munotes®

The Five Phases of an Engagement: a Lifecycle Model

Get access to whole semester resourcesSemester Pass

Chapter Nine

Syllabus topic Module 1, "Foundations of Ethical Hacking ... ethical hacking phases ... Prepare a structured lifecycle model of ethical hacking"

Pages 41 to 45 of 578

In one line

An engagement runs through five phases in order: reconnaissance, scanning, gaining access, maintaining access, and covering tracks. An attacker runs all five to stay hidden; an ethical hacker runs as far as the scope requires to prove risk, preserves the evidence, and reports.

In examination wording: the ethical hacking lifecycle is a structured, repeatable process comprising (1) reconnaissance, the gathering of information about the target; (2) scanning, the identification of live hosts, open ports and services; (3) gaining access, the exploitation of a weakness to obtain entry; (4) maintaining access, the retention of that foothold; and (5) covering tracks, the concealment of the activity. Each phase is bounded by the engagement's authorisation and scope and is met by a corresponding defensive control.

Why a lifecycle model at all

Two reasons, one practical and one for the marks.

Practically, a model stops the work being a random walk. Testing without a process means poking at whatever catches the eye, and the result is uneven: three hours on an interesting but unimportant service while an exposed administrative interface sits undiscovered. A named sequence makes the work repeatable (another tester would cover the same ground) and complete (you can say what you did and did not do), and it makes the report readable, because the reader can follow the same order.

For the marks, MU asks you to prepare the model, which means drawing it and defending it, not listing five words. A model that lists five words is worth very little; a model that carries, for each phase, what happens, where authorisation binds it, and how a defender meets it, is the answer.

The provision broken down: the five phases

Phase 1: Reconnaissance

Gathering information about the target before, or with minimal, contact. It divides into passive reconnaissance, which uses third parties and never touches the target's systems (search engines, public records, social media, WHOIS), and active reconnaissance, which does touch them (resolving names against their servers, a light probe).

The aim is a map: domain names, addresses, technologies, people, email formats, third-party suppliers. Chapters later in this module cover it in detail.

This is the phase beginners undervalue and professionals rate highest, because everything after it is narrowed by what it finds. An attacker who knows your staff names, your technology versions and your forgotten test server has reduced a vast problem to a small one before sending a single suspicious packet.

The authorisation note: passive reconnaissance reads what is already public and touches nothing, so it does not engage section 43. Active reconnaissance does touch the target and does.

Phase 2: Scanning

Turning the map into a list of live hosts, open ports, running services and their versions. Host discovery first, then port scanning, then service and version detection, and often operating-system fingerprinting.

munotes.in41

The Five Phases of an Engagement: a Lifecycle Model

The output of this phase is the input to vulnerability analysis: a service and a version is what you look up to find known flaws. "Apache 2.4.x on port 443" is a sentence you can act on; "there is a web server somewhere" is not.

The authorisation note, and it is the important one: scanning plainly touches the target's systems and is an act under section 43. This is the first phase that unambiguously requires written permission, and students routinely believe the line is crossed later, at "gaining access". It is not.

Phase 3: Gaining access

Using a weakness found in scanning to obtain entry: a weak or default credential, an unpatched service with a known flaw, an injection flaw in an application, a misconfiguration.

This is where a risk stops being theoretical. A report that says "this version has a known critical flaw" is a hypothesis; a report that says "we used it to read the configuration file, here is the evidence" is proof, and it is far harder for an organisation to defer.

The discipline for an ethical hacker is least intrusion: gain access to the depth the scope allows, capture the evidence that proves the finding, and stop. The goal is demonstration, not conquest.

Phase 4: Maintaining access

Keeping the foothold, as a real attacker would, to show what a persistent intruder could reach: other systems, more data, higher privilege. Attackers do this with backdoors, additional accounts, scheduled tasks and rootkits.

In an ethical engagement this phase happens only if the scope permits it, everything installed is logged and removed afterwards, and the purpose is to demonstrate impact rather than to establish a presence. Many engagements stop before this phase entirely, and the report simply notes what a real attacker would have attempted next.

Phase 5: Covering tracks

An attacker's fifth phase is concealment: deleting or editing logs, hiding files, clearing command history, using timestamps that blend in. The purpose is to remain undetected so that phases three and four keep paying.

An ethical hacker inverts the spirit of this phase, and this is the single most important distinction in the chapter. They do not destroy the client's logs. They may test whether logging can be evaded, because "our logging did not record this" is a valuable finding, but they preserve the evidence, record precisely what they did and when, and hand it over. Cleaning up, for a tester, means removing the artefacts they introduced, not removing the record that they were there.

Understanding the attacker's version matters defensively, because it tells you what an intruder will attack: the logs are the record of the attack, so the logs are a target. That is the argument for centralised, append-only, off-host logging.

munotes.in42

The Five Phases of an Engagement: a Lifecycle Model

The lifecycle model, as a table you can reproduce

This is what MU asks you to prepare. Learn it in this shape and you can draw it under examination conditions.

