Pick a depth. Each prompt opens in your AI pre-loaded with the lesson. Click a row to preview the prompt.
Multiple methodologies codify pentesting; they overlap but have different emphases. PTES (Penetration Testing Execution Standard) is the most-cited; OSSTMM focuses on operational security testing; NIST 800-115 is the US government's framework. A real engagement combines elements; the methodology is the planning skeleton.
PTES phases: 1. Pre-engagement (RoE, scope, contracts), 2. Intelligence gathering (OSINT), 3. Threat modelling (what's high-value), 4. Vulnerability analysis, 5. Exploitation, 6. Post-exploitation, 7. Reporting. Each has its own deliverables; the report is the only thing the client sees.