing

12
00:00:38,280 --> 00:00:40,740
generally involves exploiting combinations

13
00:00:40,740 --> 00:00:43,950
of vulnerabilities on one or more systems.

14
00:00:43,950 --> 00:00:46,110
Now, the testing can originate from within

15
00:00:46,110 --> 00:00:48,270
a target environment or external.

16
00:00:48,270 --> 00:00:51,420
So, internal or external
penetration testing.

17
00:00:51,420 --> 00:00:54,150
In addition to identifying
the vulnerabilities,

18
00:00:54,150 --> 00:00:56,250
the improper configurations,
and the hidden points

19
00:00:56,250 --> 00:00:58,860
of entry penetration testing can also be

20
00:00:58,860 --> 00:01:02,069
really useful for determining
incident detection

21
00:01:02,069 --> 00:01:04,293
and response capabilities.

22
00:01:05,550 --> 00:01:08,370
Now, there are three
primary testing approaches,

23
00:01:08,370 --> 00:01:11,610
a known environment, a
partially known environment,

24
00:01:11,610 --> 00:01:13,173
and an unknown environment.

25
00:01:14,040 --> 00:01:16,080
In the known environment, the testers,

26
00:01:16,080 --> 00:01:17,850
now the testers could be internal folks

27
00:01:17,850 --> 00:01:21,000
who are independent folks, external.

28
00:01:21,000 --> 00:01:23,340
Really just, depending on
what kind of test you're doing

29
00:01:23,340 --> 00:01:25,530
and what your compliance requirements are.

30
00:01:25,530 --> 00:01:28,770
But the testers have
comprehensive knowledge

31
00:01:28,770 --> 00:01:31,530
about the target system or the network.

32
00:01:31,530 --> 00:01:33,540
And with this level of knowledge

33
00:01:33,540 --> 00:01:37,950
the testing team can conduct
really in-depth analysis,

34
00:01:37,950 --> 00:01:42,330
targeted assessments, and
explore potential attack vectors.

35
00:01:42,330 --> 00:01:43,863
So a known environment.

36
00:01:45,870 --> 00:01:47,820
We have a partially known environment.

37
00:01:47,820 --> 00:01:49,590
Now, in a partially known environment,

38
00:01:49,590 --> 00:01:52,020
the organization will provide restricted

39
00:01:52,020 --> 00:01:54,570
or selected information to the testers.

40
00:01:54,570 --> 00:01:57,120
Again, it could be internal
or external testers.

41
00:01:57,120 --> 00:02:00,630
This approach really simulates scenarios

42
00:02:00,630 --> 00:02:03,720
where an attacker might
gain partial information

43
00:02:03,720 --> 00:02:06,270
through reconnaissance
or social engineering.

44
00:02:06,270 --> 00:02:07,770
So in a partially known environment,

45
00:02:07,770 --> 00:02:10,260
perhaps they're given IP addresses,

46
00:02:10,260 --> 00:02:12,900
perhaps they're even given a username.

47
00:02:12,900 --> 00:02:15,690
And password to log in with the assumption

48
00:02:15,690 --> 00:02:17,160
that maybe through reconnaissance

49
00:02:17,160 --> 00:02:20,220
or social engineering our adversaries,

50
00:02:20,220 --> 00:02:22,350
the attacker would be able
to get that information.

51
00:02:22,350 --> 00:02:24,990
So we work in the premise
of what if they got

52
00:02:24,990 --> 00:02:27,510
that information, what could they do?

53
00:02:27,510 --> 00:02:31,830
Or what if this attack
and initiated from inside,

54
00:02:31,830 --> 00:02:34,830
from an insider who already
had a name and password

55
00:02:34,830 --> 00:02:37,410
and they were already on our system?

56
00:02:37,410 --> 00:02:39,680
And then third is an unknown environment.

57
00:02:39,680 --> 00:02:42,450
In an unknown environment,
no information is provided

58
00:02:42,450 --> 00:02:45,330
to the testers other
than what the target is.

59
00:02:45,330 --> 00:02:47,790
The testers need to
discover vulnerabilities.

60
00:02:47,790 --> 00:02:49,530
They'll need to conduct reconnaissance,

61
00:02:49,530 --> 00:02:52,260
they'll need to identify
those potential entry points.

