Penetration Testing Services

Penetration testing activities attempt to gain access through unknown (“blackbox”), partially known (“graybox”) or known (“whitebox”) access methods to our clients physical or logical infrastructure. Penetration testing of the network perimeter is performed in accordance with an agreed upon Rules of Engagement (ROE) document. Sunera expends extensive effort to ensure the normal operation of the systems and networks is not disrupted and production data is not affected. Assessment actions will not include denial of service attacks, however, potential denial of service conditions will be identified and actionable findings and recommendations will be delivered in a concise report format.
Penetration Testing Methodology
Penetration Testing attempts to leverage and exploit discovered weaknesses in logical and physical environments to compromise the target. Specifically, each asset undergoes a comprehensive attack and the results are evaluated to determine a successful compromise. The assessment may also identify potentially less significant risks that, when combined, may escalate the severity of the attack and the underlying vulnerability and result in a compromise of the information systems.
Successful system compromise(s) can be documented using proof of concept (PoC) demonstrations. Each PoC provides the attack scenario, specific actions taken to compromise the system, steps to remediate the risk, and industry standard references.
For all information security assessment services, Sunera will identify vulnerabilities, threats and risks, provide recommendations, and assist in vulnerability remediation.



