
π’ Penetration Testing Process β Notes
Definition
- Process = sequence of events, flexible not fixed.
- Pentest process = successive steps to reach predefined objectives.
- Must be adaptable (every client/network is unique).
Stages of Penetration Testing
- Pre-Engagement
- Define objectives, scope, timeline.
- Contracts: NDA, Rules of Engagement.
- Client education + clarifications.
- Information Gathering
- Collect info about company, tech stack, infra.
- Identify potential attack surfaces.
- Vulnerability Assessment
- Analyze gathered info for known vulns.
- Manual + automated checks.
- Assess threat level & attack vectors.
- Exploitation
- Execute attacks against identified vectors.
- Gain initial access to systems.
- Post-Exploitation
- Maintain access.
- Privilege escalation.
- Pillaging: hunt credentials, sensitive data.
- Demonstrate impact to client.
- Lateral Movement
- Move inside internal network β more hosts.
- Iterative with post-exploitation.
- Example: foothold β priv esc β creds β DB server β more data.
- Proof-of-Concept (PoC)
- Document chain of vulnerabilities.
- Show clear attack path.
- Create scripts for reproducibility (if feasible).
- Post-Engagement
- Prepare detailed report (admins + execs).
- Walkthrough meeting with client.
- Clean traces, archive data.
- Optional retest after remediation.
Key Takeaways
- No fixed βrecipeβ, process must be flexible.