Security Penetration
2Secure conducts comprehensive Security Penetration Tests that provides the customer with in-depth tests of their defenses against external or internal attackers that target IT-systems.
The tests are performed methodically, based on a scenario agreed upon with the customer, which defines the scope and target systems for the test. IT-Systems are searched for weaknesses that could allow an attacker to perform an intrusion and gain unauthorized access to servers, network equipment or sensitive information. Compromised systems are searched for information that could provide the attacker with additional credentials to systems closer to the target.
Our tests are divided into phases according to the following:
- Network Surveying – discovery of domain and server names, IP-addresses and network topology.
- System Services Identification – analysis of OS versions, patch levels, service protocols and versions.
- Competitive Intelligence Review – analysis of information indexed by public search engines.
- Authentication – analysis of authentication services and controls.
- Vulnerability Research and Verification – mapping of services and versions to known vulnerabilities.

