1. Pentest Report — Mục đích
Report Audiences:
Executive (C-Level, Board):
├── Overall security posture
├── Business risk summary
├── Investment priorities
└── Compliance status
Technical (Dev, DevOps, Security):
├── Detailed vulnerability descriptions
├── Proof of concept steps
├── Technical remediation guidance
└── Code-level fixes
Compliance (Auditors):
├── Methodology used
├── Scope and coverage
├── Findings mapped to standards
└── Remediation evidence
Report = Deliverable:
Quality report = professional credibility
Poor report = wasted pentest effort
2. Pentest Report Structure
Professional Pentest Report:
1. Cover Page
├── Document title & classification
├── Client name & project name
├── Report version & date
├── Author & reviewer
└── Distribution list
2. Table of Contents
3. Executive Summary (1-2 pages)
├── Engagement overview
├── Key findings (risk-based)
├── Overall risk rating
├── Critical recommendations
└── Security posture trend
4. Methodology
├── Type (Black/Gray/White box)
├── Standards followed (PTES, OWASP)
├── Tools used
├── Scope & limitations
└── Testing timeline
5. Findings Summary
├── Risk distribution chart
├── Findings table (sorted by severity)
└── Compliance mapping
6. Detailed Findings (per finding)
├── Title & severity
├── CVSS v4.0 score & vector
├── Description
├── Affected component
├── Steps to reproduce
├── Evidence (screenshots, requests/responses)
├── Business impact
├── Remediation
└── References (CWE, OWASP, CVE)
7. Remediation Summary
├── Priority matrix
├── Estimated effort
└── Recommended timeline
8. Appendix
├── Full CVSS calculations
├── Tool output logs
├── Network diagrams
└── Glossary
3. Executive Summary Template
# Penetration Test Report
## Example Corp — Annual Security Assessment 2026
### Executive Summary
**Engagement Period:** April 1-14, 2026
**Type:** Gray Box (Web Application + API + Cloud)
**Tested By:** xDev Security Team
**Overall Risk Rating:** HIGH
#### Security Posture Overview
Total findings: **18**
| Severity | Count | % |
|----------|-------|---|
| Critical | 2 | 11% |
| High | 5 | 28% |
| Medium | 7 | 39% |
| Low | 4 | 22% |
#### Critical Risks Identified
1. **SQL Injection in Payment API** — An attacker can extract
the entire customer database including payment tokens.
Immediate remediation required.
2. **SSRF to AWS Metadata** — Server-Side Request Forgery
allows unauthorized access to AWS credentials, potentially
compromising the entire cloud infrastructure.
#### Positive Observations
- MFA enforced for all admin accounts
- TLS 1.3 properly configured
- Security headers well-implemented
- Incident response plan documented
#### Key Recommendations
1. Fix critical findings within 48 hours
2. Implement Web Application Firewall (WAF)
3. Establish quarterly vulnerability scanning
4. Deploy SIEM for security monitoring
#### Year-over-Year Comparison
| Metric | 2025 | 2026 | Trend |
|-----------------|---------|---------|-------|
| Critical | 3 | 2 | ↓ ✅ |
| High | 8 | 5 | ↓ ✅ |
| Medium | 12 | 7 | ↓ ✅ |
| Total | 28 | 18 | ↓ ✅ |
| Avg CVSS | 7.2 | 6.5 | ↓ ✅ |
Overall security posture has **improved** compared to 2025.
4. Detailed Finding Template
### Finding #1: SQL Injection in Payment Search API
| Attribute | Value |
|--------------|-------------------------------------------------|
| **ID** | XDEV-2026-001 |
| **Severity** | Critical |
| **CVSS v4.0**| 9.3 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N) |
| **CWE** | CWE-89 (SQL Injection) |
| **OWASP** | A03:2021 — Injection |
| **Status** | Open |
**Affected Component:**
`POST /api/v1/payments/search`
**Description:**
The payment search endpoint constructs SQL queries using
unsanitized user input in the `query` parameter. An attacker
can inject arbitrary SQL commands to extract, modify, or
delete data from the database.
**Steps to Reproduce:**
1. Send the following request:
```http
POST /api/v1/payments/search HTTP/2
Host: api.example.com
Content-Type: application/json
{"query": "test' UNION SELECT username,password_hash,credit_token,null,null FROM users--"}
```
2. Response contains user credentials:
```json
{
"results": [
{"id": "admin", "amount": "$2b$12$hash...", "description": "ct_live_xxx..."},
...
