Offensive Reporting

Penetration test and red team report writing methodology: executive summary structuring (risk-led narrative for non-technical readers), technical finding format (title, severity, scope, narrative, reproduction, impact, remediation, references), CVSS v3.1/v4.0 scoring with vector justification, OWASP risk rating, evidence hygiene (redacting credentials, hashing client data, time-stamping actions), screenshot and PoC artifact management, finding chain narratives, scope/limitations/assumptions, retest and remediation tracking, deliverable formats (PDF, DOCX, HTML, JSON for SIEM), client-customer-deliverable separation, and common mistakes (over-CVSSing, undermining the triager, missing the 'so what'). Use at the end of an engagement when authoring a deliverable, restructuring a draft for executive readability, or building a reusable report template. Authorized security research, training, or assessment only.

26zl d69e54a 14.3 KB Updated

File contents

26zl/cybersec-toolkit/tree/main/.claude/skills/offensive-reporting commit d69e54a5f7

Frequently asked questions

npx skillmds@latest add 26zl/offensive-reporting