1
Scoping Organizational/Customer Requirements
2
Defining the Rules of Engagement
3
Footprinting and Gathering Intelligence
4
Evaluating Human and Physical Vulnerabilities
5
Preparing the Vulnerability Scan
6
Scanning Logical Vulnerabilities
7
Analyzing Scanning Results
8
Avoiding Detection and Covering Tracks
9
Exploiting the LAN and Cloud
10
Testing Wireless Networks
11
Targeting Mobile Devices
12
Attacking Specialized Systems
13
Web Application-Based Attacks
14
Performing System Hacking
15
Scripting and Software Development
16
Leveraging the Attack: Pivot and Penetrate
17
Communicating During the PenTesting Process
18
Summarizing Report Components
19
Recommending Remediation
20
Performing Post-Report Delivery Activities