Penetration Testing Methodology: From Scope to Retest

Penetration Testing Methodology must only be conducted within an approved Scope and Rules of Engagement. The process includes information gathering, controlled validation, Evidence, risk assessment, remediation, and Retest.
Professional penetration testing is an authorized and defined process, not a collection of commands. Scope, Rules of Engagement, evidence, risk assessment, remediation, and Retest are an integral part of the work. This article focuses on Penetration Testing Methodology and is intended for PT students, clients, and Junior Pentesters. The goal is to provide a working method that can be applied in practice, during professional interviews, and in a work environment, without settling for a dictionary definition.
The main challenge is that data is almost always partial. In-scope assets, out-of-scope, and time window can indicate a direction, but their meaning depends on the time, asset, user, and expected activity. Therefore, we will build the test around an investigative question, required evidence, and clear termination criteria.
The practical scenario in the article is: mapping a lab project to all stages of the methodology. All examples are lab data or process descriptions. When it comes to Penetration Testing, Web, or Cloud, one must only work with explicit authorization, a defined Scope, and the ability to stop the test.




