Lecture Two
CYU 08102 : Ethical Hacking Concept
Ethical Hacking Life Cycle
Ethical Hacking in Gathering Information
–Ethical Hacking Lifecycle
–Vulnerability Assessment
–Penetration Testing
–Vulnerability Assessment vs Penetration Testing
Ethical Hacking Lifecycle
• Ethical Hacking Lifecycle refers to a structured and systematic
process followed by ethical hackers to identify, validate and
report security weaknesses in an organization’s systems. Unlike
malicious hacking, ethical hacking follows a predefined
methodology, ensuring that security testing is legal, controlled,
and aligned with organizational objectives.
• The lifecycle mirrors how real attackers operate but applies
professional standards, documentation, and ethical
responsibility throughout the process.
Purpose of the Ethical Hacking Lifecycle
• The ethical hacking lifecycle ensures that security testing is conducted in a
logical sequence where each phase builds on the previous one. This
approach reduces the risk of overlooking vulnerabilities and enables
accurate assessment of real-world attack impact.
• Organizations benefit by understanding not only what vulnerabilities exist,
but how they can be exploited and what damage could result if attackers
succeed.
• Key Benefits:
• Structured vulnerability discovery
• Risk-based prioritization
• Legal and ethical compliance
• Actionable remediation guidance
Overview of Ethical Hacking Lifecycle Stages
The ethical hacking lifecycle typically consists of the following stages:
• Planning and Authorization
• Reconnaissance (Information Gathering)
• Scanning and Enumeration
• Vulnerability Analysis
• Exploitation
• Post-Exploitation From Book
• Reporting and Remediation
Although different frameworks may combine or rename stages, the
underlying principles remain consistent across professional penetration
testing and red teaming engagements.
Although different frameworks may combine or rename stages, the underlying principles remain consistent across professional penetration testing and red
teaming engagements. – Redefine Hacking Book Ch 2.
More info: Hands on Hacking: Become an Expert at Next Gen Penetration Testing and Purple, Chp. 2 pg. 18
Overview of Ethical Hacking Lifecycle Stages
Stage 1 – Planning and Authorization
• Planning and authorization form the foundation of ethical hacking. During this phase, the
ethical hacker works with stakeholders to define the scope, objectives, constraints, and
legal permissions of the engagement.
• This stage ensures that testing activities remain lawful and aligned with business
priorities.
Key Activities:
• Defining systems and networks in scope
• Identifying testing depth (black, grey, white box)
• Establishing rules of engagement
• Obtaining written authorization
Why It Matters:
• Without authorization, hacking activities—regardless of intent—are illegal.
More info: Hands on Hacking: Become an Expert at Next Gen Penetration Testing and Purple, Chp. 2 pg. 18-19
Overview of Ethical Hacking Lifecycle Stages
Stage 2 – Reconnaissance (Information Gathering)
• Reconnaissance is the process of collecting information about the target organization before
attempting any attack. The goal is to understand the target’s infrastructure, technologies, and
human elements.
• This stage helps ethical hackers map the attack surface and identify potential entry points.
Types of Reconnaissance:
• Passive Reconnaissance: Collecting publicly available data without interacting directly with the
target
• Active Reconnaissance: Direct interaction with target systems to gather technical details
Outputs:
• Domain and IP information
• Technology stack insights
• Organizational structure data
More info: Redefining Hacking: A Comprehensive Guide to Red Teaming and Bug Bounty Hunting in AI-driven World, Chp. 9
Overview of Ethical Hacking Lifecycle Stages
More info: Redefining Hacking: A Comprehensive Guide to Red Teaming and Bug Bounty Hunting in AI-driven World, Chp. 9
Overview of Ethical Hacking Lifecycle Stages
Stage 3 – Scanning and Enumeration
• Scanning and enumeration involve actively probing the target systems to
identify live hosts, open ports, running services, and system configurations.
• Enumeration goes deeper by extracting detailed information such as
usernames, shared resources, and service versions.
Key Objectives:
• Identify accessible systems
• Discover exposed services
• Gather technical details for vulnerability mapping
Importance:
This phase transforms reconnaissance data into actionable technical
intelligence.
More info: Learn Ethical Hacking from Scratch: Your Stepping Stone to Penetration Testing, Chp. 11
More info: CEH Certified Ethical Hacker All-in-One Exam [Link], Chp. 3
Overview of Ethical Hacking Lifecycle Stages
Stage 4 – Vulnerability Analysis
• Vulnerability analysis involves identifying weaknesses in discovered systems
and services. Ethical hackers match system configurations and software
versions against known vulnerability databases and security advisories.
Vulnerabilities may arise from:
• Outdated software
• Misconfigurations
• Weak authentication mechanisms
• Insecure coding practices
The focus is on risk, not just the number of vulnerabilities.
