Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Penetration Testing: Re: pentest documentation

Re: pentest documentation

From: Andrew Hay <andrewsmhay_at_gmail.com>
Date: Mon, 2 Oct 2006 16:18:47 -0300

Hi Jürgen,

I would document the session in a hand-written notebook (each page
dated and numbered) and, if needed, take photographs instead of
video. If you ever needed to present this data in a court of law the
jury tends to associate better with the above formats.

That being said, if presenting to a client, you would probably want to
present a formal document based on your notes taken at the time of the
testing.

Hope this helps.

-- 
Andrew Hay [NSA/CCSE Plus/CCNA/Security+/RHCE/GCIA/SSP-MPA/SSP-CNSA]
blog: https://www.andrewhay.ca
email: andrewsmhay || at || gmail.com
On 02/10/06, "Jürgen R. Plasser" <plasser_at_hexagon.at> wrote:
> Hi All,
>
> How do you document and log the pentest session itself?
>
> I want to document the pentest process in detail, not only for the
> customer, but for later reviews and to avoid legal difficulties.
>
> What are the best tools to accomplish that or do you even record the
> sessions on video with a camcorder? Or some kind of screen recorder?
>
> Thanks,
>
> Jürgen
>
>
> ------------------------------------------------------------------------
> This List Sponsored by: Cenzic
>
> Need to secure your web apps?
> Cenzic Hailstorm finds vulnerabilities fast.
> Click the link to buy it, try it or download Hailstorm for FREE.
> http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
> ------------------------------------------------------------------------
>
>
Received on Oct 02 2006
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos