# Penetration Testing Methodology

> Use when structuring penetration testing engagements.

- Skill: `loopyluci/penetration-testing-methodology` (Agent Skill)
- Install (CLI): `npx skillmds@latest add loopyluci/penetration-testing-methodology`
- Raw SKILL.md: https://api.skillmd.com/api/skills/loopyluci/penetration-testing-methodology/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- License: MIT
- Author: LoopyLuci (https://skillmd.com/u/loopyluci)
- Updated: 2026-09-08
- Page: https://skillmd.com/skills/loopyluci/penetration-testing-methodology

---


# Penetration Testing Methodology

Structuring penetration testing engagements — from scoping and reconnaissance through exploitation, post-exploitation, and professional reporting.

## When to Use

- Planning and scoping a penetration test
- Executing a structured pentest methodology
- Writing professional pentest reports
- Understanding pentest phases and deliverables

## Pentest Phases

```python
PENTEST_PHASES = {
    'scoping': 'Define scope (IP ranges, URLs, apps), rules of engagement, exclusions',
    'reconnaissance': 'Passive (OSINT, DNS, WHOIS) and active (scanning, enumeration)',
    'vulnerability_analysis': 'Scanning, manual testing, configuration review, threat modeling',
    'exploitation': 'Validate vulnerabilities, gain initial access',
    'post_exploitation': 'Privilege escalation, lateral movement, data exfiltration testing',
    'reporting': 'Executive summary, findings (risk-ranked), remediation, evidence',
}

PENTEST_TYPES = {
    'black_box': 'No prior knowledge — simulates external attacker',
    'white_box': 'Full knowledge (source, credentials, architecture) — thorough assessment',
    'gray_box': 'Partial knowledge (limited credentials, documentation) — realistic insider',
    'covert': 'Stealth assessment — target doesn't know testing is happening',
}

class PentestEngagement:
    """Manage pentest engagement lifecycle."""
    def __init__(self, client: str, scope: Dict, type: str = 'gray_box'):
        self.client = client
        self.scope = scope
        self.type = type
        self.findings = []
        self.phase = 'scoping'
    
    def add_finding(self, name: str, severity: str, cvss: float,
                     description: str, remediation: str):
        self.findings.append({
            'name': name, 'severity': severity, 'cvss': cvss,
            'description': description, 'remediation': remediation,
        })
```

## Verification Checklist

- [ ] Rules of engagement documented and signed
- [ ] Scope clearly defined (what is in/out of scope)
- [ ] Authorization letter / penetration testing agreement in place
- [ ] Methodology followed (PTES, OWASP, OSSTMM, or custom)
- [ ] All phases completed (recon → analysis → exploitation → reporting)
- [ ] Findings risk-ranked (CVSS 1-10 or custom scoring)
- [ ] Remediation guidance provided per finding
- [ ] Report delivered with executive summary and technical appendix
- [ ] Data securely destroyed post-engagement

