Quick reference for authorized pentesting — the kill chain phases, lab-safe recon commands, and reporting structure.
PentestingReconCTFMethodology
Cyber Kill Chain Phases
| Phase | Attacker goal | Defense |
| Reconnaissance | Collect target info (OSINT) | Reduce exposure, ASM |
| Scanning / Enum | Find hosts, ports, versions | Firewall, IDS/IPS, segmentation |
| Gaining Access | Exploit for a foothold | Patch, input validation, least priv |
| Maintaining Access | Persistence | EDR, integrity monitoring |
| Covering Tracks | Erase evidence | Immutable/central logging, SIEM |
Recon & OSINT Tools (Lab / Authorized)
| Tool | Use |
whois / dig | Registration & DNS records |
amass / subfinder | Subdomain enumeration |
| crt.sh | Certificate transparency logs |
| theHarvester | Emails, hosts, names from public sources |
| Shodan / Censys | Internet-exposed service search |
whatweb | Web tech fingerprinting |
nmap Flags
| Flag | Meaning |
-sn | Ping/host discovery only, no port scan |
-sS | TCP SYN scan (needs root) |
-sV | Service/version detection |
-sC | Run default NSE scripts |
-p- / -p 80,443 | All ports / specific ports |
-A | OS detect + version + scripts + traceroute |
-T0..-T5 | Timing (T4 fast, T5 aggressive) |
-oA base | Output all formats (nmap/gnmap/xml) |
Common Enumeration Commands
Web / SMB / DNS
# Web content / directories
gobuster dir -u http://target -w /usr/share/wordlists/dirb/common.txt
ffuf -u http://target/FUZZ -w wordlist.txt
# SMB enumeration
enum4linux-ng -A target
smbclient -L //target -N
# DNS
dig any target.local @dns-server
dnsrecon -d target.local
# Web tech + headers
whatweb http://target
curl -sI http://target
CVSS 3.1 Severity Bands
| Score | Severity |
| 0.0 | None |
| 0.1 – 3.9 | Low |
| 4.0 – 6.9 | Medium |
| 7.0 – 8.9 | High |
| 9.0 – 10.0 | Critical |
Report Finding Template
Title: <concise vulnerability name + location>
Severity: <Critical/High/Med/Low> (CVSS x.x + vector)
Affected: <URL / host / component>
Summary: <what & why it matters, 1-2 lines>
Reproduction: 1. step 2. step 3. observed result
Impact: <business consequence if exploited>
Remediation: <concrete fix + defense in depth>
References: <CWE / OWASP / CVE>
Legal / Authorization Checklist
- Signed authorization letter from an owner/authority.
- Written scope: in-scope and out-of-scope assets.
- Rules of engagement: techniques, test window, rate limits.
- Emergency contact and stop procedure agreed.
- Data-handling and confidentiality terms in place.
- For bounties: read and follow the program policy exactly.
- Never touch out-of-scope systems — ask first, in writing.
Legal Practice Platforms
| Platform | Best for |
| TryHackMe | Guided beginner-to-intermediate rooms |
| Hack The Box | Realistic boxes & pro labs |
| OWASP Juice Shop | Deliberately vulnerable web app |
| VulnHub | Downloadable vulnerable VMs |
| PortSwigger Web Security Academy | Free web vuln labs (XSS, SQLi, etc.) |
| picoCTF | Beginner-friendly CTF challenges |