1/18
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai |
|---|
No analytics yet
Send a link to your students to track their progress
Penetration Testing
Professional hacking to access data and computing power without being granted access; professional pen-testers are hired to identify and repair vulnerabilities and only work once, given written permission to obtain ungranted access.
Known environment
An environment where the outcomes or outcome probabilities are given
Unknown environment
The pentester knows nothing about the systems under attack
Partially known environment
A partially known environment penetration test is a focused approach that usually provides detailed information about specific systems or applications.
Rules of engagement
obtaining authorization before conducting any penetration or vulnerability test
Lateral movement
The process by which an attacker is able to move from one part of a computing environment to another.
Privilege Escalation
An attack that exploits a vulnerability in software to gain access to resources that the user normally would be restricted from accessing.
Persistence
an attacker's ability to maintain a presence in a network for weeks, months, or even years without being detected
Cleanup (Penetration testing)
Leave the network in its original state
Bug bounty
Reward scheme operated by software and web services vendors for reporting vulnerabilities.
Pivoting (Penetration Testing)
Gain access to systems that would normally not be accessible
War Flying (reconnaissance)
flying in private planes or with drones while collecting information on wireless networks
War Driving
Deliberately searching for Wi-Fi signals while driving by in a vehicle
Footprinting
the process of systematically identifying the network and its security posture (usually a passive process)
OSINT
Open Source INTelligence; gathered from publicly available sources
Red Team
The "hostile" or attacking team in a penetration test or incident response exercise.
Blue Team
The defensive team in a penetration test or incident response exercise.
White Team
Staff administering, evaluating, and supervising a penetration test or incident response exercise.
Purple Team
Made up of both the blue and red teams to work together to maximize their cyber capabilities through continuous feedback and knowledge transfer between attackers and defenders.