Abstract Information system security has become a crucial aspect as organizations' reliance on digital technology increases. Increasingly complex cyber threats demand systematic and ongoing security evaluations. This study aims to analyze the security level of information systems by applying a penetration testing method based on the Metasploit Framework. The research methodology refers to the Penetration Testing Execution Standard (PTES), which includes pre-engagement, intelligence gathering, vulnerability analysis, exploitation, post-exploitation, and reporting stages. The test results showed that of the 10 vulnerabilities identified, four were categorized as high risk, three as medium risk, and three as low risk. The exploitation phase demonstrated a 70% success rate, allowing researchers to gain initial access to the target system. In the post-exploitation phase, the access gained allowed attackers to access system files, read configurations, and escalate limited privileges. These findings confirm that implementing regular penetration testing can help organizations improve their information system security posture and minimize the risk of data leaks and service disruptions.
Copyrights © 2026