Infrastructure Penetration Testing

Have the security of your IT infrastructure verified by experts.

What is a penetration test of an IT infrastructure?

In a penetration test of an infrastructure, an attack on IT systems and IT networks is simulated. If malicious actors were to attack your systems, what data could they capture and which systems could they seriously disrupt? An infrastructure pentest answers this.

Whether it is a Windows domain with various services such as Active Directory, MSSQL databases and WSUS servers, or heterogeneous infrastructures in which Linux servers with services such as Apache or Postfix are also used – as a rule, these are complex networks whose services are available to users. If an attacker manages to enter the network, for example through a poorly secured VPN access, they can access internal systems. Due to insecure configuration, inadequate updates, or default passwords, propagation to more and more systems is successful. This so-called lateral movement often leads to the takeover of critical systems and finally the entire infrastructure.

With an infrastructure penetration test, you subject your IT systems to a security audit and can preempt hackers by remediating discovered vulnerabilities.

  • Detect security gaps early
  • Fulfill compliance requirements
  • Assess your security situation
  • Protect yourself from data loss
  • Fend off cyber attacks
Product landing page example image
Figure 1 Attack vectors are determined using information from the AD in order to take over the account of a domain administrator.

When do I need an infrastructure pentest?

There are many reasons for carrying out an infrastructure penetration test. In addition to compliance requirements according to ISO 27001 or BSI Grundschutz, it must be ensured that attackers do not have an easy time and cannot hack your servers.

You need a penetration test for your infrastructure if at least one of the following conditions is met:

  • Do you operate your own network with services that process or store sensitive data?
  • Was the last penetration test more than a year ago?
  • Have certain areas of the infrastructure never been examined by a security audit?
  • Have you been requested by your client or project partner to prove that your IT systems are regularly audited?
  • Are you planning the introduction of a new IT system and are not sure how robust it is against attacks from the internet?
  • Do you want to show your customers that you are committed to the security of their data?

Process of an infrastructure pentest

1

After a commission, a joint kick-off meeting takes place.

  • The scope of the pentest is determined.
  • It is discussed which threats should be addressed in particular.
  • Contact persons are announced.
  • A period is agreed during which the tests may be carried out.

Following the meeting, the execution of the penetration test is prepared and a release is granted before the start of the actual tests.

2

In the main phase of the pentest, the infrastructure is analyzed and an attempt is made to violate security objectives.

  • Reconnaissance: The components of the IT infrastructure are examined in depth using passive and active methods.
  • Enumeration: Possible attack vectors are collected through discovered vulnerabilities.
  • Exploitation: Vulnerabilities are exploited in a controlled manner and new information is gained.
  • Documentation: The discovered vulnerabilities, steps for exploitation, and concrete remedial measures are described precisely.
3

Joint result discussion, in which the discovered vulnerabilities and recommendations for action are presented.

  • Presentation: The results and their implications are presented to the stakeholders.
  • Recommendations: Concrete suggestions for remediating vulnerabilities are given.
  • Discussion: Jointly consult on the next steps for security improvement and risk reduction.

With the end of the pentest and its results, the cooperation often continues in the diverse product portfolio of aramido.

Standards and Norms

A security audit is a proven instrument for risk management. For this reason, numerous standards and norms require the regular audit of the entire IT infrastructure through penetration tests, including ISO IEC 27001, BSI IT-Grundschutz, NIST SP 800-53, and PCI DSS. Regulations by BaFin also require security audits with ZAIT, VAIT, BAIT, and KAIT.

Comprehensive Audit of the Application

The infrastructures of organizations are complex and can include many systems. Whether a firewall or switch from a particular manufacturer, a high-availability database management system, or communication via specific protocols such as HTTP, CIFS, or SIP: suitable audits must always be carried out. aramido carries out the following audits for the jointly defined scope, for example:

  • Audit of network security by examining firewalls, routers, switches and other network services.
  • Audit of server and operating system security by examining the conceptual design, security configuration, patch management and authorization and access controls in detail.
  • Audit of applications and services, as they often allow the takeover of a host. With the control of a server, further attacks in the network can be carried out (so-called lateral movement).
  • Audit of authentication and directory systems such as Active Directory (AD), Lightweight Directory Access Protocol services (LDAP) and Identity and Access Management systems (IAM).
  • Audit of data stores such as databases, file servers or backup servers. They represent an important attack target and could be vulnerable due to insufficiently protected communication or weak authentication procedures.
  • Audit of the physical security of IT infrastructure components, which often takes place in server rooms and data centers. For example, if the hollow floor is not secured or standard locking cylinders ("Rittal 3524") are used, attackers can carry out a variety of attacks on IT components.
  • Audit of the incident response, where the focus is on the response capability of a CERT or generally an IT team.

During the kick-off of the project, special audit requests can also be specified.

Ready to secure your infrastructure? Our professionals reveal vulnerabilities before hackers do. Contact us now and defend your IT infrastructure!

Request penetration test

aramido is your qualified partner for infrastructure penetration tests

  • In-depth security analysis: Our penetration test goes far beyond simple vulnerability scans. aramido pentesters carry out manual tests and creatively use attack vectors to identify even complex vulnerabilities and assess their impact on the entire IT infrastructure. This enables a comprehensive analysis of the security situation of your IT.
  • Innovative expertise: Our team consists of highly qualified ethical hackers with many years of experience and current knowledge of the latest threats and attack techniques.
  • Tailored approaches: We adapt our tests to the individual needs of your infrastructure, whether it is an on-premise infrastructure, a cloud environment, or a hybrid form.
  • Holistic security analysis: Our approach covers both automated scans and manual tests to detect even the most sophisticated security gaps.
  • Affordable penetration testing: We offer professional services at very good, market-standard conditions.
  • Understandable reports: Our reports are clearly structured and easy to understand. You receive not only a list of vulnerabilities, but also clear recommendations for action for remediation.
  • Reliable partnership: We are by your side not only during the test, but are your contact for all questions regarding information security.
  • Detect security gaps early
  • Fulfill compliance requirements
  • Assess your security situation
  • Protect yourself from data loss
  • Fend off cyber attacks

Related Articles

Niklas Fuhrberg

Published on 25.08.2024 published.

What is the NIS 2 Directive? (Part 1)

In response to the increasing number of cyberattacks, the EU is introducing new measures. Among these is NIS 2, which sets new requirements for companies. (read more)


Niklas Fuhrberg

Published on 19.08.2024 published.

NIS 2: What do companies need to do? (Part 3)

As a first step, responsibilities within the company should be established. In addition to a coordinating body, such as an Information Security Officer, the executive management must also fulfill specific obligations. (read more)


Moritz Kaumanns

Published on 01.02.2021 published.

Security Advisory: Amazon Secret Key Publicly Accessible (CVE-2020-28199)

A security vulnerability in an Amazon Pay plugin for Shopware 5 allows the unauthorized reading of the Amazon Secret Key (CVE-2020-28199). (read more)


Andreas Sperber

Published on 28.01.2017 published.

aramido at the 18th Industry Fair i+e 2017

aramido is an exhibitor at the Industry Fair i+e 2017 in Freiburg: visitors can receive information security consulting on February 1st and 2nd. (read more)


Armin Harbrecht

Published on 14.11.2016 published.

How Much Does a Penetration Test Cost?

As penetration testers, we are often asked about the cost of a penetration test. The answer depends on several factors. (read more)