CORE IMPACT Pro Penetration Testing Reports:
Client-Side Penetration Test Report
Testing Vectors: Endpoints
The Client-Side Penetration Test Report provides detailed results of assessments performed on endpoints and end users, including information about any social engineering tactics utilized to trigger tests, whether exploits were delivered via the Web or e-mail, any un-patched vulnerabilities that can be used to compromise tested endpoints and the potential for privilege escalation to other clients or systems. As client-side attacks are the most difficult to protect against based on their need to invoke user interaction, the Client-Side Penetration Test Report delivers powerful insight into both endpoint security posture and the ability and willingness of users to adhere to secure usage policies.
Targeted Report Results:
- Detailed summaries of all client-side tests and results: arms you with comprehensive endpoint and end user security intelligence.
- Social engineering tactics: allows you to understand how users are most likely to be tricked by attackers, and how well they follow policies.
- Compromised clients listed by OS: allows you to assess which endpoint OS platforms represent greater risks, and how.
- Client patching status: highlights whether or not endpoints and applications are being properly updated with vendor fixes.
Takeaways:
- Comprehensive analysis of client security posture ranging from systems vulnerability exposure to connectivity with other assets.
- Detailed insight into which end users represent the most significant risks based on their client status and openness to social engineering.











