Configuring global settings

NAVIGATION  Global Settings

The options to configure global settings for the vPenTest account and for internal and external network penetration tests are available on the Global Settings page.

Enabling or disabling basic or advanced assessment settings

The settings saved in the Basic Assessment Settings and Advanced Assessment Settings sections on the Global Settings page determine the default settings applied to all assessments.

NOTE  These sections are disabled for new vPenTest users by default.

Enabling basic settings or both basic and advanced settings adds an extra step called Settings to the scheduling wizard, which can be modified on a per-assessment basis. Refer to Steps in the scheduling wizard.

Turning the Enable Basic Settings or Enable Advanced Settings toggles on or off enables or disables those settings, respectively. If basic settings are disabled, enabling advanced settings automatically enables basic settings.

EXAMPLE  This example shows the Settings step in the scheduling wizard when both basic and advanced settings are enabled.

Basic Assessment Settings overview

Enabling basic settings allows you to control the host discovery process, including the port scan tool, speed, and port list. After making any changes, click Save in the lower-right corner of the section.

Explanations and recommended best practices for Basic Assessment Settings are outlined in the following drop-down sections.

Advanced Assessment Settings overview

IMPORTANT  Customizing the following settings may lead to severe business, network, or user disruption. The default settings have been thoroughly tested to prevent disruption. We highly recommend using our default options for most situations, which can be applied any time by clicking Restore Default Settings in the upper-right corner of the section. Changes should be made with extreme caution and only for specific reasons.

The advanced settings in vPenTest are designed to offer you more control over the focus and aggressiveness of your penetration testing. After making any changes, click Save in the lower-right corner of the section.

Explanations and recommended best practices for Advanced Assessment Settings are outlined in the following drop-down sections.

Grey Box Pentesting

In the scheduling wizard, the Grey Box Pentesting toggle is displayed at the top of the Advanced Settings section when scheduling an internal assessment. Compromised Microsoft AD/local credentials are a significant security risk. This feature helps organizations assess the real-world impact of stolen or phished credentials, ensuring they can proactively mitigate threats before they become breaches. Refer to Grey Box Internal Penetration Testing to learn more.

Exploitation Settings

For the beginning stages of the customized exploitation settings, the following options are available to help fine tune some of the attacks/techniques executed as part of a penetration test. These options allow you to tailor these attacks to specific organizations, allowing you to perform a more comprehensive test while taking into consideration security controls and settings within the targeted organization.