Derbycon 2016 – Scripting Myself Out of a Job – Automating the Penetration Test with APT2

Nearly every penetration test begins the same way; run a NMAP scan, review the results, choose interesting services to enumerate and attack, and perform post-exploitation activities. What was once a fairly time consuming manual process, is now automated! Automated Penetration Testing Toolkit (APT2) is an extendable modular framework designed to automate common tasks performed during penetration testing. APT2 can chain data gathered from different modules together to build dynamic attack paths. Starting with a NMAP scan of the target environment, discovered ports and services become triggers for the various modules which in turn can fire additional triggers. Have FTP, Telnet, or SSH? APT2 will attempt common authentication. Have SMB? APT2 determines what OS and looks for shares and other information. Modules include everything from enumeration, scanning, brute forcing, and even integration with Metasploit. Come check out how APT2 will save you time on every engagement.
Adam Compton has been a programmer, researcher, professional pentester, and farmer. Adam has over 15 years of programming, network security, incident response, security assessment, and penetration testing experience. Throughout Adam’s career, he has worked for both federal and international government agencies as well as within various aspects of the private sector. Austin Lane spent 7 years working in development before jumping over to security, which he has now been doing for 3 years. In that time, he has worked on web apps, Android apps, network security, and completed the OSCP certification. He is currently a Security Consultant at Rapid7.
For More information Please Visit:- https://www.derbycon.com/
http://www.irongeek.com/i.php?page=videos/derbycon6/mainlist

Source: SecurityTube.Net @ November 29, 2016 at 09:04PM

0
Share