How to set a security assessment objective
← All guidesA useful objective names the target and the access you want to test. “Test our security” leaves the result open to interpretation. “Obtain Domain Admin in the test domain” gives the assessment a condition it can work toward and report against.
Start with the asset you are protecting. Then decide what access to that asset would constitute a compromise.
Name the target and the action
These are examples of objective wording, not promises that every target or access method is supported:
- Directory control: obtain Domain Admin in the named Active Directory domain.
- Data access: read a designated test document from the finance file share.
- Administrative access: obtain administrator access to the named backup server.
Use names that distinguish the target from similar systems. For a data objective, agree on what evidence is needed and which data the test may access. A designated test document can make success clear without making the objective “collect everything.”
Set scope separately
The objective describes the result you want to test. Scope describes where the campaign is authorized to act. Exclusions and change permissions further constrain how it gets there.
A request to reach a server does not authorize testing every system connected to it. Check the target ranges, exclusions, deployment position and starting credentials before creating the campaign. AutoAttack requires an objective; it does not choose one for your environment.
Choose the starting access deliberately
A campaign without credentials asks whether it can establish the first foothold. An assumed-breach campaign asks what a specified identity can reach. Choose the starting point that matches the concern you are investigating.
For example, concern about a compromised employee account calls for that account’s level of access. Supplying an administrator account would answer a different question.
Read the outcome against the objective
A reached objective should have a recorded route and evidence of the access gained. Read that evidence before deciding which credential exposure or permission needs attention.
If the campaign does not reach the objective, read where it stopped and what access it established. The result describes this campaign; it does not certify that every possible route is closed.
You can start a fresh campaign after making a change. AutoAttack does not track weaknesses across campaigns as fixed. Establishing a fix requires evidence that the relevant condition was reached and tested again.
The quickstart covers setup and the report. Review campaign controls before deploying.