]
}
```
3. Further exploitation — extract all tables:
```
test' UNION SELECT table_name,null,null,null,null FROM information_schema.tables--
```
**Evidence:**
[Screenshot: Response showing extracted user data]
[Screenshot: SQLMap output confirming vulnerability]
**Business Impact:**
- Complete database compromise (50,000+ customer records)
- Payment token exposure → financial loss
- Regulatory violation (PCI DSS Req 6.2.4)
- Reputational damage
**Remediation:**
1. Use parameterized queries (prepared statements):
```python
# Before (vulnerable):
query = f"SELECT * FROM payments WHERE description LIKE '%{user_input}%'"
# After (secure):
query = "SELECT * FROM payments WHERE description LIKE %s"
cursor.execute(query, (f"%{user_input}%",))
```
2. Implement input validation (whitelist allowed characters)
3. Apply least-privilege database user
4. Deploy WAF with SQL injection rules
5. Add query parameterization to code review checklist
**References:**
- CWE-89: https://cwe.mitre.org/data/definitions/89.html
- OWASP SQL Injection: https://owasp.org/www-community/attacks/SQL_Injection
- PCI DSS v4.0 Requirement 6.2.4
5. Risk Matrix & Prioritization
Risk Matrix:
│ Low Impact │ Med Impact │ High Impact
──────────────┼─────────────┼─────────────┼────────────
High │ Medium │ High │ Critical
Likelihood │ (schedule) │ (this sprint)│ (immediate)
──────────────┼─────────────┼─────────────┼────────────
Medium │ Low │ Medium │ High
Likelihood │ (backlog) │ (schedule) │ (this sprint)
──────────────┼─────────────┼─────────────┼────────────
Low │ Info │ Low │ Medium
Likelihood │ (accept) │ (backlog) │ (schedule)
Remediation Prioritization:
Finding ID │ Title │ CVSS │ Priority │ Effort │ Deadline
───────────┼──────────────────────────┼──────┼──────────┼────────┼──────────
XDEV-001 │ SQL Injection in Payments│ 9.3 │ Critical │ Low │ 48 hours
XDEV-002 │ SSRF → AWS Metadata │ 9.3 │ Critical │ Medium │ 48 hours
XDEV-003 │ IDOR in User Documents │ 7.5 │ High │ Low │ 1 week
XDEV-004 │ Missing Rate Limiting │ 6.5 │ High │ Medium │ 1 week
XDEV-005 │ JWT Weak Secret │ 7.3 │ High │ Low │ 1 week
XDEV-006 │ Verbose Error Messages │ 4.3 │ Medium │ Low │ 2 weeks
XDEV-007 │ Missing Security Headers│ 3.5 │ Low │ Low │ 1 month
6. Reporting Tools
Professional Pentest Reporting Tools:
Pwndoc:
├── Open-source pentest reporting tool
├── Collaborative editing
├── Template system (customizable)
├── CVSS calculator built-in
├── Export: DOCX, PDF
└── Self-hosted (Docker)
PlexTrac:
├── Commercial platform
├── Findings management
├── Remediation tracking
├── Client portal
└── Integrations (Jira, ServiceNow)
Ghostwriter (SpecterOps):
├── Open-source
├── Red team report management
├── Project & finding tracking
├── DOCX export with templates
└── Activity logging
DIY Options:
├── Markdown + Pandoc → PDF
├── LaTeX templates
└── Custom scripts + Jinja2 templates
# Pwndoc — Self-hosted setup
git clone https://github.com/pwndoc/pwndoc.git
cd pwndoc
# Start with Docker Compose
docker compose up -d
# Access: https://localhost:8443
# Default: admin / admin (change immediately!)
# Features:
# - Create audit projects
# - Add findings from template library
# - Collaborative editing
# - Auto-generate DOCX reports
# - Custom report templates
7. Report Quality Checklist
Before Submitting Report:
Content:
□ Executive summary is non-technical
□ Each finding has clear reproduction steps
□ Evidence (screenshots/requests) included
□ CVSS scores calculated correctly
□ Business impact clearly stated
□ Remediation is specific and actionable
□ References included (CWE, OWASP, CVE)
Quality:
□ Peer reviewed by another pentester
□ No typos or grammatical errors
□ Consistent formatting throughout
□ Page numbers and ToC correct
□ Classification marking on every page
□ All findings sorted by severity
Security:
□ No actual credentials in report
□ Sensitive data redacted in screenshots
□ Report encrypted before transmission
□ Delivered via secure channel
□ PII masked (show pattern, not actual data)
Professional:
□ Company branding applied
□ Positive observations included
□ Recommendations are prioritized
□ Timeline for remediation suggested
□ Offer for retest/verification
8. Tổng kết
- Structure: Cover → Executive Summary → Methodology → Findings → Remediation
- Executive Summary: 1-2 pages, business language, risk-focused
- Finding Detail: Title, CVSS, PoC steps, evidence, impact, remediation
- Prioritization: Risk matrix combining severity and business impact
- Tools: Pwndoc, PlexTrac, Ghostwriter for professional reports
- Quality: Always peer-review before submission
Bài tiếp theo sẽ trình bày Automated Reporting và Remediation Tracking.