In a penetration test of an infrastructure, an attack on IT systems and IT networks is simulated. If malicious actors were to attack your systems, what data could they capture and which systems could they seriously disrupt? An infrastructure pentest answers this.
Whether it is a Windows domain with various services such as Active Directory, MSSQL databases and WSUS servers, or heterogeneous infrastructures in which Linux servers with services such as Apache or Postfix are also used – as a rule, these are complex networks whose services are available to users. If an attacker manages to enter the network, for example through a poorly secured VPN access, they can access internal systems. Due to insecure configuration, inadequate updates, or default passwords, propagation to more and more systems is successful. This so-called lateral movement often leads to the takeover of critical systems and finally the entire infrastructure.
With an infrastructure penetration test, you subject your IT systems to a security audit and can preempt hackers by remediating discovered vulnerabilities.

There are many reasons for carrying out an infrastructure penetration test. In addition to compliance requirements according to ISO 27001 or BSI Grundschutz, it must be ensured that attackers do not have an easy time and cannot hack your servers.
You need a penetration test for your infrastructure if at least one of the following conditions is met:
| 1 | After a commission, a joint kick-off meeting takes place.
Following the meeting, the execution of the penetration test is prepared and a release is granted before the start of the actual tests. |
| 2 | In the main phase of the pentest, the infrastructure is analyzed and an attempt is made to violate security objectives.
|
| 3 | Joint result discussion, in which the discovered vulnerabilities and recommendations for action are presented.
With the end of the pentest and its results, the cooperation often continues in the diverse product portfolio of aramido. |
A security audit is a proven instrument for risk management. For this reason, numerous standards and norms require the regular audit of the entire IT infrastructure through penetration tests, including ISO IEC 27001, BSI IT-Grundschutz, NIST SP 800-53, and PCI DSS. Regulations by BaFin also require security audits with ZAIT, VAIT, BAIT, and KAIT.
The infrastructures of organizations are complex and can include many systems. Whether a firewall or switch from a particular manufacturer, a high-availability database management system, or communication via specific protocols such as HTTP, CIFS, or SIP: suitable audits must always be carried out. aramido carries out the following audits for the jointly defined scope, for example:
During the kick-off of the project, special audit requests can also be specified.
Ready to secure your infrastructure? Our professionals reveal vulnerabilities before hackers do. Contact us now and defend your IT infrastructure!