1.2 Penetration Testing Methodology & Standards
Key Takeaways
The Penetration Testing Execution Standard (PTES) defines seven distinct operational phases: Pre-engagement Interactions, Intelligence Gathering, Threat Modeling, Vulnerability Analysis, Exploitation, Post-Exploitation, and Reporting.
The four eJPT examination domains map directly onto the PTES framework, assessing reconnaissance, vulnerability discovery, active exploitation, and post-exploitation across networks and web applications.
The Rules of Engagement (RoE) specify legally binding testing boundaries, explicitly distinguishing authorized targets from out-of-scope assets, defining test windows, and establishing communication channels.
Professional offensive operations require strict adherence to legal frameworks like the Computer Fraud and Abuse Act (CFAA) and rigorous evidence handling to maintain chain of custody and audit integrity.
1.2 Penetration Testing Methodology & Standards
Professional penetration testing is not an ad-hoc collection of clever exploitation tricks; it is a structured, repeatable, and legally governed engineering discipline. Performing effective security assessments requires a comprehensive understanding of industry-recognized methodologies, formal Rules of Engagement (RoE), statutory legal frameworks, and ethical responsibilities. Understanding these standards ensures that security assessments deliver actionable risk reduction while operating within authorized legal boundaries.
The Penetration Testing Execution Standard (PTES)
While several information security frameworks exist—including the Open Source Security Testing Methodology Manual (OSSTMM) and NIST Special Publication 800-115—the Penetration Testing Execution Standard (PTES) has emerged as the definitive technical standard for offensive security engagements. Developed by a consortium of senior security practitioners, PTES defines the complete lifecycle of a penetration testing assessment across seven distinct phases.
1. Pre-engagement Interactions
Before any packets are transmitted across a network, the testing organization and the client must establish clear operational boundaries. Pre-engagement interactions involve defining the business objectives of the assessment, identifying key stakeholders, establishing formal contracts and Non-Disclosure Agreements (NDAs), drafting the Rules of Engagement (RoE), determining emergency escalation paths, and verifying written authorization.
Crucially, this phase determines the scope of the engagement:
- Black-box Testing: The tester begins with zero prior knowledge of the target environment, simulating an external threat actor.
- White-box Testing: The tester is provided full architectural documentation, source code, network diagrams, and administrative credentials to identify deep-seated structural flaws.
- Gray-box Testing: The tester possesses partial information—such as a standard employee user account and internal network range—simulating an insider threat or an attacker who has bypassed perimeter defenses. The eJPT examination primarily reflects a gray-box assessment model.
2. Intelligence Gathering
In the intelligence gathering phase (reconnaissance), the penetration tester discovers as much information about the target organization and its technology stack as possible. Intelligence gathering is divided into two fundamental disciplines:
- Passive Reconnaissance (OSINT): Gathering publicly accessible data without directly interacting with the target's network infrastructure. Activities include searching WHOIS registries, inspecting public DNS records, searching code repositories (such as GitHub) for leaked API keys, executing Google dorking queries, and enumerating corporate employees and email formats using tools like
theHarvester. Passive reconnaissance leaves no identifiable signature in the target organization's firewall or intrusion detection logs. - Active Reconnaissance: Directly probing the target's systems to enumerate live network infrastructure. Activities include running ARP scans, ICMP ping sweeps, TCP/UDP port scans with Nmap, requesting web application headers, and performing DNS zone transfer queries (
dig axfr). Active reconnaissance generates network traffic that will be logged by intrusion detection systems (IDS) and web application firewalls (WAF).
3. Threat Modeling
Threat modeling transforms raw intelligence into a structured attack plan. In this phase, the tester analyzes the discovered assets, software versions, and architectural designs to identify potential threat actors, evaluate business impact, and determine the most viable attack vectors. Rather than attacking randomly, the penetration tester develops a prioritized hierarchy of targets based on exploit feasibility, service exposure, and business criticality.
4. Vulnerability Analysis
Vulnerability analysis involves identifying system flaws, software defects, outdated packages, and configuration errors that could allow an attacker to bypass security controls. Effective vulnerability analysis combines automated discovery tools with meticulous manual validation:
- Automated scanners (such as Nikto, Nessus, OpenVAS, and Nmap Scripting Engine scripts) rapidly evaluate large numbers of services against vulnerability signatures.
- Manual analysis verifies automated findings to eliminate false positives and discovers contextual vulnerabilities—such as weak or default administrative credentials, logic flaws, and improper access controls—that automated tools routinely miss.
- Discovered vulnerabilities are correlated against the Common Vulnerabilities and Exposures (CVE) database and evaluated using the Common Vulnerability Scoring System (CVSS) to determine severity.
5. Exploitation
The exploitation phase focuses solely on breaching target defenses and gaining unauthorized access to systems or data. Armed with validated vulnerabilities identified in the previous phase, the tester executes targeted exploits designed to achieve remote code execution (RCE), bypass authentication mechanisms, or extract sensitive data.
