Penetration Testing Preparation
18 items · Technical · Hard difficulty · 2 hours
Prepare everything you need for a safe, authorized penetration test.
-
Obtain written authorization and scope approval
Get a signed letter or email naming client, testers, targets, dates, and approval limits.
-
Confirm and document test scope
List in-scope and out-of-scope hosts, IP ranges, apps, and excluded systems.
-
Draft rules of engagement (RoE) document
Define allowed techniques, time windows, blackout zones, and escalation triggers.
-
Complete legal and compliance review
Verify applicable laws, contractual limits, and third-party or regulatory constraints.
-
Finalize data handling agreement and NDA
Specify evidence storage, encryption, access control, and retention timelines.
-
Compile asset inventory and access list
Collect IPs, hostnames, URLs, service ports, and authorized credentials or auth methods.
-
Review network diagrams and architecture
Verify diagrams against inventory; note segmentation, DMZs, and critical systems.
-
Obtain emergency contacts and escalation plan
Collect 24/7 contacts, incident response leads, and preferred escalation methods.
-
Schedule testing windows and maintenance windows
Agree on exact dates/times, including blackout periods and backup schedules.
-
Set up testing tools and environment
Prepare isolated lab or jump hosts, update tools, and verify license keys.
-
Configure Burp Suite for proxying and logging
Install extensions, set intercept rules, and enable detailed logging to files.
-
Run Nmap baseline scans and fingerprinting
Perform safe timing scans, save XML output, and document service versions.
-
Prepare Metasploit workspace and exploit modules
Update modules, initialize the database, and pre-load identified targets.
-
Conduct OSINT reconnaissance and target validation
Enumerate domains, subdomains, public assets, and exposed employee info.
-
Create report template and evidence capture plan
Prepare sections, severity ratings, screenshots, logs, and replayable steps.
-
Plan backups, snapshots, and rollback strategy
Arrange VM snapshots, DB exports, and clear rollback steps before intrusive tests.
-
Confirm cleanup, data retention, and destructive test constraints
Agree what artifacts will be removed, retained, or wiped after testing.
-
Perform final pre-test review and obtain stakeholder sign-off
Ensure all docs signed, contacts confirmed, tools ready, and stakeholders informed.
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.