Testing Services

We test your systems, network and people through the eyes of a real attacker.

Penetration Testing

Our Penetration Testing Service

In its simplest definition, penetration testing is work carried out on computer systems to detect their security gaps and vulnerabilities. Penetration testing is also known by the following names:

  • Penetration test
  • Pentest
  • Ethical hacking
  • White hat attack
  • Security checkup

In information security testing, a network, computer system or web application is tested to identify the security gaps an attacker could exploit.

Penetration testing and information security

Penetration tests can be automated with various applications or performed manually. In both cases the process involves gathering information about the target, identifying possible entry points, attempting to get in (penetrate) and sharing the findings. Best practice is to run the tests with more than one automated tool and then verify the results manually.

A penetration test is run to expose vulnerabilities, design weaknesses and risks in networks, systems and applications before malicious attackers find them. It also shows how adequate the security policy is, how well compliance requirements are met, how aware staff are of security issues, how well the organization detects and responds to security incidents, and how likely it is to suffer a serious security incident.

Typically, the information gathered about security weaknesses identified and/or exploited through penetration testing is presented to the organization’s decision makers, allowing it to prioritize strategic decisions and remediation efforts.

Penetration tests can also expose weaknesses in a company’s security policies. For example, a security policy may focus on detecting and preventing attacks on the organization’s systems, yet not include a process for removing an attacker who is already inside.

The penetration testing process consists of seven core steps

1. Scoping

The goal is to define the objectives of the penetration test and the IT environments in which the tests will be carried out.

At this stage, the necessary preliminary information is obtained from the organization in order to plan the work. Based on this information, the nature and scope of the test, the targeted environments, and the dates and times suitable for the organization are determined.

Once the scope is set and before testing begins, the following steps are taken:

  • The teams taking part and the contact persons for the tests are named, both at the organization and at the testing company
  • A test plan is created
  • Based on the information received, the dates and time windows for the work are set
  • Contact persons to reach in case of emergency are designated
  • Agreement is reached with the organization on the scope of the service, the methodology and the tests to be performed
  • A service agreement is signed with the organization to provide mutual legal protection
2. Information Gathering / Reconnaissance

Information gathering is the most important stage of testing and makes up 80–90% of the overall penetration testing effort. The more accurate and sufficient the information gathered at this stage, the more accurate and efficient the tests will be.

Information is gathered using two different methods: passive and active information gathering.

Passive information gathering: The target is unaware of the person gathering information, and publicly available sources are used, including the following:

  • Forums
  • Dictionary sites
  • Community sites
  • Social media
  • News sites
  • Search engines

Active information gathering: Contact is made with the target while gathering information, leaving records of that access on the target. Active information gathering generally uses the following:

  • Websites
  • Scans
  • Port scanning
  • Vulnerability scanning
  • Operating system scanning
  • Service scanning

If, once the purpose and scope are set, the organization provides information about itself and the systems to be tested, some information gathering steps become unnecessary and this stage takes less time.

3. Vulnerability Detection

Using the information obtained in the second step, vulnerability detection begins. The work focuses on learning what kinds of vulnerabilities exist in the target environments, how they could be exploited, what kinds of attacks are possible, how the system responds to them and whether it protects itself.

At this stage a general scan of the system is carried out with utility programs and tools. They reveal details such as open ports, which service runs on which port and which version of that service is in use; any known vulnerability in those versions can then be identified directly.

4. Information Analysis / Planning

Using the vulnerabilities identified in the previous step, the research, planning and preparation needed to penetrate the system are carried out.

5. Exploitation

At this stage, exploitation attempts are made against the vulnerabilities identified in the previous steps. Purpose-built tools (exploits, payloads, etc.) are used to try to get into (penetrate) the target system.

Privilege escalation: If access to the system is gained, attempts are made to raise the privilege level in order to control more of the system and perform more actions, although this does not always succeed.

Lateral movement: After compromising one machine, testers check whether other machines can be reached from it.

Persistence: Methods for keeping the connection, such as leaving a backdoor, are tried.

6. Results Analysis / Reporting

At this stage, the results of the work carried out in the previous steps are evaluated. The systems that could be affected by the identified vulnerabilities, the potential damage, and the measures that can be taken to eliminate the identified risks are reported.

7. Clean-up

Any changes made to the systems during the test are reverted; for example, files created or users defined during testing are deleted.

How Often Should Penetration Testing Be Done?

To keep IT environments consistently secure and well managed, organizations should run penetration tests regularly: at least once a year, or every six months as best practice.

