Challenges

Define the Scope

  1. Trust but verify: are you sure the clients provide IP addresses of the network they own?
  2. Discovered something out of scope? Ask the client!
  3. Rules of engagement
  4. Determine your deliverables

Good Questions to Ask

Tools to use

Data Recording: Magic Tree

Automatically records data and generates reports from:

Data Recording: Dradis

Change the template

# cd /usr/lib/dradis/server/vendor/plugins/html_export
# nano template.html.erb

Data Recording: KeepNote