Target selection and prioritization is a critical phase of penetration testing in which identified assets are evaluated based on their value to the organization and the relative ease of exploitation. This process helps testers sequence their attack path strategically to maximize efficiency and meet defined objectives.
Target Selection & Prioritization
Once we've done our discovery and figured out what's on our network, enumerated all of the different aspects of the network, and found vulnerabilities on the network, we're going to want to start choosing a target. There's going to be several targets within an organization most likely, and what we want to do is start identifying and prioritizing those targets.
There could be many different assets on this network that we want to leverage, that we want to actually carry out some sort of attack with, or use for meeting our objectives. Maybe an example of that is we find some really valuable information on the file server. Maybe this is information that we can do some sort of blackmail or ransomware with, or maybe sell to a competitor. So we find this information on there, and we're going to identify those assets that we want to leverage.
We could be encountering an issue where we have lots of different assets that we could leverage on this network. What we might want to do is start prioritizing: what is the first asset we want to leverage? What is the first thing that we want to get out of this? Maybe it's that valuable information from those files that are on there. Or maybe we find some other information or some other sources — maybe some code, maybe we find something else on the network as well. We aren't going to be able to export all of this at the same time, so we're going to have to start prioritizing what we're going to get first.
So we're going to be looking for those high value assets. But there is another evaluation as well, and that is how easy is it going to be to get to it? Are there a lot of vulnerabilities that we can leverage to get to that information, or is there going to be something better? So, for instance, maybe there's a very high value item here, but it's also going to take us a lot to get into that, versus something else might have lower value but it's going to be real easy to capture. So we capture and get that first, and then we start going after those high asset values.
So prioritization probably is off of the most valuable thing within the company, within the organization. But there's also this other assessment of what is going to be easier to get to, and some of that's based off of the vulnerabilities and our capability.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →