1.2 Penetration Testing Methodology & Standards

Key Takeaways

  • The Penetration Testing Execution Standard (PTES) defines seven distinct operational phases: Pre-engagement Interactions, Intelligence Gathering, Threat Modeling, Vulnerability Analysis, Exploitation, Post-Exploitation, and Reporting.

  • The four eJPT examination domains map directly onto the PTES framework, assessing reconnaissance, vulnerability discovery, active exploitation, and post-exploitation across networks and web applications.

  • The Rules of Engagement (RoE) specify legally binding testing boundaries, explicitly distinguishing authorized targets from out-of-scope assets, defining test windows, and establishing communication channels.

  • Professional offensive operations require strict adherence to legal frameworks like the Computer Fraud and Abuse Act (CFAA) and rigorous evidence handling to maintain chain of custody and audit integrity.

Last updated: October 2026

1.2 Penetration Testing Methodology & Standards

Professional penetration testing is not an ad-hoc collection of clever exploitation tricks; it is a structured, repeatable, and legally governed engineering discipline. Performing effective security assessments requires a comprehensive understanding of industry-recognized methodologies, formal Rules of Engagement (RoE), statutory legal frameworks, and ethical responsibilities. Understanding these standards ensures that security assessments deliver actionable risk reduction while operating within authorized legal boundaries.

The Penetration Testing Execution Standard (PTES)

While several information security frameworks exist—including the Open Source Security Testing Methodology Manual (OSSTMM) and NIST Special Publication 800-115—the Penetration Testing Execution Standard (PTES) has emerged as the definitive technical standard for offensive security engagements. Developed by a consortium of senior security practitioners, PTES defines the complete lifecycle of a penetration testing assessment across seven distinct phases.

1. Pre-engagement Interactions

Before any packets are transmitted across a network, the testing organization and the client must establish clear operational boundaries. Pre-engagement interactions involve defining the business objectives of the assessment, identifying key stakeholders, establishing formal contracts and Non-Disclosure Agreements (NDAs), drafting the Rules of Engagement (RoE), determining emergency escalation paths, and verifying written authorization.

Crucially, this phase determines the scope of the engagement:

  • Black-box Testing: The tester begins with zero prior knowledge of the target environment, simulating an external threat actor.
  • White-box Testing: The tester is provided full architectural documentation, source code, network diagrams, and administrative credentials to identify deep-seated structural flaws.
  • Gray-box Testing: The tester possesses partial information—such as a standard employee user account and internal network range—simulating an insider threat or an attacker who has bypassed perimeter defenses. The eJPT examination primarily reflects a gray-box assessment model.

2. Intelligence Gathering

In the intelligence gathering phase (reconnaissance), the penetration tester discovers as much information about the target organization and its technology stack as possible. Intelligence gathering is divided into two fundamental disciplines:

  • Passive Reconnaissance (OSINT): Gathering publicly accessible data without directly interacting with the target's network infrastructure. Activities include searching WHOIS registries, inspecting public DNS records, searching code repositories (such as GitHub) for leaked API keys, executing Google dorking queries, and enumerating corporate employees and email formats using tools like theHarvester. Passive reconnaissance leaves no identifiable signature in the target organization's firewall or intrusion detection logs.
  • Active Reconnaissance: Directly probing the target's systems to enumerate live network infrastructure. Activities include running ARP scans, ICMP ping sweeps, TCP/UDP port scans with Nmap, requesting web application headers, and performing DNS zone transfer queries (dig axfr). Active reconnaissance generates network traffic that will be logged by intrusion detection systems (IDS) and web application firewalls (WAF).

3. Threat Modeling

Threat modeling transforms raw intelligence into a structured attack plan. In this phase, the tester analyzes the discovered assets, software versions, and architectural designs to identify potential threat actors, evaluate business impact, and determine the most viable attack vectors. Rather than attacking randomly, the penetration tester develops a prioritized hierarchy of targets based on exploit feasibility, service exposure, and business criticality.

4. Vulnerability Analysis

Vulnerability analysis involves identifying system flaws, software defects, outdated packages, and configuration errors that could allow an attacker to bypass security controls. Effective vulnerability analysis combines automated discovery tools with meticulous manual validation:

  • Automated scanners (such as Nikto, Nessus, OpenVAS, and Nmap Scripting Engine scripts) rapidly evaluate large numbers of services against vulnerability signatures.
  • Manual analysis verifies automated findings to eliminate false positives and discovers contextual vulnerabilities—such as weak or default administrative credentials, logic flaws, and improper access controls—that automated tools routinely miss.
  • Discovered vulnerabilities are correlated against the Common Vulnerabilities and Exposures (CVE) database and evaluated using the Common Vulnerability Scoring System (CVSS) to determine severity.

5. Exploitation

The exploitation phase focuses solely on breaching target defenses and gaining unauthorized access to systems or data. Armed with validated vulnerabilities identified in the previous phase, the tester executes targeted exploits designed to achieve remote code execution (RCE), bypass authentication mechanisms, or extract sensitive data.

