Patent attributes
Penetration testing campaigns are carried out using a lateral movement strategy based at least in part on information about files stored in network nodes of the networked system. Information is obtained about files stored in a plurality of network nodes of the networked system, and based on the obtained information, a corresponding data-value score for each network node of the plurality of network nodes is determined according to a common data-value metric. The penetration testing campaign is executed, during which a next network node targeted for determining its compromisability is selected based on the data-value scores corresponding to at least some of the plurality of network nodes. Based on results of the penetration testing campaign, a method by which an attacker could compromise the networked system is determined and reported.