🌐External Pentesting
ROE (Rules of Engagement)
Verify Scope
Vulnerability Scan
External OSINT
Breach Creds
Identifying Emails & Employees
Enumerating valid accounts
Attacking
Attacking Login Portals
OWA (Outlook Web Access)
Other Portals
Bypassing MFA
Escalating Privileges
Common Findings
Insufficient Auth Controls
Weak Password Policy
Insufficient Patching
Default Credentials
Insufficient Encryption
Information Disclosure
Username Enum
Default Pages
IKE Aggressive Mode
Unexpected Open Ports
Insufficient traffic Blocking
Undetected Malicious Activity
Historical account compromised
Last updated