62
00:02:52,260 --> 00:02:54,600
And they'll perform their
exploitation attempts

63
00:02:54,600 --> 00:02:56,070
so they have no knowledge.

64
00:02:56,070 --> 00:02:58,634
And really what we're
trying to simulate here is

65
00:02:58,634 --> 00:03:01,260
an attacker, an adversary
who has no knowledge

66
00:03:01,260 --> 00:03:03,900
of our organization, kind
of what they would see.

67
00:03:03,900 --> 00:03:06,120
What their process would
be, what they would do.

68
00:03:06,120 --> 00:03:08,190
Because in effect, penetration testing

69
00:03:08,190 --> 00:03:12,303
really mimics what real world
attackers would be doing.

70
00:03:14,340 --> 00:03:16,050
Now, at the beginning
of a penetration test

71
00:03:16,050 --> 00:03:17,400
we're going to have an agreement known

72
00:03:17,400 --> 00:03:19,800
as a ROE or rules of engagement.

73
00:03:19,800 --> 00:03:21,663
This is similar to an audit plan.

74
00:03:21,663 --> 00:03:22,496
Remember, at the beginning of the audit

75
00:03:22,496 --> 00:03:23,670
we had an audit plan.

76
00:03:23,670 --> 00:03:25,470
But when we have an engagement like this,

77
00:03:25,470 --> 00:03:27,930
we're gonna call it an
ROE, rules of engagement.

78
00:03:27,930 --> 00:03:30,060
And that will detail the parameters

79
00:03:30,060 --> 00:03:32,850
and the expected assessor
or tester's conduct

80
00:03:32,850 --> 00:03:34,530
of the penetration test.

81
00:03:34,530 --> 00:03:37,230
Now, some components that
you'd find in an ROE,

82
00:03:37,230 --> 00:03:41,250
the scope of the test, any
assumptions and limitations.

83
00:03:41,250 --> 00:03:45,480
And a really important
limitation is proof of concept

84
00:03:45,480 --> 00:03:49,680
versus a compromise
exploitation or a true attack.

85
00:03:49,680 --> 00:03:53,130
So do we want to have them
go just far enough to prove

86
00:03:53,130 --> 00:03:55,500
that that exploit exists
or that they could get in?

87
00:03:55,500 --> 00:03:57,240
Or do you want them to really go through

88
00:03:57,240 --> 00:04:00,000
and do it potentially causing exfiltration

89
00:04:00,000 --> 00:04:02,913
of data or maybe a denial of service?

90
00:04:03,913 --> 00:04:06,540
You're also going to determine logistics

91
00:04:06,540 --> 00:04:08,880
such as who's involved, what personnel,

92
00:04:08,880 --> 00:04:10,440
what the test schedule is.

93
00:04:10,440 --> 00:04:12,420
Do you want it during
regular operating hours

94
00:04:12,420 --> 00:04:14,160
or do you want it during off hours?

95
00:04:14,160 --> 00:04:17,010
What the test site is and any equipment.

96
00:04:17,010 --> 00:04:18,630
We're gonna have a communications plan.

97
00:04:18,630 --> 00:04:20,220
So who are we communicating

98
00:04:20,220 --> 00:04:21,780
with throughout the whole test,

99
00:04:21,780 --> 00:04:23,700
particularly if either something

100
00:04:23,700 --> 00:04:25,590
very egregious is identified.

101
00:04:25,590 --> 00:04:28,680
Or if there's been a
problem with an exploit,

102
00:04:28,680 --> 00:04:32,400
the testing expectations and
the data handling requirements

103
00:04:32,400 --> 00:04:34,893
as well as what the
reporting's going to be.

104
00:04:37,108 --> 00:04:39,810
Now, there are some legal
considerations related

105
00:04:39,810 --> 00:04:43,530
to penetration testing,
including is it authorized?

106
00:04:43,530 --> 00:04:44,700
Who is liable?

107
00:04:44,700 --> 00:04:46,470
What's the indemnification?

108
00:04:46,470 --> 00:04:49,023
What about non-disclosure and privacy?

109
00:04:49,980 --> 00:04:53,700
So authorization is often
required from third parties

110
00:04:53,700 --> 00:04:55,740
that host assessment objects.

