
A complete checklist for auditing and pentesting your entire network. This covers every router, firewall, server, and yes, even the humidity controller. This is every device audited by the team that breaks into networks for a living.


What's inside?
Two checklists in one, across 15 device and infrastructure types:
The audit checklist - every device, line by line: laptops, routers, firewalls, switches, Wi-Fi, Linux and Windows servers, storage, printers, cameras, UPS, biometric readers, and the control panels most audits forget.
The pentest checklist - mapped to how testers actually work: info gathering, authentication, authorization, session management, cryptography, business logic, and client-side testing.
Framework-aligned - built on OWASP, OSSTMM, WASC, CREST, and NIST, so it matches what your auditor checks.
What you’ll learn
By the end, you'll be able to:
Harden every device on your network, not just the obvious three, but down to the IoT panels attackers love because nobody's watching them.
Spot the default settings that ship insecure (default router passwords, exposed SNMP, UPnP left on) and know exactly what to change them to.
Lock down Linux and Windows servers step by step, from SSH config and Fail2Ban to Kerberos encryption and NTFS permissions.
Run a network pentest the way professionals do, following the same testing categories your auditor will.
Walk into a SOC 2, ISO 27001, or NIST audit knowing you've already covered what they'll check.
With Astra's VAPT, a full network assessment takes 40% less time than other solutions with the same rigor, without the wait.
Who’s this for?
Read this if you're a…
Network administrator or security engineer who's responsible for everything on the network and would like to sleep at night.
IT lead prepping for an audit SOC 2, ISO 27001, PCI-DSS, NIST, and want a head start on what gets checked.
DevOps or infra engineer hardening servers and quietly hoping nobody asks about the printer.