Professional penetration testers prioritize precision, controlled execution, and safety during exploitation. Exploitation should never compromise system availability or cause unintended damage to production infrastructure. If an exploit has a high likelihood of crashing a critical daemon or triggering a kernel panic, the tester must consult the client before proceeding.
6. Post-Exploitation
Gaining an initial foothold on a target machine is rarely the end objective. The post-exploitation phase evaluates the true business impact of the compromise by answering the question: What can an attacker achieve once inside?
Key post-exploitation activities include:
- System Profiling and Information Gathering: Identifying the operating system release, patch levels, network interfaces, routing tables, and active network connections.
- Privilege Escalation: Elevating permissions from a restricted service account to local root or Windows
NT AUTHORITY\SYSTEM. - Credential Harvesting: Dumping password hashes from
/etc/shadow, Windows SAM, or LSASS memory, and extracting stored plaintext credentials from configuration files. - Lateral Movement and Pivoting: Utilizing compromised credentials and establishing network routes through multi-homed hosts to discover and compromise internal network enclaves.
- Objective Verification (Proof of Concept): Accessing critical databases, extracting designated flag files, or documenting unauthorized administrative access to substantiate the risk.
7. Reporting
The final phase represents the primary tangible deliverable of the penetration test. A professional penetration testing report communicates technical findings in a structured format suitable for both executive leadership and technical engineers:
- Executive Summary: A non-technical overview explaining the assessment scope, overall security posture, high-level business risks, and strategic recommendations.
- Technical Findings: Detailed walkthroughs of every discovered vulnerability, including CVSS severity ratings, affected assets, step-by-step reproduction instructions, proof-of-concept screenshots, and precise technical remediation guidance.
Mapping PTES to the eJPT Examination Domains
The eJPT examination is directly aligned with the technical phases of the PTES lifecycle. Each of the four eJPT exam domains operationalizes specific PTES phases within the context of an entry-level professional assessment.
| PTES Phase | eJPT Domain Alignment | Core Technical Activities in eJPT Lab | Required Tools & Artifacts |
|---|---|---|---|
| 1. Pre-engagement | General Exam Framework | Reviewing exam instructions, scoping target subnets, establishing VPN connectivity | Exam portal briefing, OpenVPN, ip route |
| 2. Intelligence Gathering | Assessment Methodologies (25%) | Passive OSINT research, active host discovery, ping sweeps, TCP/UDP port mapping | nmap, arp-scan, whois, dig, theHarvester |
| 3. Threat Modeling | Assessment Methodologies (25%) | Correlating open ports, identifying exposed web applications, prioritizing entry points | Target inventory notes, attack path diagram |
| 4. Vulnerability Analysis | Assessment Methodologies & Auditing (25%) | Service version enumeration, CVE correlation, Nmap NSE vulnerability scans, web path brute-forcing | searchsploit, NVD, nikto, gobuster, ffuf |
| 5. Exploitation | Host/Network Pentesting & Web Pentesting (50%) | Metasploit module execution, manual exploit script modifications, SQL injection, authentication bypass | msfconsole, Python/C exploits, sqlmap, Burp Suite |
| 6. Post-Exploitation | Host/Network Auditing & Pentesting (60%) | Local privilege escalation, hash dumping, pivoting across subnets, extracting dynamic flags | LinPEAS, WinPEAS, Meterpreter, proxychains, john |
| 7. Reporting | Scenario-Based Questions | Answering 35 scenario questions, submitting recovered flags, validating technical findings | Exam portal question submission interface |
In the eJPT assessment, you do not write a 50-page formal PDF report; instead, the reporting phase is evaluated directly through the 35 scenario-based exam questions. Answering these questions requires the exact same meticulous evidence collection and verification necessary to compile a professional client report.
Rules of Engagement (RoE) & Operational Scoping
The Rules of Engagement (RoE) document is the operational core of a penetration test. While commercial contracts and master services agreements (MSAs) govern financial and legal relationships, the RoE governs the day-to-day technical execution of the test.
Key Components of a Professional RoE
A comprehensive RoE defines operational parameters across five critical areas:
- Scope Boundaries:
- In-Scope Targets: An explicit, exhaustive list of authorized IP addresses, IP subnets (CIDR notation), fully qualified domain names (FQDNs), and specific applications.
- Out-of-Scope Targets: Systems explicitly excluded from testing. This frequently includes third-party cloud hosting providers, shared infrastructure, production payment gateways, SCADA/ICS industrial controllers, and specific high-availability servers.
- Authorized Testing Windows: Defining specific calendar dates and time-of-day constraints. Certain clients require off-hours testing (e.g., weekends or 22:00 to 06:00) to minimize the impact of potential service disruptions on daily business operations. Other clients mandate business-hours testing to evaluate the real-time detection and response capabilities of their internal Security Operations Center (SOC).
