What is a Pentest in Terms of scope
Pentest - controlled simulation of an attack on a pre-agreed set of systems. The key word here is "pre-agreed." Before starting work, the pentester and the customer sign Rules of Engagement, where it is clearly prescribed: which IP addresses, applications and networks are allowed to be tested, at what time you can work and what methods are permissible. Sometimes the client wants to test a system that does not even belong to him - and it would be simply illegal to test it. Therefore, the scope is fixed before the first scan.
For those in the tank - analogy. Pentest is not checking the whole house for strength. This is a lock check on the front door at the agreed time. Windows, blackout, alarms, and tenant behavior remain outside the frames if they are not included in the scope.
What checks the penetration test in a typical project:
External perimeter - web applications, APIs, VPN gateways, mail servers. Pentester launches nmapfor discovering open ports and services (Network Service Discovery, T1046 by MITRE ATT&CK), then proceeds to manual analysis in Burp Suite.
Internal network - if scope includes an internal pentest. Check segmentation, access rights, the possibility of privilege . LinPEAS helps to find a way from low-priv user to root through misconfiguration (Exploitation for Privilege Escalation, T1068).
Web applications - injections (A03:2021 on OWASP), access control violations (A01:2021), authentication errors (A07:2021), obsolete components (A06:2021).
Configurations - misconstruction of servers, cloud environments, network equipment (A05:2021 on OWASP).
The result is a specific verdict: "vulnerability exploited" or "vulnerability not detected within the allotted time and scope." And here lies the main thing: "not found" ! = "does not exist."
What does the pentest not cover
Pentest restrictions are not a defect in the method, but its nature. Understanding the blind spots is critical not to build a false sense of security on a clean report.
Insider threats
Pentest simulates an external attacker or attacker with limited access. But he does not simulate an employee who has been copying the client base for months on a personal flash drive. Valid Accounts (T1078 by MITRE ATT&CK) - one of the most frequent techniques of real attackers: the use of legitimate credentials for initial access, consolidation and increase of privileges. Pentest can check password persistence through Brute Force (T1110), but will not determine that a particular Ivanov from the accounting department already transfers his credits to a third party.
Insider threats are one of the main blind spots of the standard test. They require behavioral analysis of authorized users (UEBA, DLP) rather than finding technical vulnerabilities. The pentester is looking for holes in the fence, rather than watching who of his steals from the warehouse.
Social Engineering Beyond
Phishing, pretexting, tossing infected flash drives - all this can be included in the scope, but usually not included. The reasons are prosaic: legal risks, unwillingness to "scare" employees, budget. According to CERT-UA, phishing accounts for 71% of incidents. The most frequent vector of real attacks - and it remains untested in most standard pentests.
Testing without social engineering is like checking the lock without regard to the fact that the owner leaves a key under the mat.
Zero day vulnerabilities and business logic errors
Zero-day is a vulnerability that neither the vendor nor the researchers know. The pentester works with well-known CVE and public operating techniques. There is no public exploit - the standard testing vulnerability will not find. The point.
Business logic errors are a separate headache. This is not a SQL injection, but a situation where the user can apply a discount twice, bypass the process of agreeing on a non-standard sequence of actions or approve his own request due to the workflow bypass. Such things require a deep understanding of the customer's business processes. Pentester in one or two weeks of work rarely immerses in logic enough to detect such defects. He sees the app from the outside, not inside the business.
Continuous monitoring and long-term threats
Pentest - snapshot, point-in-time assessment. It shows the state of protection at the time of the event. Tomorrow someone will open the port "for a time," will update the library with a new vulnerability or add an API-endpoint without authorization - and the results are obsolete. On NIST Cybersecurity Framework (CSF v2.0), Detect (DE) and Respond (RS) functions are continuous processes. The Pentest does not apply to them.
APT groups have been running for months, slowly anchoring in infrastructure through Exploitation of Remote Services (T1210) and Lateral movement. The two-week pentest is physically unable to replicate such a scenario - it simply doesn't have so much time.
Pentest vs Monitoring: The Difference of Approaches
The difference between the pentest and continuous safety is between the examination of the doctor and the wearable pulse oximeter. The examination will reveal the current problems, but will not record the arrhythmia in a week.