Besides the analyses and assessments required by regulations, penetration tests can also be carried out in the following situations:

  • After new network infrastructure, systems or applications are added to the IT environment
  • After significant software or hardware changes to applications or infrastructure
  • After security patches are applied
  • After end-user policies are changed
  • After new working environments are set up at other locations

Penetration tests should be tailored to the organization as much as to the sector it operates in, and their results should cover the identified vulnerabilities as well as follow-up and evaluation tasks. When deciding how often to test, the following factors are considered:

Company Size

Companies with a larger online presence have more attack vectors and are therefore more attractive targets for attackers.

Cost

Penetration tests can be costly depending on the size of the targeted scope. A company with a smaller budget may therefore not be able to test more than once a year when there is no legal requirement, while a company with a larger budget may test every six months or yearly, or after changes that make a test necessary.

Regulations and Compliance

Organizations in certain sectors are required by law to carry out specific security tasks, including penetration tests.

Use of the Cloud

For a company whose infrastructure is in the cloud, the cloud service provider may not allow its infrastructure to be tested. The provider may, however, be running penetration tests on its own.

What Is a Penetration Tester? Which Tools Are Used?

Penetration testers generally use automated tools to uncover standard vulnerabilities. As best practice, scanning the same environments with several tools minimizes the risk of vulnerabilities being missed. Following automated scans with manual testing to confirm the vulnerabilities they report is also important.

Penetration testing tools scan code to identify malicious code in applications that could lead to a security breach. They also examine data encryption techniques and can identify hard-coded values such as usernames and passwords to verify vulnerabilities in the system.

The most essential features a penetration testing tool should have are:

  • Easy to install, configure and use
  • Able to scan systems easily
  • Able to classify vulnerabilities by severity (e.g. Urgent, Critical, High, Medium, Low)
  • Able to automate vulnerability verification
  • Able to re-verify previous exploits
  • Able to produce detailed vulnerability reports and logs

Most popular penetration testing tools are free or open source, which lets penetration testers modify or adapt the code to their needs. Some of the most widely used free or open-source tools are:

1. Metasploit Project

An open-source project owned by the security company Rapid7, which licenses full-featured editions of Metasploit. It brings together popular penetration testing tools for servers, online applications and networks. Metasploit can be used to uncover security issues, verify that vulnerabilities have been mitigated or eliminated, and manage security processes.

2. Nmap (Network Mapper)

Short for “Network Mapper”, Nmap is a port scanner that scans systems and networks for vulnerabilities in open ports. Nmap is pointed at the IP address(es) of the system or network to be scanned, and those systems are tested for open ports. Nmap can also be used to monitor the uptime of servers or services and to map network attack surfaces.

3. Wireshark

A network protocol analyser (sniffer) that captures and inspects network packets. It shows network traffic in full detail and in real time; in penetration tests it is used to examine traffic at different layers.

4. John the Ripper

Software that combines different password crackers in a single package. It automatically recognizes different types of password hashes and picks the cracking method to match. In penetration tests it is typically used to launch attacks that find weak passwords in systems or databases.

Penetration testers use most of the same tools as black hat (malicious) hackers. Besides being widely available, these tools help testers better understand how they could be used against organizations.

Penetration Testing Strategies

The most important aspect of any penetration test is defining the scope the testers must work within. The scope usually defines which systems, locations, techniques and tools may be used. A well-defined scope helps the test team stay focused on the target and ensures complete, satisfactory results.

For example, if access to a system is gained because an employee left their password in plain sight, this shows that the employee violated the security policy, but tells the testers nothing about the security of the compromised application.

Using different penetration testing strategies helps the testing teams focus on the desired systems and gain insight into the most threatening types of attack. Some of the main strategies used by security professionals are:

1. Targeted Testing

The tests are carried out jointly by the organization’s IT team and the penetration testing team, and everyone can see that the test is under way.

2. External Testing

Covers a company’s externally visible devices and systems that can be reached from the internet. External testing targets domain name servers, e-mail servers, web servers or firewalls. Its goal is to find out whether an attacker can get in from outside and, once in, how far they can get by exploiting that vulnerability.

3. Internal Testing

Simulates an insider attack behind the firewall by a user with standard access rights. Internal tests are useful for estimating how much damage a disgruntled employee could do to the IT environment.

4. Blind Testing

Simulates the actions of a real attacker by severely limiting the information given to the tester or team in advance. Typically the testers are given only the company’s name. Because reconnaissance can take considerable time, this type of test can be long and costly.

5. Double-Blind Testing

Only one or two people in the organization may know the test is taking place. Double-blind tests are useful for testing an organization’s security monitoring and incident identification, as well as its response procedures.

6. Black-Box Testing

Essentially the same as blind testing, but the tester receives no information at all before the test. Instead, the testers find their own way into the systems.

7. White-Box Testing

The testers are given information about the target network before they start. This can include details such as IP addresses, network diagrams, the protocols in use, and source code.

