Penetration Test Methodology: PTES, OWASP, OSSTMM and BSI Guidelines
Comparison of leading penetration testing methodologies: PTES, OWASP Testing Guide, OSSTMM, BSI Guidelines (BSI-CS 115), and TIBER-EU for the financial sector.
Summary: Breach and Attack Simulation (BAS) is a technology that continuously and automatically simulates cyberattacks to identify security vulnerabilities in real time - without the need for manual penetration testers. BAS platforms test detection (does the SIEM detect the attack?), prevention (does the firewall block it?), and response (does the SOC respond correctly?) based on MITRE ATT&CK® techniques.
Questions about this topic?
Our experts advise you free of charge and without obligation.
About the Author
M.Sc. in IT Security with more than 5 years of experience in offensive security analysis. Leads the delivery of penetration tests, specializing in web applications, network infrastructure, reverse engineering and hardware security. Responsible for several responsible disclosures.