Criterion Pentest Continuous monitoring
Frequency Once every 6-12 months Constantly
Depth High on narrow scope Wide, less deep
What finds exploited vulnerabilities Anomalies, new threats, configuration drift
Blind areas Everything outside of scope and time Complex operating chains
Format of the result Report with recommendations Alerts and dashboards in real time
No method replaces the other. Pentest proves exploitability is his strong side. Monitoring is recording what is happening right now. Together, they give an adequate assessment of security; separately, they do not.
Pentest Alternatives and Complementary Methods
Pentest as a method of safety assessment works, but only in conjunction with other approaches. Here’s what complements it – and when each method is appropriate:
Vulnerability Scanning - regular automatic scanning. The scanner will not build an attack chain of three vulnerabilities (this is a human task), but catches known CVE between tests. OpenVAS, Nessus - tools for intermediate control. Free entry point - OpenVAS, for those who have a budget at zero.
Red Team - extended version of the pentest without strict scope restrictions. Includes social engineering, physical penetration, long-term consolidation. It takes weeks or months. Significantly more expensive than the standard pentest, but simulates the real opponent - with his patience and ingenuity.
Bug Bounty - external researchers are looking for vulnerabilities constantly, without a time frame. Closes the gap between the annual pentests. For the Russian market it is worth taking into account the nuances: KYC-procedures on platforms, sanctions restrictions on payments, legal registration.
SIEM and SOC - collecting and analyzing real-time security events. This is the most continuous security that the pentest lacks. Without the SOC, the organization learns about the incident from the news. For start without a budget - Wazuh (open-source SIEM) closes the basic needs.
Audit of configurations - compliance check of standards settings (CIS Benchmarks, NIST SP 800-53). Catching misconfigurements that the pentester could not reach in the allotted time.
The difference between a pentest and an audit: a pentest proves that vulnerability can be exploited. The audit checks compliance with the standards without attempting to hack. The first answers the question "can I break," the second - "is it correct on documents."
Pentest - controlled simulation of an attack on a pre-agreed set of systems. The key word here is "pre-agreed." Before starting work, the pentester and the customer sign Rules of Engagement, where it is clearly prescribed: which IP addresses, applications and networks are allowed to be tested, at what time you can work and what methods are permissible. Sometimes the client wants to test a system that does not even belong to him - and it would be simply illegal to test it. Therefore, the scope is fixed before the first scan.
For those in the tank - analogy. Pentest is not checking the whole house for strength. This is a lock check on the front door at the agreed time. Windows, blackout, alarms, and tenant behavior remain outside the frames if they are not included in the scope.
What checks the penetration test in a typical project:
External perimeter - web applications, APIs, VPN gateways, mail servers. Pentester launches nmapfor discovering open ports and services (Network Service Discovery, T1046 by MITRE ATT&CK), then proceeds to manual analysis in Burp Suite.
Internal network - if scope includes an internal pentest. Check segmentation, access rights, the possibility of privilege . LinPEAS helps to find a way from low-priv user to root through misconfiguration (Exploitation for Privilege Escalation, T1068).
Web applications - injections (A03:2021 on OWASP), access control violations (A01:2021), authentication errors (A07:2021), obsolete components (A06:2021).
Configurations - misconstruction of servers, cloud environments, network equipment (A05:2021 on OWASP).
The result is a specific verdict: "vulnerability exploited" or "vulnerability not detected within the allotted time and scope." And here lies the main thing: "not found" ! = "does not exist."
What does the pentest not cover
Pentest restrictions are not a defect in the method, but its nature. Understanding the blind spots is critical not to build a false sense of security on a clean report.
Insider threats
Pentest simulates an external attacker or attacker with limited access. But he does not simulate an employee who has been copying the client base for months on a personal flash drive. Valid Accounts (T1078 by MITRE ATT&CK) - one of the most frequent techniques of real attackers: the use of legitimate credentials for initial access, consolidation and increase of privileges. Pentest can check password persistence through Brute Force (T1110), but will not determine that a particular Ivanov from the accounting department already transfers his credits to a third party.
Insider threats are one of the main blind spots of the standard test. They require behavioral analysis of authorized users (UEBA, DLP) rather than finding technical vulnerabilities. The pentester is looking for holes in the fence, rather than watching who of his steals from the warehouse.
Social Engineering Beyond
Phishing, pretexting, tossing infected flash drives - all this can be included in the scope, but usually not included. The reasons are prosaic: legal risks, unwillingness to "scare" employees, budget. According to CERT-UA, phishing accounts for 71% of incidents. The most frequent vector of real attacks - and it remains untested in most standard pentests.
Testing without social engineering is like checking the lock without regard to the fact that the owner leaves a key under the mat.
Zero day vulnerabilities and business logic errors
Zero-day is a vulnerability that neither the vendor nor the researchers know. The pentester works with well-known CVE and public operating techniques. There is no public exploit - the standard testing vulnerability will not find. The point.
Business logic errors are a separate headache. This is not a SQL injection, but a situation where the user can apply a discount twice, bypass the process of agreeing on a non-standard sequence of actions or approve his own request due to the workflow bypass. Such things require a deep understanding of the customer's business processes. Pentester in one or two weeks of work rarely immerses in logic enough to detect such defects. He sees the app from the outside, not inside the business.
Continuous monitoring and long-term threats
Pentest - snapshot, point-in-time assessment. It shows the state of protection at the time of the event. Tomorrow someone will open the port "for a time," will update the library with a new vulnerability or add an API-endpoint without authorization - and the results are obsolete. On NIST Cybersecurity Framework (CSF v2.0), Detect (DE) and Respond (RS) functions are continuous processes. The Pentest does not apply to them.
APT groups have been running for months, slowly anchoring in infrastructure through Exploitation of Remote Services (T1210) and Lateral movement. The two-week pentest is physically unable to replicate such a scenario - it simply doesn't have so much time.
Pentest vs Monitoring: The Difference of Approaches
The difference between the pentest and continuous safety is between the examination of the doctor and the wearable pulse oximeter. The examination will reveal the current problems, but will not record the arrhythmia in a week.
Criterion Pentest Continuous monitoring
Frequency Once every 6-12 months Constantly
Depth High on narrow scope Wide, less deep
What finds exploited vulnerabilities Anomalies, new threats, configuration drift
Blind areas Everything outside of scope and time Complex operating chains
Format of the result Report with recommendations Alerts and dashboards in real time
No method replaces the other. Pentest proves exploitability is his strong side. Monitoring is recording what is happening right now. Together, they give an adequate assessment of security; separately, they do not.
Pentest Alternatives and Complementary Methods
Pentest as a method of safety assessment works, but only in conjunction with other approaches. Here’s what complements it – and when each method is appropriate:
Vulnerability Scanning - regular automatic scanning. The scanner will not build an attack chain of three vulnerabilities (this is a human task), but catches known CVE between tests. OpenVAS, Nessus - tools for intermediate control. Free entry point - OpenVAS, for those who have a budget at zero.
Red Team - extended version of the pentest without strict scope restrictions. Includes social engineering, physical penetration, long-term consolidation. It takes weeks or months. Significantly more expensive than the standard pentest, but simulates the real opponent - with his patience and ingenuity.
Bug Bounty - external researchers are looking for vulnerabilities constantly, without a time frame. Closes the gap between the annual pentests. For the Russian market it is worth taking into account the nuances: KYC-procedures on platforms, sanctions restrictions on payments, legal registration.
SIEM and SOC - collecting and analyzing real-time security events. This is the most continuous security that the pentest lacks. Without the SOC, the organization learns about the incident from the news. For start without a budget - Wazuh (open-source SIEM) closes the basic needs.
Audit of configurations - compliance check of standards settings (CIS Benchmarks, NIST SP 800-53). Catching misconfigurements that the pentester could not reach in the allotted time.
The difference between a pentest and an audit: a pentest proves that vulnerability can be exploited. The audit checks compliance with the standards without attempting to hack. The first answers the question "can I break," the second - "is it correct on documents."