TechKnowSurge
VideoSecurityFree

Target Prioritization

Target selection and prioritization is a critical phase of penetration testing in which identified assets are evaluated based on their value to the organization and the relative ease of exploitation. This process helps testers sequence their attack path strategically to maximize efficiency and meet defined objectives.

Complete this video to capture a CTF flag worth 1 point.

About this video

Once network discovery and vulnerability enumeration are complete, the focus shifts to selecting and sequencing targets within the environment. A typical organizational network contains multiple assets of varying sensitivity and accessibility, and effective penetration testing requires a deliberate strategy for deciding which to pursue and in what order. Assets such as file servers containing confidential data, proprietary source code, or information with ransom or competitive intelligence value represent high-priority objectives. Because it is rarely possible to exfiltrate or exploit everything at once, testers must determine which assets to act on first. Target prioritization is driven by two intersecting factors: the value of the asset to the organization and the relative difficulty of reaching it. A highly sensitive asset protected by strong controls and few exploitable vulnerabilities may be ranked below a moderately valuable target that is far easier to access given the current vulnerability landscape and available capabilities. This approach allows testers to capture attainable assets early, potentially using them as stepping stones toward higher-value targets later in the engagement. The result is a structured attack path that reflects both strategic objectives and realistic exploitation conditions.

What you'll learn

What's covered

Target Selection & Prioritization

Key terms

Asset
Any resource of value to an organization, including hardware, software, data, and personnel.
Vulnerability
A weakness in a system, application, or process that can be exploited by a threat actor.
Penetration Testing
An authorized simulated attack on a system to identify and evaluate security vulnerabilities.
Exploit
A piece of software or technique that takes advantage of a vulnerability to gain unauthorized access or cause harm.
Data Exfiltration
The unauthorized transfer of data from a system to an external destination.
High-Value Target
HVT
An asset identified during post-enumeration as offering the greatest strategic return based on data sensitivity, business criticality, or ease of exploitation.
Exploitability
A measure of how easily a vulnerability can be leveraged by an attacker to gain unauthorized access to an asset.

Topics

Penetration Testing Target Prioritization Post Enumeration Asset Valuation Attack Path Planning Cybersecurity

Transcript

Once we've done our discovery and figured out what's on our network, enumerated all of the different aspects of the network, and found vulnerabilities on the network, we're going to want to start choosing a target. There's going to be several targets within an organization most likely, and what we want to do is start identifying and prioritizing those targets.

There could be many different assets on this network that we want to leverage, that we want to actually carry out some sort of attack with, or use for meeting our objectives. Maybe an example of that is we find some really valuable information on the file server. Maybe this is information that we can do some sort of blackmail or ransomware with, or maybe sell to a competitor. So we find this information on there, and we're going to identify those assets that we want to leverage.

We could be encountering an issue where we have lots of different assets that we could leverage on this network. What we might want to do is start prioritizing: what is the first asset we want to leverage? What is the first thing that we want to get out of this? Maybe it's that valuable information from those files that are on there. Or maybe we find some other information or some other sources — maybe some code, maybe we find something else on the network as well. We aren't going to be able to export all of this at the same time, so we're going to have to start prioritizing what we're going to get first.

So we're going to be looking for those high value assets. But there is another evaluation as well, and that is how easy is it going to be to get to it? Are there a lot of vulnerabilities that we can leverage to get to that information, or is there going to be something better? So, for instance, maybe there's a very high value item here, but it's also going to take us a lot to get into that, versus something else might have lower value but it's going to be real easy to capture. So we capture and get that first, and then we start going after those high asset values.

So prioritization probably is off of the most valuable thing within the company, within the organization. But there's also this other assessment of what is going to be easier to get to, and some of that's based off of the vulnerabilities and our capability.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →