# Penetration Test Report ## Document control - Client: - Engagement: - Report version: - Assessment dates: - Report date: - Prepared by: - Classification: ## Executive summary Summarize why the assessment was performed, what was tested, the overall risk, the most important attack paths, and the actions leadership should prioritize. ## Scope ### Included | Asset | Environment | Test type | Notes | |---|---|---|---| | | | | | ### Excluded List excluded assets, techniques, accounts, hours, and data. ## Rules of engagement - Written authorization: - Test window: - Source addresses: - Emergency contacts: - Stop conditions: - Data handling and deletion: ## Methodology Describe the standards and phases used, such as scoping, reconnaissance, threat modeling, automated analysis, manual testing, exploitation validation, cleanup, reporting, and retesting. ## Limitations and assumptions Record time constraints, unavailable accounts, blocked functionality, unstable systems, incomplete source access, or other factors that affect assurance. ## Risk summary | ID | Finding | Severity | Asset | Status | |---|---|---|---|---| | F-01 | | | | Open | ## Positive observations Record effective controls that materially reduced risk. ## Findings ### F-01 - [Finding title] **Severity:** **Affected assets:** **CWE:** **CVSS:** **Status:** Open #### Description Explain the failed security control and relevant context. #### Evidence and reproduction 1. Provide exact, safe reproduction steps. 2. Include sanitized request and response evidence. 3. Include a negative control where useful. #### Impact Describe the demonstrated business and technical impact, affected users or data, prerequisites, and realistic attack limits. #### Root cause Explain why the control failed. #### Remediation Provide an actionable root-cause fix, validation guidance, and optional defense-in-depth controls. #### References - Relevant vendor or standards guidance #### Retest - Date: - Build or environment: - Result: - Evidence: ## Strategic recommendations Group recurring root causes into prioritized program improvements with owners and measurable outcomes. ## Appendix ### Tools List tool names and versions. Do not imply automated coverage equals complete coverage. ### Evidence handling Document where evidence was stored, who received it, and when local copies will be deleted.