Scoping a Penetration Test

Here is an article from the Penetration Testing Execution Standard (PTES) about scoping a penetration test.

Go to Article

Scoping Template

Here is a scoping template you can use to build your own scoping document or compare with your current one.

View Scoping Template

Rules of Engagement

You must detail the rules of engagement in your scoping document and you must get written authorized from a person with the authority to do so at the target organization. You can go to jail if you test outside of your defined scope or do not get proper authorization to test. Watch 1:27-3:44 in this video for a word on rules of engagement.

Get the Slides
IN THE PRESS

Reconaissance

Here we go Recon stuff!

Heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Button Text

Learn from resources all over the web

Information is organized chronologically as it is needed during a penetration test

Presentation Videos

If you are doing OSINT for example, you won’t want to miss Rick Hayes’ and Karthik Rangarajan’s talk from Derbycon 2011. You will find that in the OSINT section. Increase your technical skills and perform better testing.

Text Descriptions and Links

Along with the videos, you will find summaries of the information provided and any tools or other resources that the talk spawned.

Technical Training

From scoping the test to writing the report and everything in between, learn how the professionals do it.

Penetration Testers on the web

Check this section out for a list of must watch penetration testers.

Pre-requisite knowledge

From learning the basics of computers to programming, learn what you need to understand hacking tools and techniques and develop your own.

Blue team and Incident Response

Learn defensive techniques, incident response, and digital forensics techniques to better understand your targets and develop bypasses and anti-forensics techniques and tools.

Show your support!

Please share on Twitter! Continue posting stellar blogs and presenting at conferences. If you would like to support this project directly, you may make donations through paypal. We appreciate your generosity and support!

Paypal Donation

$15 /month
500 Data Points
1 Team Member
Email Support
IOS and Android App
Customizable Dashboard
Metric API
Choose Plan

Get your swag!

$30 /month
2000 Data Points
1 Team Member
Email Support
IOS and Android App
Customizable Dashboard
Metric API
Choose Plan

Books via Amazon

$75 /month
5000 Data Points
3 Team Member
Email Support
IOS and Android App
Customizable Dashboard
Metric API
Choose Plan

Sponsorship

$250 /month
15000 Data Points
10 Team Member
Priority Support
IOS and Android App
Customizable Dashboard
Metric API
Choose Plan
Need more Data Points or Team Members? Please contact us.

Twitter mentions

“Donec ullamcorper nulla non metus auctor fringilla. Maecenas sed diam eget risus varius blandit sit amet non magna. Maecenas faucibus mollis interdum.”

Kyle Killit
Designer at Tiempo Labs

“Ullamcorper nulla non metus auctor fringilla. Maecenas sed diam eget risus varius blandit sit amet non magna”

Sergie Kalashnikov
CEO at BentoBox

“Nulla non metus auctor fringilla. Maecenas sed diam eget risus varius blandit sit amet non magna. Maecenas faucibus mollis interdum.”

Bryant Chou
CTO at Slapper Labs