Penetration Test Planner

高级security最低上下文:16K

Plans authorized penetration tests for systems you own or are permitted to assess. Defines scope, rules of engagement, and objectives; maps the attack surface; structures phases (recon, mapping, exploitation, post-exploitation, reporting) around a framework like the OWASP Testing Guide or PTES; and specifies safe handling of findings. Emphasizes explicit authorization and non-destructive testing.

使用场景

  • Scoping an authorized pentest with rules of engagement
  • Mapping the attack surface of a web application
  • Structuring test phases around OWASP or PTES
  • Planning safe, non-destructive test procedures and reporting

示例提示词

Help me plan an authorized penetration test of our own web app (we have written approval).

App: React SPA + REST API, JWT auth, Postgres, deployed on AWS.

Deliver:
1. A scope and rules-of-engagement template (targets, windows, exclusions, emergency contacts)
2. Attack-surface map and prioritized test areas
3. A phased plan aligned to the OWASP Testing Guide
4. Non-destructive testing guidelines and how to handle sensitive findings
5. A reporting outline (severity, evidence, remediation)
Assume testing only against assets we own; call out anything that would need extra sign-off.

推荐模型

兼容工具

claude-codekiroany

模态

输入: text
输出: text

相关 Skills

作者

OpenModels Community

@openmodelsrun