EXTERNAL PENTEST

Attack Strategy

External Pentest Checklist

Verifying Scope

Nessus Parser

Information Gathering OSINT

Hunting Breached Credentials

Identifying Employees & Emails

Enumerating Valid Accounts (Pre-Attack)

Attacking Login Portals

Password Spraying : Office 365, Outlook Web App, Okta SSO

Outlook Web App (OWA) Brute Force Utility

msf6 > auxiliary/scanner/http/owa_login

Bypassing Microsoft 365 MFA

Search through email in Microsoft Exchange

Common Pentest Findings

Insufficient Authentication Controls

Weak Password Policy

Insufficient Patching

Default Credentials

Insufficient Encryption

Information Disclosure

Username Enumeration

Default Web Pages

Open Mail Relays:

IKE Aggressive Mode

Unexpected Perimeter Services

Ex: RDP, Telnet, FTP, ...

Insufficient Traffic Blocking

Undetected Malicious Activity

Last updated