Professional penetration testers prioritize precision, controlled execution, and safety during exploitation. Exploitation should never compromise system availability or cause unintended damage to production infrastructure. If an exploit has a high likelihood of crashing a critical daemon or triggering a kernel panic, the tester must consult the client before proceeding.

6. Post-Exploitation

Gaining an initial foothold on a target machine is rarely the end objective. The post-exploitation phase evaluates the true business impact of the compromise by answering the question: What can an attacker achieve once inside?

Key post-exploitation activities include:

  • System Profiling and Information Gathering: Identifying the operating system release, patch levels, network interfaces, routing tables, and active network connections.
  • Privilege Escalation: Elevating permissions from a restricted service account to local root or Windows NT AUTHORITY\SYSTEM.
  • Credential Harvesting: Dumping password hashes from /etc/shadow, Windows SAM, or LSASS memory, and extracting stored plaintext credentials from configuration files.
  • Lateral Movement and Pivoting: Utilizing compromised credentials and establishing network routes through multi-homed hosts to discover and compromise internal network enclaves.
  • Objective Verification (Proof of Concept): Accessing critical databases, extracting designated flag files, or documenting unauthorized administrative access to substantiate the risk.

7. Reporting

The final phase represents the primary tangible deliverable of the penetration test. A professional penetration testing report communicates technical findings in a structured format suitable for both executive leadership and technical engineers:

  • Executive Summary: A non-technical overview explaining the assessment scope, overall security posture, high-level business risks, and strategic recommendations.
  • Technical Findings: Detailed walkthroughs of every discovered vulnerability, including CVSS severity ratings, affected assets, step-by-step reproduction instructions, proof-of-concept screenshots, and precise technical remediation guidance.

Mapping PTES to the eJPT Examination Domains

The eJPT examination is directly aligned with the technical phases of the PTES lifecycle. Each of the four eJPT exam domains operationalizes specific PTES phases within the context of an entry-level professional assessment.

PTES PhaseeJPT Domain AlignmentCore Technical Activities in eJPT LabRequired Tools & Artifacts
1. Pre-engagementGeneral Exam FrameworkReviewing exam instructions, scoping target subnets, establishing VPN connectivityExam portal briefing, OpenVPN, ip route
2. Intelligence GatheringAssessment Methodologies (25%)Passive OSINT research, active host discovery, ping sweeps, TCP/UDP port mappingnmap, arp-scan, whois, dig, theHarvester
3. Threat ModelingAssessment Methodologies (25%)Correlating open ports, identifying exposed web applications, prioritizing entry pointsTarget inventory notes, attack path diagram
4. Vulnerability AnalysisAssessment Methodologies & Auditing (25%)Service version enumeration, CVE correlation, Nmap NSE vulnerability scans, web path brute-forcingsearchsploit, NVD, nikto, gobuster, ffuf
5. ExploitationHost/Network Pentesting & Web Pentesting (50%)Metasploit module execution, manual exploit script modifications, SQL injection, authentication bypassmsfconsole, Python/C exploits, sqlmap, Burp Suite
6. Post-ExploitationHost/Network Auditing & Pentesting (60%)Local privilege escalation, hash dumping, pivoting across subnets, extracting dynamic flagsLinPEAS, WinPEAS, Meterpreter, proxychains, john
7. ReportingScenario-Based QuestionsAnswering 35 scenario questions, submitting recovered flags, validating technical findingsExam portal question submission interface

In the eJPT assessment, you do not write a 50-page formal PDF report; instead, the reporting phase is evaluated directly through the 35 scenario-based exam questions. Answering these questions requires the exact same meticulous evidence collection and verification necessary to compile a professional client report.

Rules of Engagement (RoE) & Operational Scoping

The Rules of Engagement (RoE) document is the operational core of a penetration test. While commercial contracts and master services agreements (MSAs) govern financial and legal relationships, the RoE governs the day-to-day technical execution of the test.

Key Components of a Professional RoE

A comprehensive RoE defines operational parameters across five critical areas:

  1. Scope Boundaries:
    • In-Scope Targets: An explicit, exhaustive list of authorized IP addresses, IP subnets (CIDR notation), fully qualified domain names (FQDNs), and specific applications.
    • Out-of-Scope Targets: Systems explicitly excluded from testing. This frequently includes third-party cloud hosting providers, shared infrastructure, production payment gateways, SCADA/ICS industrial controllers, and specific high-availability servers.
  2. Authorized Testing Windows: Defining specific calendar dates and time-of-day constraints. Certain clients require off-hours testing (e.g., weekends or 22:00 to 06:00) to minimize the impact of potential service disruptions on daily business operations. Other clients mandate business-hours testing to evaluate the real-time detection and response capabilities of their internal Security Operations Center (SOC).
  3. Forbidden Actions and Prohibited Techniques:
    • Explicit prohibition of Denial of Service (DoS or DDoS) attacks.
    • Prohibiting modification or deletion of production database records.
    • Restricting physical security breaches or social engineering unless explicitly contracted.
    • Restrictions on weaponizing unverified public zero-day exploits.
  4. Emergency Incident and Communication Protocols:
    • Primary and secondary technical contacts for both the testing team and client engineering staff.
    • Immediate escalation procedures if a target system crashes, experiences high latency, or enters an unstable state.
    • Immediate notification protocols if the tester discovers active evidence of a pre-existing breach or compromise by an external adversary.
  5. Data Handling and Confidentiality: Standards for encrypting client data, securing captured credentials, and securely wiping all sensitive artifacts upon conclusion of the engagement.

