Chuyển đến nội dung chính

Lesson 28: Pentest Report — Technical and Executive

Professional pentest report template, executive summary, technical findings, evidence presentation, remediation tracking.

🔒 DevSecOps — Lesson 28 Lesson 28: Pentest Report — Technical and Executive

Performance Testing & Pentest: Enterprise Standard Process 2026

Part 6: Report & Professional Process

xdev.asia

1. Pentest Report — Purpose

Report Audiences:

Executive (C-Level, Board):
  ├── Overall security posture
  ├── Business risk summary
  ├── Investment priorities
  └── Compliance status

Technical (Dev, DevOps, Security):
  ├── Detailed vulnerability descriptions
  ├── Proof of concept steps
  ├── Technical remediation guidance
  └── Code-level fixes

Compliance (Auditors):
  ├── Methodology used
  ├── Scope and coverage
  ├── Findings mapped to standards
  └── Remediation evidence

Report = Deliverable:
  Quality report = professional credibility
  Poor report = wasted pentest effort

2. Pentest Report Structure

Professional Pentest Report:

1. Cover Page
   ├── Document title & classification
   ├── Client name & project name
   ├── Report version & date
   ├── Author & reviewer
   └── Distribution list

2. Table of Contents

3. Executive Summary (1-2 pages)
   ├── Engagement overview
   ├── Key findings (risk-based)
   ├── Overall risk rating
   ├── Critical recommendations
   └── Security posture trend

4. Methodology
   ├── Type (Black/Gray/White box)
   ├── Standards followed (PTES, OWASP)
   ├── Tools used
   ├── Scope & limitations
   └── Testing timeline

5. Findings Summary
   ├── Risk distribution chart
   ├── Findings table (sorted by severity)
   └── Compliance mapping

6. Detailed Findings (per finding)
   ├── Title & severity
   ├── CVSS v4.0 score & vector
   ├── Description
   ├── Affected component
   ├── Steps to reproduce
   ├── Evidence (screenshots, requests/responses)
   ├── Business impact
   ├── Remediation
   └── References (CWE, OWASP, CVE)

7. Remediation Summary
   ├── Priority matrix
   ├── Estimated effort
   └── Recommended timeline

8. Appendix
   ├── Full CVSS calculations
   ├── Tool output logs
   ├── Network diagrams
   └── Glossary

3. Executive Summary Template

# Penetration Test Report
## Example Corp — Annual Security Assessment 2026

### Executive Summary

**Engagement Period:** April 1-14, 2026
**Type:** Gray Box (Web Application + API + Cloud)
**Tested By:** xDev Security Team
**Overall Risk Rating:** HIGH

#### Security Posture Overview

Total findings: **18**

| Severity | Count | % |
|----------|-------|---|
| Critical | 2     | 11% |
| High     | 5     | 28% |
| Medium   | 7     | 39% |
| Low      | 4     | 22% |

#### Critical Risks Identified

1. **SQL Injection in Payment API** — An attacker can extract
   the entire customer database including payment tokens.
   Immediate remediation required.

2. **SSRF to AWS Metadata** — Server-Side Request Forgery
   allows unauthorized access to AWS credentials, potentially
   compromising the entire cloud infrastructure.

#### Positive Observations
- MFA enforced for all admin accounts
- TLS 1.3 properly configured
- Security headers well-implemented
- Incident response plan documented

#### Key Recommendations
1. Fix critical findings within 48 hours
2. Implement Web Application Firewall (WAF)
3. Establish quarterly vulnerability scanning
4. Deploy SIEM for security monitoring

#### Year-over-Year Comparison

| Metric          | 2025    | 2026    | Trend |
|-----------------|---------|---------|-------|
| Critical        | 3       | 2       | ↓ ✅  |
| High            | 8       | 5       | ↓ ✅  |
| Medium          | 12      | 7       | ↓ ✅  |
| Total           | 28      | 18      | ↓ ✅  |
| Avg CVSS        | 7.2     | 6.5     | ↓ ✅  |

Overall security posture has **improved** compared to 2025.

4. Detailed Finding Template

### Finding #1: SQL Injection in Payment Search API

| Attribute    | Value                                           |
|--------------|-------------------------------------------------|
| **ID**       | XDEV-2026-001                                   |
| **Severity** | Critical                                        |
| **CVSS v4.0**| 9.3 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N) |
| **CWE**      | CWE-89 (SQL Injection)                          |
| **OWASP**    | A03:2021 — Injection                            |
| **Status**   | Open                                            |

**Affected Component:**
`POST /api/v1/payments/search`

**Description:**
The payment search endpoint constructs SQL queries using
unsanitized user input in the `query` parameter. An attacker
can inject arbitrary SQL commands to extract, modify, or
delete data from the database.

**Steps to Reproduce:**

1. Send the following request:
___CODEBLOCK_0___

2. Response contains user credentials:
___CODEBLOCK_1___

3. Further exploitation — extract all tables:
___CODEBLOCK_2___

**Evidence:**
[Screenshot: Response showing extracted user data]
[Screenshot: SQLMap output confirming vulnerability]

**Business Impact:**
- Complete database compromise (50,000+ customer records)
- Payment token exposure → financial loss
- Regulatory violation (PCI DSS Req 6.2.4)
- Reputational damage

**Remediation:**
1. Use parameterized queries (prepared statements):
___CODEBLOCK_3___

2. Implement input validation (whitelist allowed characters)
3. Apply least-privilege database user
4. Deploy WAF with SQL injection rules
5. Add query parameterization to code review checklist

**References:**
- CWE-89: https://cwe.mitre.org/data/definitions/89.html
- OWASP SQL Injection: https://owasp.org/www-community/attacks/SQL_Injection
- PCI DSS v4.0 Requirement 6.2.4

5. Risk Matrix & Prioritization

Risk Matrix:

              │ Low Impact  │ Med Impact  │ High Impact
──────────────┼─────────────┼─────────────┼────────────
High          │ Medium      │ High        │ Critical
Likelihood    │ (schedule)  │ (this sprint)│ (immediate)
──────────────┼─────────────┼─────────────┼────────────
Medium        │ Low         │ Medium      │ High
Likelihood    │ (backlog)   │ (schedule)  │ (this sprint)
──────────────┼─────────────┼─────────────┼────────────
Low           │ Info        │ Low         │ Medium
Likelihood    │ (accept)    │ (backlog)   │ (schedule)

Remediation Prioritization:

Finding ID │ Title                    │ CVSS │ Priority │ Effort │ Deadline
───────────┼──────────────────────────┼──────┼──────────┼────────┼──────────
XDEV-001   │ SQL Injection in Payments│ 9.3  │ Critical │ Low    │ 48 hours
XDEV-002   │ SSRF → AWS Metadata     │ 9.3  │ Critical │ Medium │ 48 hours
XDEV-003   │ IDOR in User Documents  │ 7.5  │ High     │ Low    │ 1 week
XDEV-004   │ Missing Rate Limiting   │ 6.5  │ High     │ Medium │ 1 week
XDEV-005   │ JWT Weak Secret         │ 7.3  │ High     │ Low    │ 1 week
XDEV-006   │ Verbose Error Messages  │ 4.3  │ Medium   │ Low    │ 2 weeks
XDEV-007   │ Missing Security Headers│ 3.5  │ Low      │ Low    │ 1 month

6. Reporting Tools

Professional Pentest Reporting Tools:

Pwndoc:
  ├── Open-source pentest reporting tool
  ├── Collaborative editing
  ├── Template system (customizable)
  ├── CVSS calculator built-in
  ├── Export: DOCX, PDF
  └── Self-hosted (Docker)

PlexTrac:
  ├── Commercial platform
  ├── Findings management
  ├── Remediation tracking
  ├── Client portal
  └── Integrations (Jira, ServiceNow)

Ghostwriter (SpecterOps):
  ├── Open-source
  ├── Red team report management
  ├── Project & finding tracking
  ├── DOCX export with templates
  └── Activity logging

DIY Options:
  ├── Markdown + Pandoc → PDF
  ├── LaTeX templates
  └── Custom scripts + Jinja2 templates
# Pwndoc — Self-hosted setup
git clone https://github.com/pwndoc/pwndoc.git
cd pwndoc

# Start with Docker Compose
docker compose up -d

# Access: https://localhost:8443
# Default: admin / admin (change immediately!)

# Features:
# - Create audit projects
# - Add findings from template library
# - Collaborative editing
# - Auto-generate DOCX reports
# - Custom report templates

7. Report Quality Checklist

Before Submitting Report:

Content:
  □ Executive summary is non-technical
  □ Each finding has clear reproduction steps
  □ Evidence (screenshots/requests) included
  □ CVSS scores calculated correctly
  □ Business impact clearly stated
  □ Remediation is specific and actionable
  □ References included (CWE, OWASP, CVE)

Quality:
  □ Peer reviewed by another pentester
  □ No typos or grammatical errors
  □ Consistent formatting throughout
  □ Page numbers and ToC correct
  □ Classification marking on every page
  □ All findings sorted by severity

Security:
  □ No actual credentials in report
  □ Sensitive data redacted in screenshots
  □ Report encrypted before transmission
  □ Delivered via secure channel
  □ PII masked (show pattern, not actual data)

Professional:
  □ Company branding applied
  □ Positive observations included
  □ Recommendations are prioritized
  □ Timeline for remediation suggested
  □ Offer for retest/verification

8. Summary

  • Structure: Cover → Executive Summary → Methodology → Findings → Remediation
  • Executive Summary: 1-2 pages, business language, risk-focused
  • Finding Detail: Title, CVSS, PoC steps, evidence, impact, remediation
  • Prioritization: Risk matrix combining severity and business impact
  • Tools: Pwndoc, PlexTrac, Ghostwriter for professional reports
  • Quality: Always peer-review before submission

Bài tiếp theo sẽ trình bày Automated Reporting và Remediation Tracking.