Penetration Testing

Verify the security of your systems with our experts.

What is a Penetration Test?

Given the increasingly complex IT landscape, vulnerabilities in software development or the configuration of IT systems are almost inevitable. However, it is precisely these that often allow serious attacks, endangering processed data or even an entire IT infrastructure. The consequences can be severe financial losses through extortion or reputational damage. A penetration test is intended to preempt such attacks and simulates attacks on IT systems in order to detect vulnerabilities at an early stage.

During a pentest, experienced security experts (ethical hackers) analyze the approach of a potential attacker to identify risks. This approach differs from a simple security scan, which focuses only on publicly known vulnerabilities. A pentest is carried out with realistic attack scenarios and uses human expertise to uncover even unknown vulnerabilities in your systems or software.

The results of a penetration test are recorded in a report, which contains detailed descriptions of the discovered weaknesses as well as direct measures to improve the level of security.

Whether you want to simulate an attack on your entire infrastructure or develop a mobile or web application, aramido is here to help with its expertise.

  • Preempt attackers
  • Detect security gaps early
  • Prevent a takeover of your infrastructure
  • Protect your developed applications
  • Avoid negative headlines and reputational damage
Video 1 An aramido special broadcast shows how hackers can take over the account of a domain administrator.

When do I need a pentest?

Given today's threats, it is important to know the security level of your own IT landscape in order to implement measures and necessary processes. A penetration test should be carried out in the following situations:

  • Do your systems process or store sensitive information?
  • Are you developing an application and are shortly before publication?
  • Do you want to find out how far an attacker would get in your infrastructure?
  • Are major changes being made to systems or applications?
  • Do you want to identify and reduce technological risks?
  • Do you want to test your blue team and the existing defense of your systems?

In view of the increasing frequency of cyber attacks, greater emphasis should be placed on penetration tests. Actively ensure that your systems are equipped for such threats.

General Process of a Pentest

1

After a commission, a joint kick-off meeting takes place.

  • The scope of the pentest is determined.
  • It is discussed which threats should be addressed in particular.
  • Contact persons are announced.
  • A period is agreed during which the tests may be carried out.

Following the meeting, the execution of the penetration test is prepared and a release is granted before the start of the actual tests.

2

In the main phase of the pentest, the system is analyzed and an attempt is made to violate security objectives.

  • Reconnaissance: The test object is examined in depth using passive and active methods.
  • Enumeration: Possible attack vectors are collected through discovered vulnerabilities.
  • Exploitation: Vulnerabilities are exploited in a controlled manner and new information is gained.
  • Documentation: The discovered vulnerabilities, steps for exploitation, and concrete remedial measures are described precisely.
3

Joint result discussion, in which the discovered vulnerabilities and recommendations for action are presented.

  • Presentation: The results and their implications are presented to the stakeholders.
  • Recommendations: Concrete suggestions for remediating vulnerabilities are given.
  • Discussion: Jointly consult on the next steps for security improvement and risk reduction.

With the end of the pentest and its results, the cooperation often continues in the diverse product portfolio of aramido.

Standards and Norms

Numerous standards and norms require the regular performance of a pentest and extensive audits of IT systems. Such an audit is considered a proven instrument for risk management. These standards and norms include, among others, PCI-DSS, ISO IEC 27001, TISAX (VDA ISA), NIST SP 800-53, and SOC 2. Regulations by BaFin also require security audits with ZAIT, VAIT, BAIT, and KAIT.

Comprehensive Audit of the Application

Depending on the respective type of pentest, different procedures and standards are followed. This is intended to ensure a uniform and thorough analysis. The following exemplary audits are carried out during a pentest:

  • Authorization and authentication audits to uncover weaknesses in the rights and role management of the software or infrastructure.
  • Audit of weak cryptography (Encryption at Rest and Encryption in Transit) for communication links between systems.
  • Mobile applications (apps) are examined according to the OWASP Mobile Application Security Testing Guide.
  • In an infrastructure pentest, systems and the configuration of the Active Directory infrastructure are analyzed and attacked.
  • Audit of the operated services and servers within an infrastructure. Examination for possible configuration errors that allow attacks.
  • Web pentests are examined for the most common sources of error according to OWASP Top 10.

Ready to audit and secure your IT systems? Our experts reveal vulnerabilities before hackers do. Contact us now and harden your systems and applications!

Request penetration test

aramido is your qualified partner for penetration tests

  • In-depth security analysis: Our penetration test goes far beyond simple vulnerability scans. aramido pentesters carry out manual tests and creatively use attack vectors to identify even complex vulnerabilities and assess their impact on the overall system. This enables a comprehensive analysis of the security situation of your platform.
  • Innovative expertise: Our team consists of highly qualified ethical hackers with many years of experience and current knowledge of the latest threats and attack techniques.
  • Tailored approaches: We adapt our tests to individual needs, whether it is a traditional website, a single-page application, a mobile application, an API, or the audit of an entire infrastructure including red teaming.
  • Holistic security analysis: Our approach covers both automated scans and manual tests to detect even the most sophisticated security gaps.
  • Affordable penetration testing: We offer professional services at very good, market-standard conditions.
  • Understandable reports: Our reports are clearly structured and easy to understand. You receive not only a list of vulnerabilities, but also clear recommendations for action for remediation.
  • Reliable partnership: We are by your side not only during the test, but are your contact for all questions regarding information security.
  • Preempt attackers
  • Detect security gaps early
  • Prevent a takeover of your infrastructure
  • Protect your developed applications
  • Avoid negative headlines and reputational damage

Related Articles

Niklas Fuhrberg

Published on 25.08.2024 published.

What is the NIS 2 Directive? (Part 1)

In response to the increasing number of cyberattacks, the EU is introducing new measures. Among these is NIS 2, which sets new requirements for companies. (read more)


Niklas Fuhrberg

Published on 19.08.2024 published.

NIS 2: What do companies need to do? (Part 3)

As a first step, responsibilities within the company should be established. In addition to a coordinating body, such as an Information Security Officer, the executive management must also fulfill specific obligations. (read more)


Moritz Kaumanns

Published on 01.02.2021 published.

Security Advisory: Amazon Secret Key Publicly Accessible (CVE-2020-28199)

A security vulnerability in an Amazon Pay plugin for Shopware 5 allows the unauthorized reading of the Amazon Secret Key (CVE-2020-28199). (read more)


Andreas Sperber

Published on 28.01.2017 published.

aramido at the 18th Industry Fair i+e 2017

aramido is an exhibitor at the Industry Fair i+e 2017 in Freiburg: visitors can receive information security consulting on February 1st and 2nd. (read more)


Armin Harbrecht

Published on 14.11.2016 published.

How Much Does a Penetration Test Cost?

As penetration testers, we are often asked about the cost of a penetration test. The answer depends on several factors. (read more)