1. Scoping and authorization
A penetration test should begin with a clearly defined scope. The organization and testing team agree the systems in scope, exclusions, objectives, timing, contacts and rules of engagement before testing starts.
2. Reconnaissance and assessment
The tester gathers relevant information about the agreed targets and evaluates the attack surface. The exact techniques depend on whether the engagement covers web applications, APIs, networks, infrastructure or another authorized environment.
3. Controlled exploitation
Where appropriate, selected weaknesses are safely validated to determine whether they are exploitable and what impact they could have. Testing should remain within the agreed authorization and operational boundaries.
4. Reporting
Findings should be documented with enough evidence and context for stakeholders to understand the issue, affected assets, risk and recommended remediation.
5. Remediation and retesting
The technical team addresses findings based on risk and business priorities. Retesting can then verify whether agreed fixes have effectively addressed the reported weaknesses.
