# How Things Work

We perform primarily internal and external network penetration tests for our clients. Most engagements are performed remotely using a virtual appliance running a modified Kali Linux. This is high-level overview of our process.

# Connecting to Your Testing Appliance

When you are assigned to a test, you will be given a list of URLs to access the virtual appliance services. For example, https://client-ssh.itasredteam.com or https://client-vnc.itasredteam.com. Despite the fact that these resources are accessed via URLs, they are NOT accessible to the public. These URLs route through the Cloudflare Zero Trust Network and will not grant access to the resource until verifying your identity with SSO. Both SSH and VNC can be accessed by entering the URLs in the web browser, but SSH also can be accessed through the Terminal app which is strongly reccomended. The output in the Terminal app is much more readable and uses colors compliant with our style guide.

# Running the Penetration Test

The engagement will primarily be managed through GhostWriter. The IP lists, exclusions, and other notes can be found here. You can use the included notes feature or keep your own notes on your workstation. Findings will be added to Ghostwriter as they are discovered.

# Scanning

Most engagements will include a Qualys vulnerability scan. We offer both credentialed and un-credentialed scans, and most clients opt for the former. Currently, scanning appliances are deployed separately from the penetration testing appliance. Qualys appliances are only available as pre-built virtual appliances, so running them separately avoids relying on nested virtualization and the assocaited performance and compatibility problems.

You will access the QualysGuard web console via SSO to configure and run the scan. When launching the scan, add yourself as a notification recipient to be notified when it completes.

Scan issues are unfortunately fairly common and becoming more so. Often times the provided account has not been properly configured. We also see instances where the scans are being blocked by internal security controls. Don't worry too much when this happens, we have the expertise on the team to troubleshoot any issues.

# Exit Meeting

Most clients opt for an exit meeting, and some request multiple. A summary memo will be prepared for the engagement. Proof-read the memo carefully, and review your findings so you are prepared to answer questions during the meeting.

# Reporting

Reporting is always a large time commitment, but it is the single most important reflection of the quality of our work. Reporting "as-you-go" is universally considered to be a best practice, and it far beats waiting until the end. This is especially true for the "Assessment Narrative" section of the report, which goes through everything that was tested. The report templates include an outline for that section, which can help give you an idea of how it should look. Prepare to make extensive modifications and add screenshots. The findings can be exported directly from GhostWriter, and will be properly formatted to copy into your report template.