From b2e2c714c8d4edc91da124e1f1db0dc4591e8b04 Mon Sep 17 00:00:00 2001 From: molfinn <92950285+molfinn@users.noreply.github.com> Date: Wed, 18 Dec 2024 12:52:15 -0600 Subject: [PATCH] Delete content/en/Cybersecurity Services/digital-risk-assessment.md --- .../digital-risk-assessment.md | 44 ------------------- 1 file changed, 44 deletions(-) delete mode 100644 content/en/Cybersecurity Services/digital-risk-assessment.md diff --git a/content/en/Cybersecurity Services/digital-risk-assessment.md b/content/en/Cybersecurity Services/digital-risk-assessment.md deleted file mode 100644 index 00fec5b48..000000000 --- a/content/en/Cybersecurity Services/digital-risk-assessment.md +++ /dev/null @@ -1,44 +0,0 @@ ---- -title: "Digital Risk Assessment" -linkTitle: "Digital Risk Assessment" -weight: 100 -description: > - Review details & methodology for Digital Risk Assessments. ---- - - -## Digital Risk Assessment - -A Digital Risk Assessment (DRA) is a systematic process for identifying, analyzing, and prioritizing potential threats and vulnerabilities from an attacker’s perspective within an organization's digital ecosystem. - -Digital Risk Assessment is a type of engagement outside of our standard Pentesting as a Service. Refer to the below chart for details of a Digital Risk Assessment. - -| **Feature** | Description | -|---|---| -| **Fulfilled by** | Cybersecurity Services | -| **Number of credits** | Typically between 6 - 12 credits, dependent on scope | -| **Number of testers** | 1 tester | -| **Collaboration** | Slack | -| **Retesting** | Yes - according to your [credit tier](https://www.cobalt.io/pentest-pricing) | -| **Earliest start date** | Earliest start date will be based on availability. Typical start dates of 3-5 business dates once test is submitted to In Review | -| **Test duration** | Typically 10 days. Finalized once test is moved to Planned | -| **Report due date** | 5 business days after the test end date. Report will be delivered as a PDF within Reports section of the platform | -| **Kick off call** | Not included | -| **Debrief call** | Not included | - -### Methodology Details - -Cobalt will use publicly available information and commonly used OSINT methodologies and tooling (such as those documented at https://osintframework.com) to assess an organization from an external, adversarial perspective. Cobalt will employ a passive approach to OSINT reconnaissance. - -Activities conducted within a Digital Risk Assessment are noted within the brief: - -- Company research -- Domain and host enumeration -- Email, name, phone, and username harvesting -- Advanced Search Engine Operators ("dorks") -- Attempts to identify code used for internal applications -- Password dumps -- Attempts to identify sensitive or proprietary indexed files -- Identification of employee badges on social media sites -- Building layouts -- Online brand protection