111
00:04:55,740 --> 00:04:59,610
So let's say you want a
penetration test on your website,

112
00:04:59,610 --> 00:05:03,480
but your website is hosted by
another party, a third party.

113
00:05:03,480 --> 00:05:05,580
You're going to have
to get their permission

114
00:05:05,580 --> 00:05:07,650
to be able to test your website.

115
00:05:07,650 --> 00:05:09,060
Or you wanna have a lease,

116
00:05:09,060 --> 00:05:10,830
maybe upfront put in your contract

117
00:05:10,830 --> 00:05:13,260
that you can go ahead
and test your website.

118
00:05:13,260 --> 00:05:15,444
But not doing so, just
saying, "Okay, well,

119
00:05:15,444 --> 00:05:19,590
my site is a third party
site that I want you to test

120
00:05:19,590 --> 00:05:21,480
and I haven't gotten
permission from them."

121
00:05:21,480 --> 00:05:23,630
That could be a violation
of your contract.

122
00:05:24,540 --> 00:05:27,810
Any potential privacy
violation should be identified.

123
00:05:27,810 --> 00:05:30,870
Non-disclosure contracts or
agreements should protect

124
00:05:30,870 --> 00:05:33,270
the disclosure of both
the data collection,

125
00:05:33,270 --> 00:05:36,690
so anything that got collected,
as well as the findings.

126
00:05:36,690 --> 00:05:38,940
And then contracts with external assessors

127
00:05:38,940 --> 00:05:41,460
generally include a
limitation of liability.

128
00:05:41,460 --> 00:05:43,170
So who's liable for what?

129
00:05:43,170 --> 00:05:44,767
And generally it'll be
the assessor saying,

130
00:05:44,767 --> 00:05:46,350
"Listen, we have no liability.

131
00:05:46,350 --> 00:05:48,450
If we crash your system,
we crash your system.

132
00:05:48,450 --> 00:05:52,350
But we're working on a good faith effort."

133
00:05:52,350 --> 00:05:54,060
And an indemnification clause.

134
00:05:54,060 --> 00:05:57,090
An indemnification clause
is financial payment

135
00:05:57,090 --> 00:05:59,340
for causing some kind of problem.

136
00:05:59,340 --> 00:06:01,200
Now, those should be in contracts

137
00:06:01,200 --> 00:06:03,933
but they should be
reviewed by legal counsel.

138
00:06:05,460 --> 00:06:07,620
A subset of penetration testing is called

139
00:06:07,620 --> 00:06:10,290
offensive and defensive
penetration testing.

140
00:06:10,290 --> 00:06:13,650
We used to refer to it as red
team, blue team simulation.

141
00:06:13,650 --> 00:06:14,580
In your exam though,

142
00:06:14,580 --> 00:06:18,210
we refer to it as offensive/defensive
penetration testing.

143
00:06:18,210 --> 00:06:20,932
In offensive/defensive
penetration testing,

144
00:06:20,932 --> 00:06:24,270
it's designed to simulate an attack.

145
00:06:24,270 --> 00:06:25,906
But what we're trying
to do here is evaluate

146
00:06:25,906 --> 00:06:28,920
our preventative, our deterrent controls,

147
00:06:28,920 --> 00:06:32,970
our detection controls, and
our response capabilities.

148
00:06:32,970 --> 00:06:34,830
So we'll have a couple of teams.

149
00:06:34,830 --> 00:06:36,750
We're going to have an offensive team

150
00:06:36,750 --> 00:06:40,110
and the offensive testing team emulates

151
00:06:40,110 --> 00:06:43,800
the behaviors and the
techniques of likely attackers.

152
00:06:43,800 --> 00:06:46,170
Then we're gonna have a defensive team,

153
00:06:46,170 --> 00:06:48,630
which is the testing team that's tasked

154
00:06:48,630 --> 00:06:51,480
with detective and defensive activities.

155
00:06:51,480 --> 00:06:54,215
So we used to refer to them
as a red team and a blue team.

156
00:06:54,215 --> 00:06:55,890
Now they're the offensive
team and the defensive team

157
00:06:55,890 --> 00:06:58,080
and we may have an integrated team.

