The tests intrusion or pentests
Internal or external ?
The objective of a pentest is to evaluate the level of security of an infrastructure, a web service or even an e-commerce site. To do this, the auditor (or commonly called pentester or ethical hacker), will test the target by simulating real attacks.
External
Internal
This type of audit can also be carried out internally, directly from the company's premises. In this configuration, the pentester simulates malicious actions from inside the company. The objective is to assess the level of risk linked to a possible compromise by an employee, a partner or a service provider of the company.
Once the perimeter has been determined, it is appropriate to choose what type of pentest will be carried out.
Black Box
The “Black Box” approach involves assessing the security level of the target without having any prior information. In this situation, the listener places himself in the position of a classic malicious actor. This approach requires a well-defined methodology as well as time to thoroughly explore the target.
Grey Box
The "Grey Box" approach aims to maximize effectiveness by optimizing the time and scope of the attack. The pentester receives a restricted set of information to define the scope of analysis. This allows the pentester to concentrate his efforts on this defined perimeter.