Penetration Testing is an important part of the security service landscape. You can put a lot of effort to secure your environment, to harden your system and improve your business processes. But at some point, you will want to know if it all adds up and works in a REAL attack scenario. Doing a penetration test helps you, to figure out what works and what needs work. But what makes a good penetration test and what are the common problems? Do you really need Threat Modelling? What about metrics? And is a Nessus scan really a pentest as the last shop claimed? This talk will tell you about the DO's and DONT's of penetration testing.
Secdocs is a project aimed to index high-quality IT security and hacking documents. These are fetched from multiple data sources: events, conferences and generally from interwebs.
Serving 8166 documents and 531.0 GB of hacking knowledge, indexed from 2419 authors from 163 security conferences.