NodeZero | Internal Pentest
Name
Required
Scope
Required

The test's scope defines the list of subnets NodeZero will attempt to test. Subnets are specified using IP or CIDR notation.

Intelligent Scope i If no scope is defined, NodeZero will test the subnet in which it is deployed and the test will auto-expand using Intelligent Scope. Intelligent Scope does not guarantee that all RFC1918 addresses (10.0.0.0/8, 172.16.0.0/12, 198.168.0.0/16) will be scanned. NodeZero will scan networks that are numerically adjacent to the starting subnets. To scan subnets that are not adjacent to your starting scope, you must explicitly add them to the Include scope.
Add Full Private IP Space i
Auto-expand Scope i
AWS and Git Accounts

All cloud resources under these accounts will be treated as in scope.

Open Source Intelligence

These are optional fields that NodeZero will use to gather OSINT (Open Source Intelligence) to use as part of this pentest. Some advanced configurations require OSINT information, such as Azure AD Credential Pivoting.

Attack Configuration

These options allow fine-grained control over the types of services and vulnerabilities NodeZero will attempt to enumerate and exploit.

Brute Force i
Credential Verification !
Data i
Default Credentials !
Environment Impact !
Exploitation
Extended Scope i
Hash Cracking i
Man in the Middle Attacks i
Others i
Post-Exploitation i
Scan Options i
Scope discovery packets per second: i
Duration

Optionally set a minimum or maximum duration to extend or limit the duration of the test.

If the minimum or maximum duration is not selected, NodeZero will autonomously complete the pentest when it determines it is ready for processing.

Minimum Duration i
Run pentest for minimum of:
Maximum Duration i
Run pentest for maximum of:
Auto-Injected Credentials

Configure credentials to be auto-injected into the test by a NodeZero Runner. Learn more about auto-injected credentials.

At a high level, the steps for configuring an auto-injected credential are:

  • Install h3-cli and spin up a NodeZero Runner on your system (the Runner is what auto-injects the credential).
  • Use h3-cli to create an auto-injected credential.
  • Return here to add the auto-injected credential to your pentest configuration/template.
Runner

Use a NodeZero Runner to automatically deploy NodeZero on your Docker host. Learn more about scheduling pentests.