1. PTES Overview
PTES (Penetration Testing Execution Standard) is an open standard, widely used in the security industry, defining 7 stages for a professional pentest.
PTES 7 Phases:
┌──────────────────────────────────────────────────┐
│ Phase 1: Pre-engagement Interactions │
│ ├── Scope definition │
│ ├── Rules of Engagement │
│ └── Authorization & NDA │
├──────────────────────────────────────────────────┤
│ Phase 2: Intelligence Gathering │
│ ├── OSINT (Open Source Intelligence) │
│ ├── Footprinting & Fingerprinting │
│ └── Social engineering reconnaissance │
├──────────────────────────────────────────────────┤
│ Phase 3: Threat Modeling │
│ ├── Asset identification │
│ ├── Threat actor profiling │
│ └── Attack tree construction │
├──────────────────────────────────────────────────┤
│ Phase 4: Vulnerability Analysis │
│ ├── Automated scanning │
│ ├── Manual testing │
│ └── False positive validation │
├──────────────────────────────────────────────────┤
│ Phase 5: Exploitation │
│ ├── Vulnerability exploitation │
│ ├── Evasion techniques │
│ └── Proof of Concept development │
├──────────────────────────────────────────────────┤
│ Phase 6: Post-Exploitation │
│ ├── Privilege escalation │
│ ├── Lateral movement │
│ ├── Data exfiltration (simulated) │
│ └── Persistence analysis │
├──────────────────────────────────────────────────┤
│ Phase 7: Reporting │
│ ├── Executive Summary │
│ ├── Technical Report │
│ └── Remediation recommendations │
└──────────────────────────────────────────────────┘
2. Phase 1: Pre-engagement Interactions
Pre-engagement Checklist:
1. Scoping Questionnaire:
□ Total number of IPs / hosts
□ Number of web applications
□ Authenticated / unauthenticated testing?
□ Number of user roles to test
□ API endpoints count
□ Cloud infrastructure scope
2. Authorization:
□ Get-Out-of-Jail letter
□ NDA signed by both parties
□ Emergency contacts exchanged
□ Testing schedule agreed
□ IP whitelist provided
3. Communication Plan:
□ Encrypted channel setup (Signal, secure email)
□ Status reporting frequency
□ Critical finding notification SLA
□ Point of contact for each side
# Pentest Authorization Letter Template
Date: 2026-04-01
Project: Annual Penetration Test - Example Corp
## Authorization
I, [CTO Name], hereby authorize [Pentest Company] to
perform penetration testing on:
### In-Scope Systems:
- 10.0.0.0/24 (Production Network)
- api.example.com (REST API)
- app.example.com (Web Application)
- mobile.example.com (Mobile Backend)
- AWS Account: 123456789012
### Testing Period:
From: 2026-04-01 08:00 UTC+7
To: 2026-04-14 18:00 UTC+7
### Restrictions:
- No Denial-of-Service attacks
- No physical access testing
- No social engineering
- Testing limited to business hours
### Emergency Contact:
Phone: +84-xxx-xxx-xxxx
Email: [email protected]
Signature: _______________
3. Phase 2: Intelligence Gathering
# --- Passive Reconnaissance ---
# Subdomain enumeration
subfinder -d example.com -all -o subdomains.txt
amass enum -passive -d example.com -o amass_subs.txt
# DNS records
dig example.com ANY +noall +answer
dig example.com MX +short
host -t txt example.com
# Certificate Transparency logs
curl -s "https://crt.sh/?q=%.example.com&output=json" \
| jq -r '.[].name_value' | sort -u
# Wayback Machine
waybackurls example.com | sort -u > wayback.txt
# Google Dorks
# site:example.com filetype:pdf
# site:example.com inurl:admin
# site:example.com ext:sql | ext:env | ext:log
# Shodan
shodan search hostname:example.com
# --- Active Reconnaissance ---
# Port scanning (Nmap)
nmap -sV -sC -O -p- -oA full_scan example.com
# Service fingerprinting
nmap -sV --version-intensity 5 -p 80,443,8080 example.com
# Web technology detection
whatweb example.com
