← PenTest+: assessment, evidence, and remediation
05 / 6 · 45 MIN

Identity, host, and cloud

Evaluate permissions and exploitation conditions precisely.

Concept and mechanism

Suspicious configuration does not prove every exploitation condition exists. For a Windows service, a path containing spaces should be correctly quoted; impact assessment also needs to consider who can write to relevant locations and when the service starts. Analysis should identify those conditions without declaring arbitrary execution merely from configuration appearance. In SMB, signing supports integrity and helps counter relay and tampering, but it is not equivalent to content encryption. Implementation needs to consider client compatibility and requirements. In cloud, outcomes depend on effective policy: an applicable explicit Deny overrides Allow regardless of creation order.

Guided application

In a fictional thumbnail project, requiring IMDSv2 strengthens metadata access but does not alone fix every destination the application can fetch. Keep outbound control and least-privilege identity permissions as separate decisions. In an authentication exercise, approving repeated notifications can demonstrate fatigue; phishing-resistant authentication, prompt limits, and detection address that pattern better than simply increasing notifications. Finally, an agent reading documents should not accept document instructions as authorization to change permissions. Test the boundary between retrieved content, user identity, and available tools. The report should state which control was observed, under what condition it failed, and which part of the path remains unvalidated, avoiding broad guarantees based on one adjustment.

IN PRACTICE

Allow with an applicable explicit Deny remains denied; an additional policy is not a tie-breaking vote.

Common pitfalls

Suspicious configuration as proven exploitation; signing as encryption; IMDSv2 as universal remediation; content as authority.

Related topics: Scope, communication, and evidence · Reconnaissance and result interpretation · Discovery, coverage, and validation

Take this idea with you

Distinguish each control and the conditions under which it acts.

Create account

Reference: IAM policy evaluation · PT0-003 / PenTest+ V3; objectives 3.0; launched 2024-12-17