Penetration Test Planning
Phase 1: Scope & Objectives
- Define test objectives
- Identify vulnerabilities in target systems
- Validate effectiveness of security controls
- Meet compliance requirements (PCI DSS, SOC 2, etc.)
- Test incident response capabilities
- Assess lateral movement potential
- Define in-scope targets
- IP ranges and hostnames
- Web applications and APIs
- Cloud accounts and services
- Mobile applications
- Wireless networks
- Define out-of-scope exclusions
- Set testing window and timeline
Scope Summary
| Target | Type | Environment | Testing Method | Priority |
|---|---|---|---|---|
| Network/App/Cloud/Wireless | Prod/Staging | Black/Gray/White box | High/Med/Low |
Phase 2: Rules of Engagement
- Define rules of engagement
- Testing hours and days permitted
- Acceptable attack techniques
- Prohibited actions (DoS, data destruction, social engineering limits)
- Data handling for sensitive findings
- Escalation procedures for critical findings
- Emergency stop procedures and contacts
- Get written authorization from system owners
- Coordinate with SOC/monitoring team
- Establish communication channels
Emergency Contact Matrix
| Role | Name | Phone | When to Contact | |
|---|---|---|---|---|
| Test Lead | Test coordination | |||
| System Owner | Authorization issues | |||
| SOC Contact | Alert deconfliction | |||
| Emergency Stop | Critical system impact |
Phase 3: Methodology Selection
- Select testing methodology
- OWASP Testing Guide (web applications)
- PTES (Penetration Testing Execution Standard)
- NIST SP 800-115 (Technical Guide to Testing)
- OSSTMM (Open Source Security Testing Methodology)
- Cloud-specific (AWS/GCP/Azure testing guides)
- Define testing phases
- Reconnaissance and information gathering
- Vulnerability scanning and analysis
- Exploitation and validation
- Post-exploitation and lateral movement
- Reporting and remediation support
Phase 4: Tool & Resource Preparation
- Prepare testing environment and tools
- Network scanning (Nmap, Masscan)
- Vulnerability scanning (Nessus, Qualys)
- Web application testing (Burp Suite, OWASP ZAP)
- Exploitation frameworks (Metasploit, custom scripts)
- Cloud assessment tools (ScoutSuite, Prowler)
- Password testing (Hashcat, John the Ripper)
- Reporting templates
- Set up VPN access and testing accounts (gray/white box)
- Verify testing infrastructure is ready
Phase 5: Execution Plan
- Day-by-day execution schedule
- Day 1-2: Reconnaissance and scanning
- Day 3-5: Vulnerability analysis and exploitation
- Day 6-7: Post-exploitation and lateral movement
- Day 8: Cleanup and evidence collection
- Day 9-10: Report writing
- Daily status reporting to stakeholders
- Immediate notification for critical findings
- Evidence collection and chain of custody
Phase 6: Reporting & Remediation
- Prepare penetration test report
- Executive summary for leadership
- Technical findings with CVSS scoring
- Proof-of-concept details with evidence
- Remediation recommendations prioritized by risk
- Positive findings (controls that worked)
- Conduct findings walkthrough with technical team
- Develop remediation plan with timelines
- Schedule retest for critical and high findings
Finding Severity Classification
| Severity | CVSS Score | Remediation SLA | Example |
|---|---|---|---|
| Critical | 9.0-10.0 | 7 days | RCE, auth bypass |
| High | 7.0-8.9 | 30 days | SQLi, privilege escalation |
| Medium | 4.0-6.9 | 90 days | XSS, info disclosure |
| Low | 0.1-3.9 | 180 days | Missing headers, verbose errors |
Counter-Rationalizations
| Shortcut | Counter | Why |
|---|---|---|
| "We can skip some steps for this case" | Adapt the workflow steps, don't skip them | Skipped steps are where incidents and oversights originate |
| "The user seems to already know what to do" | Complete all workflow phases with the user | The workflow catches blind spots that experience alone misses |
| "This is a minor case, full process is overkill" | Scale the process down, don't turn it off | Minor cases become major when unstructured; the process scales, not disappears |
| "I'll fill in the details later" | Complete each section before moving on | Deferred details are forgotten; real-time capture is more accurate |
| "The template output isn't necessary" | Always produce the structured output format | Structured output enables comparison, audit trails, and handoff to other teams |
Output Format
- Scope Document: Targets, rules of engagement, authorization
- Test Plan: Day-by-day schedule with methodology
- Status Reports: Daily updates during testing
- Final Report: Executive summary and technical findings
- Remediation Tracker: Findings with owners and SLA deadlines
Action Items
- Define scope and get written authorization
- Establish rules of engagement and emergency contacts
- Coordinate with SOC to avoid false positive alerts
- Prepare tools and testing environment
- Execute test per approved schedule
- Deliver report and conduct findings walkthrough
- Track remediation to completion and schedule retest