Vulnerability Assessment
Brookcourt Solutions offers a full vulnerability assessment service which aims to reduce the security exposure within an organisations infrastructure through identification of vulnerabilities that could be exploited through accidental or malicious activity, enabling the organisation to implement appropriate mitigation.
Brookcourt can produce a baseline that can be used to measure the effectiveness of ongoing mitigating controls over time.
We will use a range of tools to enumerate potential vulnerabilities. We will perform a vulnerability scan in two phases;
- The first phase will consist of a non-intrusive enumeration of potential vulnerabilities performed with no elevated privileges. This demonstrates the level of information that can be attained simply by ‘requesting’ it from given systems.
- The second phase will be a more intrusive approach to extracting information from the systems targeted. Genuine user credentials will be supplied and simple exploits to identified vulnerabilities will be undertaken. It is important to note that the second stage could result in systems becoming unavailable or user accounts being locked and therefore consideration should be given to the timing of this phase of the analysis.
You can expect the following results;
a breakdown, by IP address or range, of the following;
- Open Ports
- Warnings
- Holes
- Informational Notes