SysTools logoSysTools VAPT
VAPT Service

Network / Infrastructure VAPT

Security assessment of approved internal and external infrastructure — servers, endpoints, network devices, security appliances, databases and remote-access services. The questionnaire below is limited to the technical scope information the assessment team needs.

Progress 0% 0 of 0 answered 0 mandatory pending

Please note

  • Do not enter live passwords, private keys, SNMP community strings or production credentials in this form. Credentials are shared separately through an approved secure channel.
  • Only the IP addresses, hosts and devices listed in the approved scope are tested. Fields marked * are required to begin testing.
  • This is a controlled, defined-scope assessment — not a red-team engagement.

1 Assessment Details

Mandatory

2 Scope Type and Testing Approach

Mandatory

Grey Box shares limited information plus credentials. White Box adds full device configurations and network diagrams. Black Box shares nothing, so part of the effort goes into discovery rather than testing.

Please note: assessment frequency is not included in the timeline estimate in section 10. The estimate covers a single assessment cycle only. Frequency, and the schedule for repeat cycles, is agreed while finalising the scope.

A single-time engagement covers one assessment cycle together with its retests.

A full firewall rule-base audit is only possible when configuration access is provided.

3 Asset Inventory and Counts

Drives effort

Enter approximate counts — leave blank or zero where not applicable. These counts feed the timeline estimate in section 10.

Perimeter and hosts

Public IP
Internal IP
Windows laptops / endpoints
Linux / Unix endpoints
Printers
NVR

Servers and appliances

Servers
VMs
Application servers
DB servers

Network devices

Firewalls
Routers
Managed switches

Only addresses and hosts listed in the approved scope are tested.

4 Network Services and Access

Blocks kickoff if incomplete

Authenticated scanning reveals missing patches, local configuration and privilege issues that are invisible from the network.

5 Test Environment and Restrictions

Mandatory

Anything not authorized here will not be tested.

Testing through blocking controls reports the control's behaviour rather than the asset's real security posture.

This engagement is controlled Infrastructure and Network VAPT, not a red-team exercise. It does not include social engineering, phishing, physical-security testing, stealth or evasion operations, persistence, unrestricted lateral movement or data-exfiltration exercises.

6 Data Sensitivity and Standards

Drives severity ratings

7 Testing Coverage Areas

All included by default

Deselect any area to be excluded from this engagement.

8 Assessment Methodology

Automated and manual testing, adapted to the approved scope, asset types, operating systems, access level and client restrictions.

01

Scope and Authorization Verification

Approved IP addresses and ranges, hostnames, internal and external separation, asset and device inventory, cloud assets, testing location, authenticated or unauthenticated requirements, credentials, testing period, restrictions and written authorization.

02

Asset Discovery

Live IP addresses, hostnames, operating systems, servers, endpoints, virtual machines, network devices, cloud systems and security appliances — strictly within the approved ranges.

03

Port and Service Enumeration

Open ports, running services, versions and accessible management interfaces; whether exposed services are required, hardened, patched and properly restricted.

04

Automated and Authenticated Vulnerability Assessment

Missing patches, unsupported operating systems, known CVEs, weak SSL/TLS, default configurations and insecure protocols. Authenticated scanning is performed where credentials are provided. All findings are manually reviewed.

05

Configuration and Hardening Review

Accounts, privileges, password and lockout policy, audit and logging, host firewall, remote access, installed software, running services, scheduled tasks, file-system permissions and system-hardening controls.

06

Authentication, Authorization and Network Service Testing

Default and weak credentials, account lockout, MFA, excessive user and service-account privileges, share and ACL permissions, insecure protocols, exposed management interfaces and cleartext credential transmission.

07

Segmentation, Privilege Escalation and Controlled Lateral Access

Zone-to-zone access verification, local privilege escalation paths, credential reuse and trust relationships — limited validation against approved systems only, with no persistence or data exfiltration.

08

Validation, Reporting and Retest

Affected host, port, service and software confirmed and reproduced using controlled techniques without destructive payloads. Findings are severity-rated and documented, then retested after remediation.

This is not a red-team engagement

Testing is limited to the approved asset list, defined testing period, agreed techniques and documented restrictions. The team does not move outside the approved asset list, attempt organization-wide compromise, establish persistence, exfiltrate business data, target employees, or perform stealth or evasion testing.

9 Vulnerability Risk Classification

SeverityDescription
CriticalMay result in complete system compromise, remote code execution, administrative access, widespread infrastructure impact or significant sensitive-data exposure.
HighMay result in unauthorized access, privilege escalation, system compromise, significant data exposure or access to additional approved systems.
MediumMay affect infrastructure security under specific conditions, or may require authentication, limited privileges, internal access or user interaction.
LowLimited direct impact; remediated as part of infrastructure-hardening and security-improvement activities.
InformationalConfiguration observation or hardening recommendation without direct exploitability.

After retesting each finding is marked Closed, Open, Partially Fixed, Risk Accepted or Not Retested.

10 Timeline Estimate

Calculated from the SysTools infrastructure effort model. Asset counts from section 3 are carried over automatically; the OS image, hypervisor and WLAN counts are entered by the assessment team.

Endpoints

Unique OS images
Windows endpoint hosts
Linux / Unix endpoint hosts
Printers
NVR

Servers

General servers
Hypervisor hosts
VMs
Application servers
Database servers

Network devices

Firewalls
Routers
Managed switches
WLAN controllers with APs

Retest

Number of retests

One retest is included as standard. Increase this only if additional retest cycles are required.

Estimated duration 0 working days
Testing0
Retest0

Subject to final scope review, access availability and resource confirmation. The final timeline is confirmed after the complete scope has been reviewed and understood.

Save and Export Response

Responses are stored in this browser until exported or cleared.