Deselect any area to be excluded from this engagement.
Asset discovery and enumeration Live host identification, port scanning, service and version enumeration, OS fingerprinting
Patch and vulnerability assessment Known CVEs, missing patches, outdated applications, unsupported and end-of-life software
Authentication and credential security Default, weak and blank passwords, account lockout, MFA, credential reuse and exposure
Authorization and access control Excessive privileges, service accounts, group membership, file, share and ACL permissions, sudo and registry
OS and system hardening Account, password, audit and logging policy, host firewall, services, scheduled tasks, CIS baseline configuration
Server security Exposed services, banner and information disclosure, insecure HTTP methods, sensitive and backup file exposure, weak cryptography
Endpoint security controls AV / EDR validation, host firewall, disk encryption, secure boot, USB and removable media, script and macro controls
Database server security Exposure and version, default and weak accounts, privileges, encryption in transit and at rest, backup and dump exposure, audit logging
Firewall and VPN security Management exposure, firmware, permissive and shadowed rules, NAT and port forwarding, VPN encryption and authentication, logging
Router security Management exposure, routing protocol authentication, ACL validation, anti-spoofing, control-plane protection, SNMP, information disclosure
Managed switch security VLAN segmentation and hopping, trunk and port security, DHCP snooping, dynamic ARP inspection, STP protections, storm control, SNMP
Network service and protocol security Insecure and cleartext protocols, weak SSL/TLS and ciphers, anonymous access, exposed management interfaces, SNMP community strings
Segmentation and lateral access validation Zone-to-zone access verification, credential reuse, accessible shares, trust relationships — controlled validation only
Logging, monitoring and time synchronization Audit and security logging, SIEM forwarding, log tampering risk, NTP configuration
Wireless network security Rogue access point detection, encryption and authentication, guest isolation, controller hardening — only if wireless is in scope