Checks - Reporting with Executive Summary and Risk Profiling - Read Out Call - Post Pentest Support Approach: - Time Boxed Approach (You have to cover 100s of test cases in given pentest timeline and you can not just focus on one or two categories) - Recon → Unauthenticated Testing → Authenticated Testing → Test Case Coverage → Compliance Check Coverage → Final Reporting
- Good at Recon? - Wide Scope - Good at Access Controls? - Multi - Tenant/Multi - Role Applications - Good at Business Logics? - Go for Complex Applications - Good at Server-Side Attacks? - Choose SaaS Products Similarly know what you are good at and approach accordingly. Approach: - No Time Boxing – If you think you found a potential issue, keep trying to exploit it - Often results in fruitful vulns. - Approach test cases that you are most comfortable with. - Report & Reward - Re-testing