More info: Ethical Hacking and Penetration Testing Guide , Chp. 5
Overview of Ethical Hacking Lifecycle Stages
Stage 5 – Exploitation
• Exploitation is the controlled process of attempting to take advantage of identified
vulnerabilities. The goal is not damage, but validation—proving that a vulnerability is
exploitable.
Key Principles:
• Minimal impact
• Controlled execution
• Proof of concept only
Examples of Exploitation Outcomes:
• Unauthorized access
• Privilege escalation
• Data exposure demonstration
More info: Learn Ethical Hacking from Scratch: Your Stepping Stone to Penetration Testing, Chp. 16
More info: Redefining Hacking: A Comprehensive Guide to Red Teaming and Bug Bounty Hunting in AI-driven World, Chp. 6
Overview of Ethical Hacking Lifecycle Stages
Stage 6 – Post-Exploitation
• Post-exploitation assesses the real-world impact of a successful
attack. Ethical hackers determine how far an attacker could move
within the system and what data or resources could be compromised.
Activities Include:
• Privilege escalation analysis
• Lateral movement testing
• Data sensitivity evaluation
Purpose:
To demonstrate business impact rather than technical flaws alone.
More info: Learn Ethical Hacking from Scratch: Your Stepping Stone to Penetration Testing, Chp. 16
More info: Redefining Hacking: A Comprehensive Guide to Red Teaming and Bug Bounty Hunting in AI-driven World, Chp. 6
Overview of Ethical Hacking Lifecycle Stages
Stage 7 – Reporting and Remediation
• Reporting is one of the most critical phases of ethical hacking. Findings must
be documented clearly for both technical and non-technical stakeholders.
Effective Reports Include:
• Vulnerability descriptions
• Risk ratings
• Exploitation evidence
• Clear remediation recommendations
Ethical hackers may also support organizations during remediation and re-
testing.
More info: Learn Ethical Hacking from Scratch: Your Stepping Stone to Penetration Testing, Chp. 16
More info: Redefining Hacking: A Comprehensive Guide to Red Teaming and Bug Bounty Hunting in AI-driven World, Chp. 9
More info: Ethical Hacking and Penetration Testing Guide , Chp. 1 Pg 8 -12
More info: Redefining Hacking: A Comprehensive Guide to Red Teaming and Bug Bounty Hunting in AI-driven World, Chp. 9
More info: Ethical Hacking and Penetration Testing Guide , Chp. 1 Pg 8 -12
More info: Redefining Hacking: A Comprehensive Guide to Red Teaming and Bug Bounty Hunting in AI-driven World, Chp. 9
Ethical Principles Across the Lifecycle
Ethics apply to every stage of ethical hacking. Ethical hackers must:
• Respect privacy
• Protect sensitive data
• Operate within scope
• Maintain confidentiality
Ethical failures can cause reputational, legal, and financial harm.
Modern Ethical Hacking Lifecycle (AI Integration)
• Modern ethical hacking integrates AI technologies to enhance
reconnaissance, scanning, and analysis.
AI Enhancements Include:
• Automated OSINT analysis
• Intelligent attack surface discovery
• Vulnerability prioritization using ML
• Continuous security monitoring
However, human oversight remains essential to ensure accuracy and
ethics.
More info: Redefining Hacking: A Comprehensive Guide to Red Teaming and Bug Bounty Hunting in AI-driven World, Chp. 9
Vulnerability Assessment and Penetration Testing
• Vulnerability Assessment and Penetration Testing are
two core security testing approaches used to identify
and manage security risks in information systems.
While they are often mentioned together, they serve
different purposes, follow different methodologies,
and produce different outcomes.
• Understanding the distinction between VA and PT is
critical for selecting the appropriate security testing
strategy and for interpreting security reports correctly.
More info: Hands on Hacking: Become an Expert at Next Gen Penetration Testing and Purple, Chp. 2 pg. 17
More info: Ethical Hacking and Penetration Testing Guide , Chp. 1 Pg 8 -9
Why Organizations Need VA and PT
• Modern organizations operate complex systems that
are continuously exposed to cyber threats.
Vulnerability Assessment and Penetration Testing help
organizations proactively identify weaknesses before
they are exploited by attackers.
• Vulnerability Assessment focuses on breadth and
coverage, while Penetration Testing focuses on depth
and impact. Together, they provide a comprehensive
view of an organization’s security posture.
More info: Ethics Hacking and Penetration Testing Guide, Chp. 3
More info: Redefining Hacking: A Comprehensive Guide to Red Teaming and Bug Bounty Hunting in AI-driven World, Chp. 1
What Is Vulnerability Assessment?
• Vulnerability Assessment is a systematic process of identifying,
quantifying, and prioritizing vulnerabilities in systems,
networks, and applications. It aims to discover as many
potential weaknesses as possible without attempting to exploit
them.
• The primary objective is risk awareness rather than attack
simulation.
