A Logo

Feel free to include my content in your page via my
RSS feed

Help Irongeek.com pay for
bandwidth and research equipment:

Subscribestar or Patreon

Search Irongeek.com:

Affiliates:
Irongeek Button
Social-engineer-training Button

Help Irongeek.com pay for bandwidth and research equipment:

paypalpixle


Common Assessment Mistakes Pen Testers and Clients Should Avoid - Brent White & Tim Roberts Derbycon 2017 (Hacking Illustrated Series InfoSec Tutorial Videos)

Common Assessment Mistakes Pen Testers and Clients Should Avoid
Brent White & Tim Roberts
Derbycon 2017

Penetration assessments can be a stressful time for those involved. It’s a moment where the network admins find out if the network they manage, or maybe even helped to build, holds up against simulated attacks. Or, it’s a moment as a pen tester where you can help the client and strengthen their security posture, or screw things up by making a mistake - potentially losing a client and giving your company a black eye. However, this shouldn’t be a stressful time. As a client, it is important to understand why the test is taking place and how this helps. As a pentester it is important that you know what you are doing, need to ask for and aren’t just going in blind or throwing the kitchen sink at the network. This talk is to highlight common issues that we’ve either encountered or have have been vented to about from both the penetration tester’s side of the assessment as well as the client’s side. We’d like to bring these issues to light to hopefully help ensure a more smooth assessment “experience” for all parties involved.

Tim and Brent are Sr. Security Consultants within NTT Security’s Threat Services group. They have developed Red Team and Social Engineering testing methodologies and have spoken at internationally recognized security conferences including DEFCON, DerbyCon, B-Sides, ISSA International, AIDE at Marshall Univ, Techno Sec & Forensics Invest. Con, and more. Tim has held management, IT and physical security roles across multiple industries, including healthcare and government. He is a regular contributor to NTT Security’s ‘#WarStoryWednesday' series, has developed methodologies for for red team and social engineering assessments and has been featured in CSO on the subject of onsite social engineering Brent is the founding member of the Nashville Def Con group (DC615), and is a supervisor for the Def Con conference “Groups” program. He has also held several IT roles including Security Director of a global franchise company as well as Web Manager and information security positions for multiple television personalities and television shows on The Travel Channel. He has also been interviewed on the topic of social engineering on the popular web series, “Hak5” with Darren Kitchen. Both have been interviewed on the topic of “White hat hacking” for Microsoft’s “Roadtrip Nation” television series. Their experiences with traditional/non-traditional pentesting techniques include network, wireless, social engineering, application and physical testing. These techniques have led to highly successful Red Team assessments against corporate environments. By sharing their experiences, they hope to continue to contribute to the InfoSec community.

Brent White - @brentwdesign, Tim Roberts - @zanshinh4x

Back to Derbycon 2017 video list

Printable version of this article

15 most recent posts on Irongeek.com:


If you would like to republish one of the articles from this site on your webpage or print journal please contact IronGeek.

Copyright 2020, IronGeek
Louisville / Kentuckiana Information Security Enthusiast