Information gathering is the most important stage of testing and makes up 80–90% of the overall penetration testing effort. The more accurate and sufficient the information gathered at this stage, the more accurate and efficient the tests will be.
Information is gathered using two different methods: passive and active information gathering.
Passive information gathering: The target is unaware of the person gathering information, and publicly available sources are used, including the following:
- Forums
- Dictionary sites
- Community sites
- Social media
- News sites
- Search engines
Active information gathering: Contact is made with the target while gathering information, leaving records of that access on the target. Active information gathering generally uses the following:
- Websites
- Scans
- Port scanning
- Vulnerability scanning
- Operating system scanning
- Service scanning
If, once the purpose and scope are set, the organization provides information about itself and the systems to be tested, some information gathering steps become unnecessary and this stage takes less time.
Social Engineering
Our Social Engineering Service
Social engineering is a general term for activities carried out through human interaction that rely on various methods of persuasion to obtain the desired information.
Most people and organizations face social engineering attacks.
Social engineering attacks essentially take place in four stages: information gathering, building a relationship, exploitation and access.
Technical measures alone cannot stop these attacks. People are the weakest link in the security chain, and no system that involves people can be fully protected against social engineering. Social engineers target this link to get past an organization’s defences.
Although no defence can close these gaps completely, it is possible to reduce the risks and so minimize the potential damage. The most effective defence is auditing. Regular audits should be used to identify weaknesses, and their results should be used both to find and fix gaps in the organization’s security policies and to educate employees and raise their awareness.
With this service, we use a range of social engineering scenarios to determine how prepared your employees are for such attacks and how effective your security policies are. By evaluating the results, we identify your employees’ training gaps and present the measures to be taken.
Related:Red Team · Penetration Testing · ISO 27001 Consulting