Pentest Process Lifecycle

Standard penetration testing phases

Penetration Testing Process

Tip: Click on any node to see related information!

MAP Interactive Mind Map

graph TD A[Pre-Engagement] --> B[Information Gathering] B --> C[Vulnerability Assessment] C --> D[Exploitation] D --> E[Post-Exploitation] E --> F[Reporting] A --> G[Scope & Rules] B --> H[Recon & Enum] C --> I[Scan & Validate] D --> J[Gain Access] E --> K[PrivEsc & Pivot] F --> L[Document Findings]

REF Quick Reference

Phases

  • Pre-engagement: Scope, RoE, legal
  • Recon: Passive & active info gathering
  • Enumeration: Services, users, shares
  • Exploitation: Initial access
  • Post-Exploitation: Privesc, persistence, lateral movement
  • Reporting: Document findings

Key Commands

whois domain.com # Query domain registration info
dig domain.com ANY # Query all DNS records
host -t mx domain.com # Find mail servers
Back to Mind Maps View Full Module