Question
FortiDeceptors running during PEN test - advice
Our cyber insurance company is running an internal pen test, and I wanted to see what others do when FortiDeceptor is running. My plan was to say nothing but add their IP to the safe list to prevent them from getting locked out mid-test. Then, when they find one, I will disclose it if they report it as a finding.
On the other hand, I feel that I am lowering my security for them, so I am torn on what to do. Any pen testers or people with FortiDeceptor out there who have had a similar issue?
Â
