pentest-engagement
Yetkili penetration testing engagement'i icin planning + scoping + ROE dokumantasyonu uretir.
Triggers
- "pentest plan hazirla"
- "ROE taslagi cikar"
- "scoping document"
- "engagement timeline"
- "MITRE ATT&CK matrix"
- "kickoff meeting agenda"
- "closeout rapor sablonu"
Deliverable'lar
- Scope Document (in-scope, out-of-scope, kisitlar)
- Rules of Engagement (ROE) (yasak teknikler, calisma saatleri, escalation path)
- Phased Timeline (kickoff -> recon -> exploit -> post-ex -> reporting -> closeout)
- MITRE ATT&CK Mapping (her faza karsilik gelen Tactic + Technique listesi)
- Communication Plan (musteri contact, escalation contact, incident response)
- Acceptance Criteria (kapsanan testler, raporlama, deliverable listesi)
Scope Document Sablonu
# Engagement Scope — <Musteri>
## In-Scope
- IP Ranges: 10.0.0.0/16, 192.168.50.0/24
- Domains: *.example.com, app.example.com
- Cloud Accounts: AWS 123456789012 (production us-east-1)
- Test Tipi: External / Internal / Web App / Cloud / Red Team
## Out-of-Scope
- Production DB direct query
- Email/Phishing musteri calisani
- DoS / stress testing
- 3. taraf SaaS (Stripe, SendGrid, vb.)
## Restrictions
- Calisma saatleri: Hafta ici 09:00-17:00 (TR)
- Aggressive scan: Sadece kullanici onayli pencerede
- Data exfil: Yok — sadece kanit dosyasi (max 1MB)
## Authorization
- Letter of authorization: <link>
- Musteri imza: <isim, tarih>
- Pentest firma imza: <isim, tarih>
Phased Plan Sablonu (5 Phase)
| Faz |
Sure |
Aktivite |
MITRE Tactic |
| 1. Recon |
1-2 gun |
OSINT, subdomain enum, port scan |
TA0043 Reconnaissance |
| 2. Initial Access |
2-3 gun |
Web app exploit, phishing sim, AD attack |
TA0001 Initial Access |
| 3. Post-Exploit |
3-4 gun |
Privesc, lateral, persistence, exfil sim |
TA0004/TA0008/TA0003/TA0010 |
| 4. Detection |
1-2 gun |
SIEM/EDR coverage gap |
TA0042 Resource Development (defansif) |
| 5. Report |
2-3 gun |
Bulgu yazimi, CVSS, remediation, debrief |
— |
MITRE ATT&CK Mapping
Her bulgu icin minimum 1 ATT&CK Technique ID belirt (T1059, T1078, vb.). Mapping:
finding: SQL Injection in /api/users
mitre:
tactic: TA0001 (Initial Access)
techniques:
- T1190 (Exploit Public-Facing Application)
detection:
- Sigma rule: web/sql_injection.yml
remediation:
priority: P0
effort: 8h
Kickoff Meeting Agenda (1 saat)
- Scope review + signoff (10 dk)
- ROE walkthrough + restrictions (15 dk)
- Communication channel + escalation (10 dk)
- Asset inventory hand-off (15 dk)
- Q&A + ilk gun planning (10 dk)
Closeout Meeting Agenda (1.5 saat)
- Executive summary (10 dk)
- Top 3 critical finding walkthrough (30 dk)
- Remediation roadmap (20 dk)
- Detection rule hand-off (15 dk)
- Lessons learned (15 dk)
Cikti Konumu
Engagement basinda olustur:
engagements/<musteri>-<yyyymmdd>/
scope.md
roe.md
timeline.md
mitre-mapping.yml
contacts.md
Out-of-Scope (Bu Skill Yapmaz)
- Live komut composer'lama (pentest-recon, pentest-web vb. yapar)
- Exploit guide uretmek (pentest-exploit-chain yapar)
- Rapor yazma (pentest-report yapar)
Bu skill sadece planning + scoping doc uretir.
1---2name: pentest-engagement3description: Penetration testing engagement planning — scoping, ROE drafting, phased timeline, MITRE ATT&CK mapping, kickoff/closeout dokumantasyonu. Triggers on engagement plan, ROE, rules of engagement, scoping, pentest plan, phased plan, MITRE mapping, attack matrix, kickoff, closeout.4license: MIT5---6
7# pentest-engagement
8
9Yetkili penetration testing engagement'i icin **planning + scoping + ROE** dokumantasyonu uretir.
