IndianZ Logo

About Blog Cheatsheets Defense Links Offense
Offense
Code Audit Exploit Hacking Input Validation Metasploit Methods Nmap OSSTMM Test OWASP Webtest Pentest Physical Pentest Backtrack Pentest SQL Inject

OSSTMM Test

OSSTMM Channels
Physical Security: Human and Physical
Spectrum Security: Wireless
Communication Security: Telecommunication and Data Networks
OSSTMM Process
A Induction Phase
0 Posture Review (culture, rules, norms, laws)
1 Logistics (distance, speed, paths)
2 Active Detection Verification (ips)
B Interaction Phase
3 Visibility Audit(visible targets in scope)
4 Access Verification (protocols, open ports TCP/UDP)
5 Trust Verification (trusts)
6 Control Verification (class B -alarm)
C Inquest Phase
7 Process Verification (process docs, maintenance)
8 Configuration/Training Verification (operation)
9 Property Validation (intellectual)
10 Segregation Review (classification)
11 Exposure Review (osint)
12 Competetive Intelligence Scouting
D Intervention Phase
13 Quarantine Verification (antivirus, black/white lists)
14 Privileges Audit (misuse, abuse)
15 Survivability Validation/Service Continuity (resilience)
16 Alert and Log Review/End Survey (log/alarms)



(download osstmm3.dia)