EXTERNAL PENTEST
Attack Strategy
External Pentest Checklist
Verifying Scope
Nessus Parser
Information Gathering OSINT
Hunting Breached Credentials
Identifying Employees & Emails
Enumerating Valid Accounts (Pre-Attack)
Attacking Login Portals
Password Spraying : Office 365, Outlook Web App, Okta SSO
Outlook Web App (OWA) Brute Force Utility
msf6 > auxiliary/scanner/http/owa_login
Bypassing Microsoft 365 MFA
Search through email in Microsoft Exchange
Common Pentest Findings
Insufficient Authentication Controls
Weak Password Policy
Insufficient Patching
Default Credentials
Insufficient Encryption
Information Disclosure
Username Enumeration
Default Web Pages
Open Mail Relays:
IKE Aggressive Mode
Unexpected Perimeter Services
Ex: RDP, Telnet, FTP, ...
Insufficient Traffic Blocking
Undetected Malicious Activity
Last updated