Before executing a penetration test on a system or network, we must first create the rules of engagement or a plan of action. It won't be professional if a penetration tester simply rushes into a network and launches random attacks against the target. In addition, having a plan of action makes the job at hand a bit simpler when deciding on the tools and types of attacks based on the vulnerabilities on the target.
Phases of penetration testing
The pre-attack phase
The pre-attack phase focuses on the planning and preparation of the penetration test, this is done prior to any direct engagements to the target system or network. During this phase, the penetration tester would be creating an arsenal of tools, scripts, and operating...