8. Penetration Testing as a Service (PTaaS)

A traditional penetration test assesses an organization’s technical infrastructure as it stands at the time of testing. PTaaS goes a step further and allows testing to run continuously: IT infrastructure, systems and applications are tested on an ongoing basis to identify potential vulnerabilities, so they can be found and fixed faster. PTaaS providers usually work on an annual subscription covering a business’s entire technical infrastructure, and many also offer regular vulnerability scan reports (daily, weekly, bi-weekly, monthly, quarterly, etc.) and live scans on demand.

BDDK Compliant Pentest

Our BDDK Compliant Penetration Testing Service

Banking and finance is one of the sectors most targeted by cyber attacks, and these attacks often cause financial and reputational losses.

For this reason, the “Communiqué on the Principles to Be Taken as Basis in Information Systems Management in Banks”, published by the Banking Regulation and Supervision Agency (BDDK) on 24.07.2012 with number B.02.1.BDK.0.77.00.00/010.06.02-1, sets out the minimum procedures and principles for managing the information systems banks use in their operations, including the management of the risks and vulnerabilities those systems may be exposed to.

Sub-paragraph (ç) of the third paragraph of Article 7, “Establishing and managing the security control process”, in Part Two, Section One, “Risk Management for Information Systems”, of that communiqué states:

“Processes shall be established to ensure that the reliability and consistency of information systems are reviewed regularly. Within this framework, penetration tests shall be performed at regular intervals by independent teams that have no executive duty in fulfilling the requirements of the security provisions. Current developments and new vulnerabilities in the field of security shall be followed, necessary software updates shall be made and necessary patches shall be applied.”

With this provision, penetration testing became mandatory for the banking sector.

As the types of cyber attacks against information systems evolve and change rapidly, a decision of the Banking Regulation and Supervision Board set the frequency of the penetration tests required by that provision at no less than once a year.

Under this decision, all institutions operating in the banking sector, with its high security needs, must have their networks, systems, hardware, software and users tested against various scenarios subject to specific conditions approved by the BDDK, and must present the resulting data as a report. This way, the vulnerabilities and possible security risks of the institution’s information systems are identified, and work to close the identified gaps can begin.

How Is a BDDK Compliant Penetration Test Performed?

According to the circular published by the BDDK, the work carried out within the scope of penetration testing covers, at a minimum, the following areas:

  • External Network Penetration Test
  • Communication Infrastructure and Active Devices
  • Domain and User Computers
  • DNS Services
  • E-mail Services
  • Database Systems
  • Web Applications
  • Wireless Network Systems
  • Denial of Service Tests
  • Social Engineering Tests
  • Internal Network (Intranet) Penetration Test
  • Mobile Applications
  • ATM Systems
  • Source Code Analysis

DDoS / DoS Testing

Our DDoS/DoS Testing Service

Denial of Service (DDoS/DoS) attacks exploit the fact that network resources have limited capacity, aiming to disrupt the services delivered over those networks or to take the targeted network out of service entirely.

DDoS/DoS attacks are among the attack vectors encountered more and more every day. They harm both organizations and the customers those organizations serve.

Denial of service tests clearly show how well systems and networks are protected against such attacks. By simulating a DDoS/DoS attack under controlled conditions, we learn whether the necessary protective measures exist and are sufficient. The measures needed to eliminate the identified design flaws, vulnerabilities and risks can then be taken, ensuring the continuity of the IT infrastructure.

With our DDoS/DoS testing service, we aim to determine how resilient organizations are against potential attacks. Carried out in a safe, controlled environment, our DDoS/DoS tests are scenario-based and also cover the network infrastructure.

Red Team

Our Red Team Service

The Red Team service is a multi-layered attack simulation designed to measure how well an organization’s cyber defences hold up against a real attack. The work is carried out by a team called the Red Team: security experts who act like attackers and try to get past the organization’s cybersecurity measures and controls.

The Red Team service focuses on the organization’s technology, people and physical premises, using a variety of techniques to find vulnerabilities in these areas.

These techniques include various attack vectors such as adversary simulation, black-box penetration testing and breach scenarios built on vulnerability findings, as well as gaining access to sensitive data by getting past physical security controls through social engineering.

You may think your company is “too small” or “too uninteresting” to be attacked, but research shows that small and medium-sized companies are just as exposed and vulnerable as large multinationals, and often become targets precisely because of their limited security measures and controls.

Teams in Cybersecurity

Red Team

The team that uses the real-world attack methods of malicious hackers to raise an organization’s level of protection. Made up of white hat (ethical) hackers, the Red Team uses real attackers’ tools, techniques and methods to test the organization’s security across systems, people and processes. It is offence-focused and simulates how an attacker would get past the organization’s defences.