158
00:06:58,080 --> 00:07:00,510
Now, the integrated
penetration testing team

159
00:07:00,510 --> 00:07:03,600
actively engages in monitoring, detection,

160
00:07:03,600 --> 00:07:06,990
and response activities
during the testing process.

161
00:07:06,990 --> 00:07:09,060
With a focus on information sharing

162
00:07:09,060 --> 00:07:11,853
and cooperation, really a feedback bridge.

163
00:07:12,840 --> 00:07:15,420
These are really great type of tests.

164
00:07:15,420 --> 00:07:18,750
It allows us to say, okay,
for a particular scenario,

165
00:07:18,750 --> 00:07:21,531
a DDoS attack, a ransomware attack,

166
00:07:21,531 --> 00:07:26,531
a SQL injection type of
attack, would we detect it?

167
00:07:27,060 --> 00:07:28,380
And how would we respond?

168
00:07:28,380 --> 00:07:30,000
And probably even before that,

169
00:07:30,000 --> 00:07:33,030
do we have the right preventative
and deterrent controls?

170
00:07:33,030 --> 00:07:34,890
Do we have the right detective controls?

171
00:07:34,890 --> 00:07:37,590
Can we respond quickly and appropriately?

172
00:07:37,590 --> 00:07:40,050
If we need to call on our
incident response plan,

173
00:07:40,050 --> 00:07:41,580
can we do that as well?

174
00:07:41,580 --> 00:07:45,450
So it really gives us a
sense of how well prepared

175
00:07:45,450 --> 00:07:49,920
an organization is to respond
to specific types of attack.

176
00:07:49,920 --> 00:07:53,190
But what I wanna stress
is it is not, it is not,

177
00:07:53,190 --> 00:07:57,780
it is not a substitute for doing
a regular penetration test.

178
00:07:57,780 --> 00:07:59,880
They're two very different
things, even though they both

179
00:07:59,880 --> 00:08:02,463
now have penetration test in their name.

180
00:08:03,568 --> 00:08:05,190
Now, there's also what's known

181
00:08:05,190 --> 00:08:07,350
as physical penetration testing,

182
00:08:07,350 --> 00:08:09,000
which focuses on evaluating

183
00:08:09,000 --> 00:08:11,010
the effectiveness of an organization's

184
00:08:11,010 --> 00:08:14,040
physical security controls and measures.

185
00:08:14,040 --> 00:08:16,470
The physical penetration testing aims

186
00:08:16,470 --> 00:08:19,410
to assess the physical
security measures in place

187
00:08:19,410 --> 00:08:22,560
such as access control
systems, locks, alarms,

188
00:08:22,560 --> 00:08:24,990
surveillance systems, perimeter security,

189
00:08:24,990 --> 00:08:27,330
as well as employee awareness.

190
00:08:27,330 --> 00:08:29,910
Physical penetration testers simulate

191
00:08:29,910 --> 00:08:31,770
the techniques and the tactics

192
00:08:31,770 --> 00:08:35,880
that malicious actors might use
to gain unauthorized access.

193
00:08:35,880 --> 00:08:38,940
So for example, social
engineering, tailgating,

194
00:08:38,940 --> 00:08:41,400
which is following a authorized personnel

195
00:08:41,400 --> 00:08:45,543
into a secured area, or lock
picking, or badge cloning.

196
00:08:47,940 --> 00:08:49,200
All right, that my friends brings us

197
00:08:49,200 --> 00:08:51,060
to a three second challenge.

198
00:08:51,060 --> 00:08:53,070
Five challenge questions,
three seconds each.

199
00:08:53,070 --> 00:08:53,903
Let's do it.

200
00:08:55,598 --> 00:08:58,410
A term used to describe
authorized penetration testing

201
00:08:58,410 --> 00:09:00,093
for legitimate purposes.

202
00:09:01,080 --> 00:09:02,673
One, two, three.

203
00:09:03,769 --> 00:09:05,550
We call that ethical hacking.

204
00:09:05,550 --> 00:09:09,183
Number two, document that
details the testing parameters.

205
00:09:10,650 --> 00:09:12,660
1, 2, 3.

206
00:09:12,660 --> 00:09:15,423
That's gonna be a rules
of engagement or an ROE.

