Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
CORE IMPACT Pro
Penetration Testing Software
SHARE

CORE IMPACT Pro Penetration Testing Reports: 
Client-Side User Report


Testing Vectors:
Endpoints

The Client-Side User Report outlines all the relevant testing data necessary to help organizations understand exactly how well their end users stand up to testing, specifically social engineering attacks involving both e-mail and Web-based delivery models, including spear phishing assessments derived from real-world information gathering and e-mail address harvesting. Addressing one of the hardest elements of IT security to assess – the human response to potential attacks, the Client Side User Report allows organizations to determine where users are most vulnerable to threats to drive both training and policy enforcement efforts.

Targeted Report Results:

  • Top-level statistics regarding how many users can be compromised: offers a glimpse into overall employee computing habits.
  • Numbers of test e-mails sent, click-through rates and exploits: illustrates specifically how users can be exposed by attackers.
  • Compromised users listed by host and web browser: provides detailed insight into where fast-moving web attacks may succeed.
  • Social engineering success rates: highlights how users can be convinced to take the bait by sophisticated cybercriminals.

Takeaways:

  • Unique intelligence regarding the ability of today’s advanced attackers to subvert users across multiple techniques.
  • An ability to target end user education programs and internal security policies at specific, relevant weaknesses.

Compliance Reports

CORE IMPACT Pro offers several compliance-specific reporting capabilities around PCI DSS and U.S. federal FISMA regulations that allow organizations to prove that they are meeting mandated controls, including penetration testing requirements, and help them to prepare for external compliance audits. The PCI and FISMA reports specifically map exploitable vulnerabilities identified by IMPACT Pro to any compliance requirements that the involved issues would violate. Reports also illustrate how organizations using IMPACT Pro are validating the efficacy of mandated controls while embracing the underlying spirit of the guidelines, versus merely seeking to achieve check-box compliance status.

Related Content



Learn more about penetration testing, the approach used by CORE IMPACT security testing software solutions.

Additional Reporting Features

CORE IMPACT Pro reports offer the following additional features for meeting your unique assessment goals:

SCAP Support
In support of the SCAP standard, CORE IMPACT Pro incorporates CVE, CVSS and CPE data into the product's reports and can also export this data in XML format for use in centralized security databases.

Customization
Many CORE IMPACT Pro reports can be tailored to meet the needs of different internal constituencies by providing tailored results for groups including IT management, network administrators, remediation staff, and other IT/security professionals. Additionally, the reports are exportable to other applications for integration with complimentary sets of data.

Aggregation
CORE IMPACT Pro report consolidation capabilities enable customers to create overarching reports of enterprise penetration testing results. Users can import and consolidate results from different penetration tests - conducted at various times using multiple workspaces and consoles - into each of IMPACT Pro’s standard report templates.