Blue Team

The team that designs, deploys and operates the protective cybersecurity infrastructure. It performs core functions such as finding and fixing cybersecurity errors and vulnerabilities, eliminating security-related configuration issues, monitoring and analysing security environments and events, and keeping systems up to date. The Blue Team is defence-focused and works with the Red Team to build a strong cybersecurity environment.

Purple Team

Set up so that the Red and Blue Teams work together and share information regularly. It combines offensive and defensive thinking. Often it isn’t a separate team at all, but the name for the cooperation between the Red and Blue Teams.

Tiger Team

Similar to, but not the same as, the Red Team. It consists of experts brought together to solve a specific cybersecurity problem.

Benefits of the Red Team Service

The main benefits of a Red Team engagement:

1. Multi-dimensional

A typical Red Team engagement covers the technological, social (human) and physical dimensions and reveals whether the organization has vulnerabilities in any of these layers. Alongside penetration testing of technological systems (network, system, web application, mobile, etc.), it uses social engineering (phone, e-mail, SMS, face-to-face contact, etc.) and physical intrusion (avoiding cameras, bypassing alarms, gaining unauthorized access, etc.) to determine how prepared the security components are against malicious actors.

2. The Most Realistic Attack

Using the techniques, tactics and procedures of real-world threat actors, it shows how prepared the organization is for cyber attacks carried out as realistically as possible.

3. Risk

By identifying the organization’s vulnerabilities and risks, it allows all relevant assets to be classified by their level of exposure and sensitivity priority.

4. Detection – Response

Using complex, targeted real-world attack scenarios, it provides data to demonstrate and evaluate the detection, response and prevention capability of your teams and products, revealing how ready the organization is for cyber attacks.

5. Process Effectiveness

It audits the organization’s security processes, measures their maturity and effectiveness, and uses the results to provide data for maturing those processes.

6. Infrastructure Improvement

Once existing vulnerabilities are identified, it helps create a roadmap of what needs to be done to improve your security infrastructure.

7. Training – Development

The engagement is a good training environment for the organization’s cybersecurity team (the Blue Team). Working with professional, experienced attackers lets security teams learn the tools, methods and techniques real attackers could use to get into the organization and its confidential data.

8. Building Awareness

By giving feedback on the level of information security awareness in your organization, it helps spread and raise that awareness.

9. Regulatory Compliance

It meets the requirement to comply with the cybersecurity laws and regulations the organization is subject to.

10. Budget – Approval

Demonstrating how a real (serious) cyber attack could harm the organization and its data makes clear which investments are needed for a robust security infrastructure, and makes them easier to approve.

Our Red Team Methodology

The types of security tests carried out within a Red Team engagement are determined by the client’s security needs. For example, one organization may bring all its systems and network infrastructure, or only certain parts of them, into scope, while another may aim to test a single piece of software or web application it considers critical.

Usable in any engagement regardless of the planned scope, our Red Team methodology has been developed in line with globally recognized industry standards.

Differences Between Red Teaming and Penetration Testing

Red Team engagements and penetration tests are often confused. Although both aim to identify security vulnerabilities, they differ significantly in practice. A classic penetration test focuses on technology, whereas a Red Team engagement is broader, covering the social (human) factor and physical means and environments as well as technology.

When the tests in the Compliance (control and audit) and Risk Reduction (vulnerability scanning, penetration testing, security infrastructure analysis, source code analysis) categories are compared by scope and by the information the organization provides, the Red Team engagement is the most comprehensive, requires the most working time, and comes closest to simulating real-world threats.

A Red Team engagement shows how well your systems would hold up against a real attack, without having to suffer one. Write to us to plan the scope and schedule.

Social Engineering

Our Social Engineering Service

Social engineering is a general term for activities carried out through human interaction that rely on various methods of persuasion to obtain the desired information.

Most people and organizations face social engineering attacks.

Social engineering attacks essentially take place in four stages: information gathering, building a relationship, exploitation and access.

Technical measures alone cannot stop these attacks. People are the weakest link in the security chain, and no system that involves people can be fully protected against social engineering. Social engineers target this link to get past an organization’s defences.

Although no defence can close these gaps completely, it is possible to reduce the risks and so minimize the potential damage. The most effective defence is auditing. Regular audits should be used to identify weaknesses, and their results should be used both to find and fix gaps in the organization’s security policies and to educate employees and raise their awareness.

With this service, we use a range of social engineering scenarios to determine how prepared your employees are for such attacks and how effective your security policies are. By evaluating the results, we identify your employees’ training gaps and present the measures to be taken.

Our Other Services

Our Accreditations