207
00:09:16,890 --> 00:09:19,980
Number three, a team that
emulates the behaviors

208
00:09:19,980 --> 00:09:22,293
and techniques of likely attackers.

209
00:09:23,340 --> 00:09:27,423
1, 2, 3, it's gonna be the offensive team.

210
00:09:29,580 --> 00:09:33,210
Number four, testing approach
that provides no information

211
00:09:33,210 --> 00:09:34,203
to the testers.

212
00:09:35,790 --> 00:09:40,320
1, 2, 3, that is unknown environment.

213
00:09:40,320 --> 00:09:43,680
And lastly, number five, the
type of penetration testing

214
00:09:43,680 --> 00:09:46,410
that might focus on surveillance systems,

215
00:09:46,410 --> 00:09:50,040
perimeter security,
and employee awareness.

216
00:09:50,040 --> 00:09:51,273
1, 2, 3.

217
00:09:52,110 --> 00:09:54,183
And that's physical penetration testing.

218
00:09:55,230 --> 00:09:57,450
So that brings us to a security-in-action.

219
00:09:57,450 --> 00:09:59,850
This one's about a penetration test.

220
00:09:59,850 --> 00:10:02,460
AnyTown bank has hired Testers, Inc.

221
00:10:02,460 --> 00:10:05,160
To conduct a penetration
test that they don't intend

222
00:10:05,160 --> 00:10:08,400
to provide any details or authorization.

223
00:10:08,400 --> 00:10:10,260
They expect the scope to include

224
00:10:10,260 --> 00:10:13,680
both external and onsite attempts.

225
00:10:13,680 --> 00:10:16,080
So my question to you is, in the ROE,

226
00:10:16,080 --> 00:10:17,490
the rules of engagement,

227
00:10:17,490 --> 00:10:19,980
how should they describe this approach?

228
00:10:19,980 --> 00:10:21,930
So a quick recap, we've got a bank.

229
00:10:21,930 --> 00:10:26,160
They've hired Testers, Inc. to
conduct the penetration test.

230
00:10:26,160 --> 00:10:29,160
They do not intend, so do not intend

231
00:10:29,160 --> 00:10:32,040
to provide any details or authorization.

232
00:10:32,040 --> 00:10:33,990
And they expect the scope to include

233
00:10:33,990 --> 00:10:37,263
both external and onsite attempts.

234
00:10:38,550 --> 00:10:41,640
So how are we gonna
describe this in the ROE?

235
00:10:41,640 --> 00:10:43,530
Go ahead and put me on pause for a moment.

236
00:10:43,530 --> 00:10:44,400
Think about it.

237
00:10:44,400 --> 00:10:47,183
Come on back and we'll talk
about the rules of engagement.

238
00:10:48,720 --> 00:10:51,870
Well, since no details of
the environment are provided,

239
00:10:51,870 --> 00:10:55,083
the approach would be considered
an unknown environment.

240
00:10:56,850 --> 00:10:59,310
Now, the onsite component
of the test would be known

241
00:10:59,310 --> 00:11:02,790
as physical penetration
testing and one would expect it

242
00:11:02,790 --> 00:11:05,343
to include a social engineering component.

243
00:11:06,420 --> 00:11:10,500
Now, the ROE should
clearly detail expectations

244
00:11:10,500 --> 00:11:12,960
and communication plans.

245
00:11:12,960 --> 00:11:15,750
Being able to understand
how to put this in an ROE

246
00:11:15,750 --> 00:11:17,970
and communicate it to our testers,

247
00:11:17,970 --> 00:11:20,550
that my friends is definitely
security in action.

248
00:11:20,550 --> 00:11:22,050
There's your word cloud.

249
00:11:22,050 --> 00:11:23,580
Make sure that you know all of these

250
00:11:23,580 --> 00:11:25,170
before you go on to our next lesson.

251
00:11:25,170 --> 00:11:26,730
'cause we're gonna continue talking

252
00:11:26,730 --> 00:11:28,020
about penetration testing

253
00:11:28,020 --> 00:11:30,150
and we're gonna build on these terms.

254
00:11:30,150 --> 00:11:31,973
So I'll see you there when you're ready.
