Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
CORE IMPACT Pro
Penetration Testing Software
SHARE

CORE IMPACT Pro Penetration Testing Reports: 
Client-Side Penetration Test Report


Testing Vectors:
Endpoints

The Client-Side Penetration Test Report provides detailed results of assessments performed on endpoints and end users, including information about any social engineering tactics utilized to trigger tests, whether exploits were delivered via the Web or e-mail, any un-patched vulnerabilities that can be used to compromise tested endpoints and the potential for privilege escalation to other clients or systems. As client-side attacks are the most difficult to protect against based on their need to invoke user interaction, the Client-Side Penetration Test Report delivers powerful insight into both endpoint security posture and the ability and willingness of users to adhere to secure usage policies.

Targeted Report Results:

  • Detailed summaries of all client-side tests and results: arms you with comprehensive endpoint and end user security intelligence.
  • Social engineering tactics: allows you to understand how users are most likely to be tricked by attackers, and how well they follow policies.
  • Compromised clients listed by OS: allows you to assess which endpoint OS platforms represent greater risks, and how.
  • Client patching status: highlights whether or not endpoints and applications are being properly updated with vendor fixes.

 
Takeaways:

  • Comprehensive analysis of client security posture ranging from systems vulnerability exposure to connectivity with other assets.
  • Detailed insight into which end users represent the most significant risks based on their client status and openness to social engineering.
Related Content



Learn more about penetration testing, the approach used by CORE IMPACT security testing software solutions.

Additional Reporting Features

CORE IMPACT Pro reports offer the following additional features for meeting your unique assessment goals:

SCAP Support
In support of the SCAP standard, CORE IMPACT Pro incorporates CVE, CVSS and CPE data into the product's reports and can also export this data in XML format for use in centralized security databases.

Customization
Many CORE IMPACT Pro reports can be tailored to meet the needs of different internal constituencies by providing tailored results for groups including IT management, network administrators, remediation staff, and other IT/security professionals. Additionally, the reports are exportable to other applications for integration with complimentary sets of data.

Aggregation
CORE IMPACT Pro report consolidation capabilities enable customers to create overarching reports of enterprise penetration testing results. Users can import and consolidate results from different penetration tests - conducted at various times using multiple workspaces and consoles - into each of IMPACT Pro’s standard report templates.