• It includes the following characteristics
• Broad coverage
• Mostly automated
• Non-intrusive
• Repeated regularly
What Is Vulnerability Assessment?
• The Vulnerability Assessment process typically includes
asset discovery, vulnerability scanning, analysis of findings,
and risk prioritization.
• The results help security teams understand what
vulnerabilities exist, where they are located, and which
ones require urgent attention.
Typical Activities Include:
• Network and system scanning
• Configuration reviews
• Software version checks
• Vulnerability severity ranking
Types of Vulnerability Assessment
• Vulnerability Assessment can be classified based on
the scope and target environment.
• Common Types Include:
• Network-based vulnerability assessment
• Host-based vulnerability assessment
• Application vulnerability assessment
• Cloud and configuration vulnerability assessment
• Each type focuses on identifying weaknesses in a specific
layer of the IT environment.
Limitations of Vulnerability Assessment
• While Vulnerability Assessment is valuable, it has
limitations. It often generates a large number of
findings, including false positives, and does not
confirm whether vulnerabilities are exploitable in real-
world scenarios.
• VA answers the question “What could be
vulnerable?” but not “What can actually be
exploited?”
What Is Penetration Testing?
• Penetration Testing is a controlled security exercise
that simulates real-world cyberattacks to evaluate the
effectiveness of security controls. Unlike Vulnerability
Assessment, Penetration Testing actively attempts to
exploit identified vulnerabilities.
• The goal is to demonstrate actual risk and impact
rather than theoretical weaknesses.
More info: Ethical Hacking and Penetration Testing Guide , Chp. 1
Penetration Testing Process
• Penetration Testing follows a structured methodology that
includes reconnaissance, scanning, exploitation, post-
exploitation, and reporting.
• Each phase builds on the previous one to simulate how an
attacker would progress through the environment.
Key Focus Areas:
• Exploit validation
• Attack path identification
• Security control testing
More info: Ethical Hacking and Penetration Testing Guide , Chp. 1
Gray Hat Hacking: The Ethical Hacker's Handbook, Chp 6 Pg 114
Categories of Penetration Testing
• Penetration Testing can be classified based on
knowledge and access provided to the tester.
Common Categories Include:
• Black-box testing
• White-box testing
• Grey-box testing
Each type provides different insights into security
weaknesses and defensive effectiveness.
More info: Ethical Hacking and Penetration Testing Guide , Chp. 1 Pg 7
More info: Ethical Hacking and Penetration Testing Guide , Chp. 1 Pg 7
Types of Penetration Testing
• There are several types of penetration tests; however, the following are the ones most commonly performed;
• Network Penetration Test In a network penetration test, you would be testing a network environment for potential
security vulnerabilities and threats. This test is divided into two categories: external and internal penetra tion tests. An
external penetration test would involve testing the public IP addresses, whereas in an inter nal test, you can become
part of an internal network and test that network. You may be provided VPN access to the network or would have to
physically go to the work environment for the pen etration test depending upon the engagement rules that were
defined prior to conducting the test.
• Web Application Penetration Test Web application penetration test is very common nowadays, since your application
hosts critical data such as credit card numbers, usernames, and passwords; therefore this type of penetration test has
become more common than the network penetration test.
• Mobile Application Penetration Test The mobile application penetration test is the newest type of penetration test that
has become common since almost every organization uses Android- and iOS-based mobile applications to provide
services to its customers. Therefore, organizations want to make sure that their mobile applications are secure enough
for users to rely on when providing personal information when using such applications.
• Social Engineering Penetration Test A social engineering penetration test can be part of a network penetration test. In
a social engineering penetration test the organization may ask you to attack its users. This is where you use speared
phishing attacks and browser exploits to trick a user into doing things they did not intend to do.
• Physical Penetration Test A physical penetration test is what you would rarely be doing in your career as a penetration
tester. In a physical penetration test, you would be asked to walk into the organization’s building physi cally and test
physical security controls such as locks and RFID mechanisms.
More info: Ethical Hacking and Penetration Testing Guide , Chp. 1 Pg 8
Limitations of Penetration Testing
• Penetration Testing is time-bound and resource-intensive. It may not
identify all vulnerabilities and focuses primarily on exploitable issues
within the defined scope and timeframe.
• Penetration Testing answers “How far can an attacker go?” but not
“What vulnerabilities exist everywhere?”
Key Differences Between VA and PT
• Vulnerability Assessment and Penetration Testing differ in purpose,
approach, and outcomes.
• Vulnerability Assessment focuses on identification, while Penetration
Testing focuses on exploitation. VA is defensive and continuous,
whereas PT is adversarial and periodic.
Aspect Vulnerability Assessment Penetration Testing
Objective Identify vulnerabilities Exploit vulnerabilities
Scope Broad Narrow and deep
Automation High Low to moderate
Impact demonstration No Yes
Frequency Continuous Periodic