← All cheat sheets

PTES-METHODOLOGY

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

The Penetration Testing Execution Standard (PTES) is a community framework that
defines what a penetration test should cover, from first client contact to the
final report. It is organised into SEVEN phases. This sheet summarises the
durable structure of each phase and its PTES Technical Guidelines activities.
It is a methodology map, not a tool list - pick current tooling yourself and
always work within a signed authorization. Practice it in the methodology quiz
at /quiz/?topic=pentest-methodology.

THE SEVEN PTES PHASES#

  1. Pre-engagement Interactions   scope, goals, rules of engagement
  2. Intelligence Gathering        OSINT and footprinting of the target
  3. Threat Modeling               model assets, processes and threat agents
  4. Vulnerability Analysis        find and validate weaknesses
  5. Exploitation                  gain access by exploiting confirmed issues
  6. Post Exploitation             value of the compromise; pivot; persistence
  7. Reporting                     communicate findings, risk and remediation

  Flow: 1 -> 2 -> 3 -> 4 -> 5 -> 6 -> 7, iterating between phases as new
  information is discovered. Reporting is prepared throughout, not just at end.

1. PRE-ENGAGEMENT INTERACTIONS#

  Goal: agree WHAT will be tested, HOW, and under what constraints - before
  any testing starts. No testing happens in this phase.

  - Scoping            assets, IP ranges, apps, physical sites, people
  - Specify start/end  test window and timezone; avoid open-ended scope
  - Scope creep        define a change process; extra scope = new agreement
  - Goals              compliance-driven vs. objective/threat-driven testing
  - Rules of Engagement (RoE)  allowed techniques, DoS yes/no, social eng y/n
  - Authorization      signed permission from someone with authority to grant
  - Questionnaires     pre-engagement questions to size and plan the work
  - Communication      status cadence, incident/deconfliction channel
  - Emergency contacts both sides; what triggers an immediate stop
  - Handling evidence  storage, encryption, retention, destruction

2. INTELLIGENCE GATHERING#

  Goal: learn as much as possible about the target. PTES defines three levels
  of effort.

  Levels:
    Level 1   mostly automated; compliance-driven minimum
    Level 2   Level 1 + manual analysis and business context
    Level 3   advanced; adds heavy manual effort (state-sponsored class)

  Activity areas (Technical Guidelines):
  - OSINT - Corporate     locations, org chart, business partners, products,
                          job postings, financial and legal data
  - OSINT - Individuals   social-network profiles, email addresses, usernames,
                          personal domains, public activity
  - Internet Footprint    external hosts, domains, DNS, email and name servers
  - Covert Gathering      on-location recon; physical security observation
  - External Footprinting enumerate the Internet-facing attack surface
  - Internal Footprinting from an internal viewpoint: discovery, enumeration

3. THREAT MODELING#

  Goal: turn intelligence into a realistic picture of who would attack and how.

  - Business Asset Analysis      what is valuable (data, systems, processes)
  - Business Process Analysis    how the organisation actually operates
  - Threat Agent / Community      who the relevant attackers are
  - Threat Capability Analysis   what tools and access those agents have
  - Motivation modeling          why they would attack (money, data, disruption)
  - Map agents -> assets         prioritise likely attack paths

4. VULNERABILITY ANALYSIS#

  Goal: discover and CONFIRM weaknesses before attempting exploitation.

  - Vulnerability Testing   active vs. passive; automated vs. manual; across
                            network, web app, wireless, physical, social layers
  - Vulnerability Validation correlate scanner output; remove false positives;
                            confirm each candidate is real and reachable
  - Attack Avenues          build the list of confirmed, exploitable paths
  - Research                public advisories, exploit availability, versions

5. EXPLOITATION#

  Goal: establish access by exploiting confirmed vulnerabilities, with the
  least noise and risk needed to prove impact.

  Note: Pillaging and Persistence appear here AND in Post Exploitation. In the
  PTES Technical Guidelines they are listed under Exploitation; in practice the
  bulk of looting and establishing persistence happens once access is held.

  - Precision strike        targeted exploitation of a known-good vector
  - Customized Exploitation tailor or develop an exploit for the target
  - Countermeasure evasion  work around AV/IDS/IPS and defences
  - Attacking the User      client-side and social vectors
  - VPN detection           identify remote-access entry points
  - Route detection         map network routes, including static routes
  - Pillaging               harvest useful data from a foothold
  - Business impact attacks  demonstrate impact to the business, safely
  - Further penetration     expand into the wider infrastructure
  - Persistence             maintain access as agreed in the RoE

6. POST EXPLOITATION#

  Goal: determine the VALUE of the compromised machine and keep control, all
  within rules of engagement.

  - RoE for post-ex       protect the system; no unnecessary damage
  - Infrastructure analysis  mapping, pivoting, trust relationships
  - High-value targets     identify the data/systems that matter
  - Pillaging / looting    credentials, config, sensitive data
  - Windows post-exploitation  local enumeration and privilege review
  - Obtaining password hashes  from the compromised host (as scoped)
  - Data exfiltration test  prove the path without removing real PII
  - Persistence            agreed footholds for continued testing
  - Cleanup                remove tools, accounts and changes afterwards

7. REPORTING#

  Goal: communicate clearly to BOTH business and technical audiences.

  Executive-Level Reporting (for leadership):
    - Background and objectives
    - Overall security posture
    - Risk ranking / profile
    - General findings (non-technical)
    - Recommendation summary and strategic roadmap

  Technical Reporting (for technical staff):
    - Introduction and methodology
    - Intelligence gathering results
    - Vulnerability assessment detail
    - Exploitation / verification with evidence
    - Post-exploitation results
    - Risk and exposure per finding
    - Conclusion

  Quantifying the risk   assign a severity so remediation can be prioritised
                         (e.g. CVSS v3.1, or the OWASP Risk Rating Methodology)
  Deliverable            the final, securely delivered report; offer a retest

HOW PTES RELATES TO OTHER MODELS#

  - NIST SP 800-115    4 pentest phases: Planning, Discovery, Attack, Reporting
  - Cyber Kill Chain   7 attacker stages: Recon, Weaponization, Delivery,
                       Exploitation, Installation, C2, Actions on Objectives
  - MITRE ATT&CK       tactics/techniques catalogue of real attacker behaviour
  PTES is the engagement process; the others describe phases, attacker steps
  or technique taxonomies that plug into it.

SEE ALSO#

  - Pentest reporting & templates   /cheatsheets/pentest-reporting
  - Red-team comms templates        /cheatsheets/redteam-comms
  - OSCP methodology                /cheatsheets/oscp-methodology
  - Methodology quiz                /quiz/?topic=pentest-methodology