Rules of Engagement in the eJPT Exam

When launching the eJPT examination, the initial exam instruction page functions as your formal Rules of Engagement:

  • Authorized Targets: The simulated corporate network subnets specified in your exam brief.
  • Strictly Prohibited Targets: INE's underlying lab virtualization infrastructure, the examination grading portal, other student networks, and internet resources outside the designated lab scope.
  • Prohibited Conduct: Launching denial-of-service attacks or attempting to manipulate the underlying hypervisor. Violating these rules results in immediate exam termination and voucher revocation.

Ethical Responsibilities & Statutory Legal Frameworks

The boundary separating a professional penetration tester from a criminal threat actor is not defined by tools, technical expertise, or methodologies. Both utilize the same network scanners, exploit frameworks, and reverse shells. The sole defining factor is explicit, authorized permission.

Statutory Legal Frameworks

Operating without authorization—or exceeding the scope of authorized permission—triggers severe criminal liability under national and international legal statutes:

Computer Fraud and Abuse Act (CFAA - 18 U.S.C. § 1030)

In the United States, the CFAA serves as the primary federal statute governing computer crime. Key provisions criminalize:

  • Intentionally accessing a protected computer without authorization or exceeding authorized access, and thereby obtaining information from any protected computer (18 U.S.C. § 1030(a)(2)).
  • Intentionally causing damage without authorization to a protected computer through the transmission of a program, code, or command (18 U.S.C. § 1030(a)(5)(A)).

Under the CFAA, "exceeding authorized access" is a critical concept for penetration testers. If a client authorizes testing on 192.168.10.0/24, and the tester intentionally scans or exploits an adjacent subnet 192.168.20.0/24 that was not included in the signed scope document, the tester has exceeded authorized access and may face criminal prosecution.

International Cybercrime Statutes

  • United Kingdom - Computer Misuse Act 1990: Sections 1 through 3 criminalize unauthorized access to computer material, unauthorized access with intent to commit further offenses, and unauthorized acts with intent to impair the operation of a computer.
  • European Union & Budapest Convention: The Council of Europe Convention on Cybercrime establishes common standards for criminalizing unauthorized access, illegal interception of communications, and system data interference across signatory nations.

Evidence Handling and Audit Integrity

Professional penetration testers maintain an unbroken chain of custody and rigorous audit trails for all assessment activities. Maintaining audit integrity serves three vital purposes:

  1. Client Transparency and Reproducibility: The client must be able to verify exactly what actions were taken, which commands were executed, and when each payload was delivered.
  2. Attribution and Non-Repudiation: If a client experiences a service outage during the testing window, comprehensive logs allow the penetration tester to prove whether the disruption was caused by their testing activities or by an unrelated operational event.
  3. Legal Protection: In the event of a contractual or legal dispute, complete terminal logs, timestamped packet captures, and signed scope agreements provide an undeniable record of authorized, responsible execution.
Test Your Knowledge

Under the Penetration Testing Execution Standard (PTES), which phase immediately precedes Exploitation and focuses on identifying system flaws, software defects, and configuration errors?

A

Pre-engagement Interactions

B

Post-Exploitation

C

Threat Modeling

D

Vulnerability Analysis

Test Your Knowledge

Within a professional penetration testing Rules of Engagement (RoE) document, what is the primary purpose of defining scope boundaries?

A

To establish an explicit, legally binding distinction between authorized target assets and excluded systems or third-party infrastructure

B

To select which automated exploitation frameworks the testing team is permitted to install on their local machines

C

To dictate the specific visual formatting and corporate branding guidelines required in the final executive report

D

To determine the commercial billing rate and invoicing schedule for the penetration testing engagement

Test Your Knowledge

What primary factor legally distinguishes a professional penetration tester from a criminal threat actor under statutory frameworks such as the Computer Fraud and Abuse Act (CFAA)?

A

The specific operating system distribution and open-source tools utilized during the assessment

B

Whether the individual has achieved an industry certification like the eJPT or CEH

C

The presence of formal, written, legally binding authorization defining explicit scope and boundaries

D

The total duration of the testing window and whether scans are conducted after business hours

Sections you finish are checked off in the contents.