PTES-METHODOLOGY
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
The Penetration Testing Execution Standard (PTES) is a community framework that defines what a penetration test should cover, from first client contact to the final report. It is organised into SEVEN phases. This sheet summarises the durable structure of each phase and its PTES Technical Guidelines activities. It is a methodology map, not a tool list - pick current tooling yourself and always work within a signed authorization. Practice it in the methodology quiz at /quiz/?topic=pentest-methodology.
THE SEVEN PTES PHASES#
1. Pre-engagement Interactions scope, goals, rules of engagement 2. Intelligence Gathering OSINT and footprinting of the target 3. Threat Modeling model assets, processes and threat agents 4. Vulnerability Analysis find and validate weaknesses 5. Exploitation gain access by exploiting confirmed issues 6. Post Exploitation value of the compromise; pivot; persistence 7. Reporting communicate findings, risk and remediation Flow: 1 -> 2 -> 3 -> 4 -> 5 -> 6 -> 7, iterating between phases as new information is discovered. Reporting is prepared throughout, not just at end.
1. PRE-ENGAGEMENT INTERACTIONS#
Goal: agree WHAT will be tested, HOW, and under what constraints - before any testing starts. No testing happens in this phase. - Scoping assets, IP ranges, apps, physical sites, people - Specify start/end test window and timezone; avoid open-ended scope - Scope creep define a change process; extra scope = new agreement - Goals compliance-driven vs. objective/threat-driven testing - Rules of Engagement (RoE) allowed techniques, DoS yes/no, social eng y/n - Authorization signed permission from someone with authority to grant - Questionnaires pre-engagement questions to size and plan the work - Communication status cadence, incident/deconfliction channel - Emergency contacts both sides; what triggers an immediate stop - Handling evidence storage, encryption, retention, destruction
2. INTELLIGENCE GATHERING#
Goal: learn as much as possible about the target. PTES defines three levels
of effort.
Levels:
Level 1 mostly automated; compliance-driven minimum
Level 2 Level 1 + manual analysis and business context
Level 3 advanced; adds heavy manual effort (state-sponsored class)
Activity areas (Technical Guidelines):
- OSINT - Corporate locations, org chart, business partners, products,
job postings, financial and legal data
- OSINT - Individuals social-network profiles, email addresses, usernames,
personal domains, public activity
- Internet Footprint external hosts, domains, DNS, email and name servers
- Covert Gathering on-location recon; physical security observation
- External Footprinting enumerate the Internet-facing attack surface
- Internal Footprinting from an internal viewpoint: discovery, enumeration
3. THREAT MODELING#
Goal: turn intelligence into a realistic picture of who would attack and how. - Business Asset Analysis what is valuable (data, systems, processes) - Business Process Analysis how the organisation actually operates - Threat Agent / Community who the relevant attackers are - Threat Capability Analysis what tools and access those agents have - Motivation modeling why they would attack (money, data, disruption) - Map agents -> assets prioritise likely attack paths
4. VULNERABILITY ANALYSIS#
Goal: discover and CONFIRM weaknesses before attempting exploitation.
- Vulnerability Testing active vs. passive; automated vs. manual; across
network, web app, wireless, physical, social layers
- Vulnerability Validation correlate scanner output; remove false positives;
confirm each candidate is real and reachable
- Attack Avenues build the list of confirmed, exploitable paths
- Research public advisories, exploit availability, versions
5. EXPLOITATION#
Goal: establish access by exploiting confirmed vulnerabilities, with the least noise and risk needed to prove impact. Note: Pillaging and Persistence appear here AND in Post Exploitation. In the PTES Technical Guidelines they are listed under Exploitation; in practice the bulk of looting and establishing persistence happens once access is held. - Precision strike targeted exploitation of a known-good vector - Customized Exploitation tailor or develop an exploit for the target - Countermeasure evasion work around AV/IDS/IPS and defences - Attacking the User client-side and social vectors - VPN detection identify remote-access entry points - Route detection map network routes, including static routes - Pillaging harvest useful data from a foothold - Business impact attacks demonstrate impact to the business, safely - Further penetration expand into the wider infrastructure - Persistence maintain access as agreed in the RoE
6. POST EXPLOITATION#
Goal: determine the VALUE of the compromised machine and keep control, all within rules of engagement. - RoE for post-ex protect the system; no unnecessary damage - Infrastructure analysis mapping, pivoting, trust relationships - High-value targets identify the data/systems that matter - Pillaging / looting credentials, config, sensitive data - Windows post-exploitation local enumeration and privilege review - Obtaining password hashes from the compromised host (as scoped) - Data exfiltration test prove the path without removing real PII - Persistence agreed footholds for continued testing - Cleanup remove tools, accounts and changes afterwards
7. REPORTING#
Goal: communicate clearly to BOTH business and technical audiences.
Executive-Level Reporting (for leadership):
- Background and objectives
- Overall security posture
- Risk ranking / profile
- General findings (non-technical)
- Recommendation summary and strategic roadmap
Technical Reporting (for technical staff):
- Introduction and methodology
- Intelligence gathering results
- Vulnerability assessment detail
- Exploitation / verification with evidence
- Post-exploitation results
- Risk and exposure per finding
- Conclusion
Quantifying the risk assign a severity so remediation can be prioritised
(e.g. CVSS v3.1, or the OWASP Risk Rating Methodology)
Deliverable the final, securely delivered report; offer a retest
HOW PTES RELATES TO OTHER MODELS#
- NIST SP 800-115 4 pentest phases: Planning, Discovery, Attack, Reporting
- Cyber Kill Chain 7 attacker stages: Recon, Weaponization, Delivery,
Exploitation, Installation, C2, Actions on Objectives
- MITRE ATT&CK tactics/techniques catalogue of real attacker behaviour
PTES is the engagement process; the others describe phases, attacker steps
or technique taxonomies that plug into it.
SEE ALSO#
- Pentest reporting & templates /cheatsheets/pentest-reporting - Red-team comms templates /cheatsheets/redteam-comms - OSCP methodology /cheatsheets/oscp-methodology - Methodology quiz /quiz/?topic=pentest-methodology