Stages of Investigation
The type of services offered to clients to some extent reflects the nature of the clients. For example, ClearTrace Intelligence would be a bad client for its own services! Generally speaking, the ideal client has been around for many years; has tended to outsource its IT or experience high turnover to its IT; may no longer be certain about its domains, subdomains, and their service condition; and has not kept up to date on the known vulnerabilities.
Stage 1: Reconnaissance
Normally, any domain or subdomain that had made of HTTPS has some type of public record. It may be difficult to determine if a particular domain belongs to the company or if it merely seems familiar. A list of possible candidates is gathered. Once the public records have been reviewed, any internal network information is also collected (only if the company wants to share the details).
Stage 2: Authorization for TCP Pinging
Although ClearTrace Intelligence has its own tools that non-invasively "ping" servers (to determine if they still seem to be operational), nonetheless every effort is made to obtain authorization to investigate the listed assets. If any listed server is unlikely to belong to company, it is excluded from this process. Note that this is not "scanning" in the conventional sense where attempts are made to identify the port services.
Stage 3: Authorization for Enumeration
This process is somewhat more invasive and is therefore scheduled during non-business hours. Using the list of active servers, a systematic process takes place to check each one for its port services. If possible, banners are collected to indentify the specific applications and their versions.
Stage 4: Check of Known Vulnerabilties
Although the "potential" vulnerabilities are documented for reporting purposes, no effort is made to actually confirm vulnerabilities. The ultimate confirmation comes from exploitation. I made a business decision not to do this. However, the findings can be used to support exploitation if the company is interested in this option at some future point.
Thousands of new vulnerabilities are discovered every month. One of the benefits of maintaining a record (essentially a type of audit or inventory) is to simplify the process of determining exposure to risk and determining the most appropriate mitigation measures. However, my involvement ends after I submit the vulnerability report. I would of course be delighted repeat the process as frequently as contracted to keep the records up to date.