The framework
Seven phases. Nothing improvised.
Pressure makes people skip steps. A checklist doesn't. Each phase below is a preview — full tooling notes and per-check guidance ship with the release.
PTESOWASP WSTGOWASP Top 10MITRE ATT&CK
01Pre-engagementPTES · Scoping
- Written authorization and scope boundaries confirmed
- Rules of engagement, timing, and emergency contacts agreed
- Success criteria and out-of-scope assets recorded
02ReconnaissancePTES · ATT&CK TA0043
- Passive OSINT: domains, subdomains, exposed assets
- Active discovery: port and service enumeration
- Attack surface mapped and prioritized
03Threat modelingOWASP
- Entry points and trust boundaries identified
- Likely abuse cases ranked by impact
- Test plan derived from the model, not from habit
04Vuln analysisOWASP WSTG
- Web checks across the WSTG categories
- Manual verification of every automated hit
- False positives cleared before exploitation
05ExploitationATT&CK TA0001/0002
- Confirm impact with the least-destructive proof possible
- Capture reproducible evidence at each step
- Stay inside scope and rules of engagement
06Post-exploitationATT&CK TA0008
- Assess real business impact, not theoretical reach
- Document access gained and data exposed
- Clean up artifacts, restore state
07ReportingPTES · Deliverable
- Findings written to be reproduced, not admired
- Severity, impact, and remediation for each
- Executive summary that a non-engineer can act on