10
11## Triggers
12
13- "pentest plan hazirla"
14- "ROE taslagi cikar"
15- "scoping document"
16- "engagement timeline"
17- "MITRE ATT&CK matrix"
18- "kickoff meeting agenda"
19- "closeout rapor sablonu"
20
21## Deliverable'lar
22
231. **Scope Document** (in-scope, out-of-scope, kisitlar)
242. **Rules of Engagement (ROE)** (yasak teknikler, calisma saatleri, escalation path)
253. **Phased Timeline** (kickoff -> recon -> exploit -> post-ex -> reporting -> closeout)
264. **MITRE ATT&CK Mapping** (her faza karsilik gelen Tactic + Technique listesi)
275. **Communication Plan** (musteri contact, escalation contact, incident response)
286. **Acceptance Criteria** (kapsanan testler, raporlama, deliverable listesi)
29
30## Scope Document Sablonu
31
32```markdown
33# Engagement Scope — <Musteri>
34
35## In-Scope
36- IP Ranges: 10.0.0.0/16, 192.168.50.0/24
37- Domains: *.example.com, app.example.com
38- Cloud Accounts: AWS 123456789012 (production us-east-1)
39- Test Tipi: External / Internal / Web App / Cloud / Red Team
40
41## Out-of-Scope
42- Production DB direct query
43- Email/Phishing musteri calisani
44- DoS / stress testing
45- 3. taraf SaaS (Stripe, SendGrid, vb.)
46
47## Restrictions
48- Calisma saatleri: Hafta ici 09:00-17:00 (TR)
49- Aggressive scan: Sadece kullanici onayli pencerede
50- Data exfil: Yok — sadece kanit dosyasi (max 1MB)
51
52## Authorization
53- Letter of authorization: <link>
54- Musteri imza: <isim, tarih>
55- Pentest firma imza: <isim, tarih>
56```
57
58## Phased Plan Sablonu (5 Phase)
59
60| Faz | Sure | Aktivite | MITRE Tactic |
61|-----|------|----------|--------------|
62| 1. Recon | 1-2 gun | OSINT, subdomain enum, port scan | TA0043 Reconnaissance |
63| 2. Initial Access | 2-3 gun | Web app exploit, phishing sim, AD attack | TA0001 Initial Access |
64| 3. Post-Exploit | 3-4 gun | Privesc, lateral, persistence, exfil sim | TA0004/TA0008/TA0003/TA0010 |
65| 4. Detection | 1-2 gun | SIEM/EDR coverage gap | TA0042 Resource Development (defansif) |
66| 5. Report | 2-3 gun | Bulgu yazimi, CVSS, remediation, debrief | — |
67
68## MITRE ATT&CK Mapping
69
70Her bulgu icin minimum 1 ATT&CK Technique ID belirt (T1059, T1078, vb.). Mapping:
71
72```yaml
73finding: SQL Injection in /api/users
74mitre:
75 tactic: TA0001 (Initial Access)
76 techniques:
77 - T1190 (Exploit Public-Facing Application)
78detection:
79 - Sigma rule: web/sql_injection.yml
80remediation:
81 priority: P0
82 effort: 8h
83```
84
85## Kickoff Meeting Agenda (1 saat)
86
871. Scope review + signoff (10 dk)
882. ROE walkthrough + restrictions (15 dk)
893. Communication channel + escalation (10 dk)
904. Asset inventory hand-off (15 dk)
915. Q&A + ilk gun planning (10 dk)
92
93## Closeout Meeting Agenda (1.5 saat)
94
951. Executive summary (10 dk)
962. Top 3 critical finding walkthrough (30 dk)
973. Remediation roadmap (20 dk)
984. Detection rule hand-off (15 dk)
995. Lessons learned (15 dk)
100
101## Cikti Konumu
102
103Engagement basinda olustur:
104```
105engagements/<musteri>-<yyyymmdd>/
106 scope.md
107 roe.md
108 timeline.md
109 mitre-mapping.yml
110 contacts.md
111```
112
113## Out-of-Scope (Bu Skill Yapmaz)
114
115- Live komut composer'lama (pentest-recon, pentest-web vb. yapar)
116- Exploit guide uretmek (pentest-exploit-chain yapar)
117- Rapor yazma (pentest-report yapar)
118
119Bu skill **sadece planning + scoping doc** uretir.