Pentest methodology: how we test for penetration

Stages of penetration testing, tools, and report format.

What is a pentest?

Penetration testing is a controlled simulation of attacks to identify vulnerabilities. SAQTEK conducts pentests using OWASP, PTES, and OSSTMM.

Types of testing
Black Box

No information about the system. Simulating an external attacker.

Grey Box

Limited information: basic accounts, network diagram.

White Box

Full access to the source code and architecture. The most in‑depth analysis.

Stages of the process:

1. Planning — согласование of the scope and methods, signing of an NDA.

2. Reconnaissance — gathering information: domains, IP addresses, technologies, ports.

3. Vulnerability analysis — scanning and manual verification.

4. Exploitation — attempts to exploit vulnerabilities.

5. Post‑exploitation — assessment of the depth of access and business impact.

6. Reporting — description, evidence, CVSS, recommendations.

Each vulnerability is classified according to CVSS v3.1. Critical vulnerabilities are closed within the first 24 hours.

Report structure

Executive Summary — for management: overall assessment, risks, priorities.

Technical Report — for IT/IS: proof-of-concept, remediation instructions.

Другие статьи