wappalyzer example.com # browser extension
4. Phase 3: Threat Modeling
STRIDE Threat Model cho Web Application:
┌──────────────────────────────────────────┐
│ Web Application │
├──────────────────────────────────────────┤
│ Threat │ Attack Vector │
├────────────────┼─────────────────────────┤
│ Spoofing │ Session hijacking │
│ │ Credential stuffing │
├────────────────┼─────────────────────────┤
│ Tampering │ SQL Injection │
│ │ Parameter manipulation │
├────────────────┼─────────────────────────┤
│ Repudiation │ Log tampering │
│ │ Missing audit trail │
├────────────────┼─────────────────────────┤
│ Info Disclosure│ Error message leakage │
│ │ Directory listing │
├────────────────┼─────────────────────────┤
│ Denial of Svc │ Resource exhaustion │
│ │ ReDoS │
├────────────────┼─────────────────────────┤
│ Elev. Privilege│ IDOR │
│ │ Broken access control │
└────────────────┴─────────────────────────┘
Attack Tree — Account Takeover:
Root: Chiếm quyền tài khoản user
├── [OR] Brute-force login
│ ├── [AND] Enumerate valid usernames
│ └── [AND] No rate limiting
├── [OR] Password reset poisoning
│ ├── [AND] Host header injection
│ └── [AND] Predictable token
├── [OR] Session hijacking
│ ├── [AND] XSS → steal cookie
│ └── [AND] Cookie without HttpOnly
└── [OR] OAuth misconfiguration
├── [AND] Open redirect in callback
└── [AND] No state parameter
5. Phase 4: Vulnerability Analysis
# Automated scanning
# Nuclei — template-based scanner
nuclei -u https://example.com -t cves/ -t exposures/ -severity critical,high \
-o nuclei_results.txt -stats
# Nessus CLI (tenable)
nessuscli scan --policy "Advanced Scan" --target 10.0.0.0/24
# OWASP ZAP automated scan
zap-cli quick-scan -s all -r report.html https://example.com
# nikto web scanner
nikto -h https://example.com -o nikto_results.html -Format html
# Manual testing checklist
# □ Authentication bypass
# □ Authorization checks (IDOR)
# □ Input validation (SQLi, XSS, SSRF)
# □ Business logic flaws
# □ Race conditions
# □ File upload restrictions
# □ API parameter pollution
6. Phase 5-6: Exploitation & Post-Exploitation
Exploitation Workflow:
Vulnerability Found
│
▼
Verify Exploitability
│
├── Can reproduce? ──No──▶ Document as unconfirmed
│
▼ Yes
Develop PoC (Proof of Concept)
│
├── Minimal impact PoC
├── Screenshot / video evidence
└── Document exact steps
│
▼
Assess Impact → CVSS v4.0 score
│
▼
Post-Exploitation (if authorized):
├── Privilege escalation attempt
├── Lateral movement mapping
├── Data access verification
└── Persistence mechanism check
│
▼
Clean Up
├── Remove test accounts
├── Delete uploaded files
├── Restore modified configs
└── Verify clean state
7. Compare Pentest Frameworks
| Framework_ | Scope_ | Advantages | Use case_ |
|---|---|---|---|
| PTES | General pentest | Comprehensive, practical_ | Enterprise pentest |
| OSSTMM 3 | Security testing | Metrics-based (RAV score) | Compliance, audit |
| NIST SP 800-115 | Technical security | Government standard | Federal / regulated |
| OWASP Testing Guide v5 | Web application | Web-focused, detailed | Web app pentest |
| MITRE ATT&CK | Adversary TTPs | Real-world mappings | Red team exercises |
| CREST | Professional std | Certification-backed | UK/intl pentest firms |
8. Summary
- PTES: 7-phase standard — from pre-engagement to reporting
- Pre-engagement: Authorization, scope, ROE, communication plan
- Intelligence: Passive (OSINT) + Active (scanning) reconnaissance
- Threat Modeling: STRIDE, Attack Trees, asset prioritization
- Exploitation: Minimal impact PoC, evidence collection, clean up
- Frameworks: PTES, OSSTMM, NIST, OWASP TG, MITER ATT&CK
The next article will analyze in detail OWASP Top 10 (2025).