CORE IMPACT Pro Penetration Testing Reports:
Client-Side User Report
Testing Vectors: Endpoints
The Client-Side User Report outlines all the relevant testing data necessary to help organizations understand exactly how well their end users stand up to testing, specifically social engineering attacks involving both e-mail and Web-based delivery models, including spear phishing assessments derived from real-world information gathering and e-mail address harvesting. Addressing one of the hardest elements of IT security to assess – the human response to potential attacks, the Client Side User Report allows organizations to determine where users are most vulnerable to threats to drive both training and policy enforcement efforts.
Targeted Report Results:
- Top-level statistics regarding how many users can be compromised: offers a glimpse into overall employee computing habits.
- Numbers of test e-mails sent, click-through rates and exploits: illustrates specifically how users can be exposed by attackers.
- Compromised users listed by host and web browser: provides detailed insight into where fast-moving web attacks may succeed.
- Social engineering success rates: highlights how users can be convinced to take the bait by sophisticated cybercriminals.
Takeaways:
- Unique intelligence regarding the ability of today’s advanced attackers to subvert users across multiple techniques.
- An ability to target end user education programs and internal security policies at specific, relevant weaknesses.
Compliance Reports
CORE IMPACT Pro offers several compliance-specific reporting capabilities around PCI DSS and U.S. federal FISMA regulations that allow organizations to prove that they are meeting mandated controls, including penetration testing requirements, and help them to prepare for external compliance audits. The PCI and FISMA reports specifically map exploitable vulnerabilities identified by IMPACT Pro to any compliance requirements that the involved issues would violate. Reports also illustrate how organizations using IMPACT Pro are validating the efficacy of mandated controls while embracing the underlying spirit of the guidelines, versus merely seeking to achieve check-box compliance status.