- Forbidden Actions and Prohibited Techniques:
- Explicit prohibition of Denial of Service (DoS or DDoS) attacks.
- Prohibiting modification or deletion of production database records.
- Restricting physical security breaches or social engineering unless explicitly contracted.
- Restrictions on weaponizing unverified public zero-day exploits.
- Emergency Incident and Communication Protocols:
- Primary and secondary technical contacts for both the testing team and client engineering staff.
- Immediate escalation procedures if a target system crashes, experiences high latency, or enters an unstable state.
- Immediate notification protocols if the tester discovers active evidence of a pre-existing breach or compromise by an external adversary.
- Data Handling and Confidentiality: Standards for encrypting client data, securing captured credentials, and securely wiping all sensitive artifacts upon conclusion of the engagement.
Rules of Engagement in the eJPT Exam
When launching the eJPT examination, the initial exam instruction page functions as your formal Rules of Engagement:
- Authorized Targets: The simulated corporate network subnets specified in your exam brief.
- Strictly Prohibited Targets: INE's underlying lab virtualization infrastructure, the examination grading portal, other student networks, and internet resources outside the designated lab scope.
- Prohibited Conduct: Launching denial-of-service attacks or attempting to manipulate the underlying hypervisor. Violating these rules results in immediate exam termination and voucher revocation.
Ethical Responsibilities & Statutory Legal Frameworks
The boundary separating a professional penetration tester from a criminal threat actor is not defined by tools, technical expertise, or methodologies. Both utilize the same network scanners, exploit frameworks, and reverse shells. The sole defining factor is explicit, authorized permission.
Statutory Legal Frameworks
Operating without authorization—or exceeding the scope of authorized permission—triggers severe criminal liability under national and international legal statutes:
Computer Fraud and Abuse Act (CFAA - 18 U.S.C. § 1030)
In the United States, the CFAA serves as the primary federal statute governing computer crime. Key provisions criminalize:
- Intentionally accessing a protected computer without authorization or exceeding authorized access, and thereby obtaining information from any protected computer (18 U.S.C. § 1030(a)(2)).
- Intentionally causing damage without authorization to a protected computer through the transmission of a program, code, or command (18 U.S.C. § 1030(a)(5)(A)).
Under the CFAA, "exceeding authorized access" is a critical concept for penetration testers. If a client authorizes testing on 192.168.10.0/24, and the tester intentionally scans or exploits an adjacent subnet 192.168.20.0/24 that was not included in the signed scope document, the tester has exceeded authorized access and may face criminal prosecution.
International Cybercrime Statutes
- United Kingdom - Computer Misuse Act 1990: Sections 1 through 3 criminalize unauthorized access to computer material, unauthorized access with intent to commit further offenses, and unauthorized acts with intent to impair the operation of a computer.
- European Union & Budapest Convention: The Council of Europe Convention on Cybercrime establishes common standards for criminalizing unauthorized access, illegal interception of communications, and system data interference across signatory nations.
Evidence Handling and Audit Integrity
Professional penetration testers maintain an unbroken chain of custody and rigorous audit trails for all assessment activities. Maintaining audit integrity serves three vital purposes:
- Client Transparency and Reproducibility: The client must be able to verify exactly what actions were taken, which commands were executed, and when each payload was delivered.
- Attribution and Non-Repudiation: If a client experiences a service outage during the testing window, comprehensive logs allow the penetration tester to prove whether the disruption was caused by their testing activities or by an unrelated operational event.
- Legal Protection: In the event of a contractual or legal dispute, complete terminal logs, timestamped packet captures, and signed scope agreements provide an undeniable record of authorized, responsible execution.
Under the Penetration Testing Execution Standard (PTES), which phase immediately precedes Exploitation and focuses on identifying system flaws, software defects, and configuration errors?
Pre-engagement Interactions
Post-Exploitation
Threat Modeling
Vulnerability Analysis
Within a professional penetration testing Rules of Engagement (RoE) document, what is the primary purpose of defining scope boundaries?
To establish an explicit, legally binding distinction between authorized target assets and excluded systems or third-party infrastructure
To select which automated exploitation frameworks the testing team is permitted to install on their local machines
To dictate the specific visual formatting and corporate branding guidelines required in the final executive report
To determine the commercial billing rate and invoicing schedule for the penetration testing engagement
What primary factor legally distinguishes a professional penetration tester from a criminal threat actor under statutory frameworks such as the Computer Fraud and Abuse Act (CFAA)?
The specific operating system distribution and open-source tools utilized during the assessment
Whether the individual has achieved an industry certification like the eJPT or CEH
The presence of formal, written, legally binding authorization defining explicit scope and boundaries
The total duration of the testing window and whether scans are conducted after business hours
Sections you finish are checked off in the contents.