pen-test
[Top] [All Lists]

Re: Blue Team ROE

To: mesenbrink@hotmail.com
Subject: Re: Blue Team ROE
From: Pete Herzog <lists@isecom.org>
Date: Wed, 14 Mar 2007 14:43:39 +0100
Cc: "Angelacci, Anna M CTR SPAWAR, J616" <anna.angelacci@navy.mil>, pen-test@securityfocus.com
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
Delivered-to: moderator for pen-test@securityfocus.com
In-reply-to: <D4A636FF3966F0439BC2B79F347E968D0549A6CF@NAEACHRLEX03VA.nadsusea.nads.navy.mil>
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
References: <D4A636FF3966F0439BC2B79F347E968D0549A6CF@NAEACHRLEX03VA.nadsusea.nads.navy.mil>
Resent-date: Wed, 14 Mar 2007 13:14:01 -0700 (MST)
Resent-from: pen-test-return-1078483781@securityfocus.com
Resent-message-id: <20070314201401.5F1752373F8@outgoing3.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
User-agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.10) Gecko/20050716 Thunderbird/1.0.6 Mnenhy/0.7.2.0
I need to second what Anna says. If they are shopping for a Blue Team test then why are you coming at them with Pen Test procedures? For a Blue Team test, take a note from the OSSTMM, document what you don't do as much as what you do like in its Security Testing Audit Report. And you don't need to crawl through all the holes to identify them, define protection and controls for them, and look to see who maybe was there before you. That's a Blue Team test and it can be a very thorough audit. What it won't be is a pen test.

-pete.

Angelacci, Anna M CTR SPAWAR, J616 wrote:
Plan
Prepare  letter of consent, and letter of instruction. Blue teams do not
penn test, Red teams do. Blue teams detect, protect, react, and recover.
With your current methodology, you could lose your work.

-----Original Message-----
From: listbounce@securityfocus.com [mailto:listbounce@securityfocus.com]
On Behalf Of mesenbrink@hotmail.com
Sent: Thursday, March 01, 2007 2:45 PM
To: pen-test@securityfocus.com
Subject: Blue Team ROE


List,

I wanted to send out a general email asking the members of this list
their professional opinions on being limited during a Blue Team
pen-test.  I have a govt customer that is trying deny us the ability to
remove password hashes/files from the system for cracking, write
procedures for every tool/exploit that could be possibly executed, not
allow the loading of any tools/exploits on target systems, things like
that.....  Of course my reaction is that my company will not perform the
assessment with such restrictions, what are some thoughts from this list
on this subject?

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.

http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>