Preview · fully operational 26.08.2026. Everything here is browsable now.
PTES · OWASP · ATT&CK

Pentest
Methodology

A reusable engagement framework mapping PTES, OWASP, and MITRE ATT&CK into a phase-by-phase checklist — so nothing gets skipped under pressure.

COMING SOONframework being documented for release
The framework

Seven phases. Nothing improvised.

Pressure makes people skip steps. A checklist doesn't. Each phase below is a preview — full tooling notes and per-check guidance ship with the release.

PTESOWASP WSTGOWASP Top 10MITRE ATT&CK
01Pre-engagementPTES · Scoping
  • Written authorization and scope boundaries confirmed
  • Rules of engagement, timing, and emergency contacts agreed
  • Success criteria and out-of-scope assets recorded
02ReconnaissancePTES · ATT&CK TA0043
  • Passive OSINT: domains, subdomains, exposed assets
  • Active discovery: port and service enumeration
  • Attack surface mapped and prioritized
03Threat modelingOWASP
  • Entry points and trust boundaries identified
  • Likely abuse cases ranked by impact
  • Test plan derived from the model, not from habit
04Vuln analysisOWASP WSTG
  • Web checks across the WSTG categories
  • Manual verification of every automated hit
  • False positives cleared before exploitation
05ExploitationATT&CK TA0001/0002
  • Confirm impact with the least-destructive proof possible
  • Capture reproducible evidence at each step
  • Stay inside scope and rules of engagement
06Post-exploitationATT&CK TA0008
  • Assess real business impact, not theoretical reach
  • Document access gained and data exposed
  • Clean up artifacts, restore state
07ReportingPTES · Deliverable
  • Findings written to be reproduced, not admired
  • Severity, impact, and remediation for each
  • Executive summary that a non-engineer can act on