PhaseWhat happensAuthorisation boundaryDefensive control
1. ReconnaissanceGather public information (passive) and light-contact information (active)Passive touches nothing; active touches the target and needs permissionReduce public footprint; monitor for unusual queries
2. ScanningFind live hosts, open ports, services and versionsPlainly an act under s.43; written permission requiredFirewall, close unused ports, intrusion detection
3. Gaining accessExploit a weakness to obtain entry and prove the riskOnly to the depth the scope allows; least intrusionPatching, strong authentication, input validation, least privilege
4. Maintaining accessRetain the foothold to demonstrate impactOnly if the scope permits; log everything and remove it afterEndpoint detection, integrity monitoring, hunting for persistence
5. Covering tracksAn attacker conceals; a tester preserves and documentsNever destroy the client's evidenceCentralised, append-only, protected logging

The third column is the thread from the law chapters running through every phase. The fourth column is the thread that runs into every later chapter of the book, and it is the subject of the next chapter.

A worked example

Sana is engaged to test one web server. The scope names a single host, permits exploitation to the minimum depth needed to prove a finding, and forbids persistence.

Reconnaissance. She reads the company's public site, notes the technology named in its page headers and a staff email format from a published address, and looks up the domain's DNS records. Nothing she has done touches the company's own systems.

Scanning. With the authorisation in hand she scans the one named host and finds three open ports; version detection shows an out-of-date web server on one of them.

Gaining access. She confirms the outdated version has a known flaw and uses it to read a configuration file. That is enough: the risk is proven. She captures the evidence with the sensitive values masked and goes no further.

Maintaining access. Out of scope, so she does not attempt it. The report records that a real attacker would have tried, and that the credentials in the configuration file would have allowed it.

Covering tracks. She preserves every log, records the exact times of each test so the client can separate her activity from a real attacker's, removes nothing, and hands over the evidence.

Her report then follows the same five headings, which is a second reason to internalise the model: it structures the work and the write-up alike.

munotes.in43

The Five Phases of an Engagement: a Lifecycle Model

What beginners get wrong

  • Believing an ethical hacker runs all five phases fully. They run as far as the scope requires to prove risk, often stopping in phase 3, and they never "cover tracks" against the client.
  • Skipping reconnaissance because it does not feel like hacking. It is the phase with the highest return, and the one whose omissions silently limit everything after it.
  • Thinking the legal line is crossed at phase 3. It is crossed at phase 2, and often in the active half of phase 1. Scanning is an act under section 43.
  • Treating the phases as strictly one-way. They loop: access to one system starts fresh reconnaissance and scanning from inside it. The linear order is the teaching model; real work spirals.
  • Listing five words as "the model". MU asks for a structured model. Without the authorisation boundary and the defensive control, it is a list, not a model.

Quick revision

  • Five phases: (1) reconnaissance, (2) scanning, (3) gaining access, (4) maintaining access, (5) covering tracks.
  • Reconnaissance splits into passive (third parties, touches nothing) and active (touches the target, needs permission).
  • Scanning is the first phase that plainly needs authorisation under s.43, not gaining access.
  • An ethical hacker stops where the scope says, practises least intrusion, and preserves evidence rather than destroying it; cleaning up means removing artefacts introduced, not removing the record.
  • The model to reproduce carries four columns: phase, what happens, the authorisation boundary, the defensive control.
  • The phases loop; the linear order is a teaching device.

Test yourself

  1. Name the five phases of an ethical hacking engagement in order, and say what each produces.

Reconnaissance (a map of the target from public and light-contact sources), scanning (live hosts, open ports, services and versions), gaining access (proven entry through a weakness), maintaining access (demonstrated persistence and reach), covering tracks (concealment by an attacker; preserved and documented evidence by a tester).

  1. At which phase is authorisation first clearly required, and why do students get this wrong?

At scanning, because scanning unambiguously touches the target's systems and is an act under section 43 of the IT Act. Students assume the line is crossed only at gaining access, but by then it has been crossed twice, since active reconnaissance can require permission too.

  1. How does an ethical hacker's handling of the fifth phase differ from an attacker's, and what does the attacker's version teach a defender?

An attacker deletes or edits logs and hides files to stay undetected. An ethical hacker preserves the client's logs, documents exactly what was done and when, and removes only the artefacts they introduced. The attacker's version teaches that logs are themselves a target, which is the argument for centralised, append-only, off-host logging.

munotes.in44

The Five Phases of an Engagement: a Lifecycle Model

  1. What four things should each phase carry in the lifecycle model MU asks you to prepare?

The phase name, what happens in it, the authorisation and scope boundary that applies to it, and the defensive control that detects or prevents it.

  1. Why is reconnaissance described as the highest-value phase?

Because it narrows a vast problem to a small one before any suspicious contact: knowing the technologies, people, email format and forgotten hosts determines what every later phase can achieve, and anything missed in reconnaissance silently limits the rest of the engagement.

munotes.in45

The rest of this subject

These notes are cut from the University's printed syllabus. Open the syllabus itself for the same subject.

Issue
Done!