GithubHelp home page GithubHelp logo

hartl3y94 / pentest-consulting-creator Goto Github PK

View Code? Open in Web Editor NEW

This project forked from cybersecurityup/pentest-consulting-creator

1.0 0.0 0.0 15.17 MB

Repository with some necessary information for you to create your PenTest consultancy

pentest-consulting-creator's Introduction

PenTest-Consulting-Creator

Repository with some necessary information for you to create your PenTest consultancy

PwnDoc is a pentest reporting application making it simple and easy to write your findings and generate a customizable Docx report.

Curated list of public penetration test reports released by several consulting firms and academic security groups.

PenTest Calculator Cost

PenTest Checklist

PenTest Methodology

PTES

OSSTMM

NIST 800-115

ISSAF

OWASP Test Guide

Timeline PenTest

Planning – 1-2 Weeks: Includes the contract execution, initial deposit, scheduling of resources, and review/agreement of the project Rules of Engagement (ROE).

Execution – 2-3 Weeks: This phase is when active testing of all in-scope targets is set to occur – the length of this phase varies by project and is directly related to the size/scope of the assessment.

Analysis, Documentation, and Quality Assurance – 1 Week: Document preparation including the Executive Summary Report and Technical Findings Report. This phase may also include some minimal testing and manual interactions with the in-scope targets to validate findings identified during the original execution of the test or gather more detail.

Presentation of Findings – 1 Day: Scheduled after all documentation and QA is complete, this is the final step to review findings, address questions, and wrap up the project.

Burocracy

  • Understand the bureaucratic part of the country you work in, whether in opening a company, even in providing services and the proper credentials to act.

  • Structure your portfolio of services well in PenTest, the types of tests you do and how you perform them, what methodology is used in each one?

Certifications

  • CEH
  • OSCP
  • eCPPT
  • eCPTX
  • eWPT
  • GPEN
  • GWAPT
  • CREST CPSA
  • CRTO
  • CRTL
  • OSWE
  • OSEP
  • CRTP
  • CARTP

Toolkits

  • What tools do you use?

  • Do you have trading tools?

  • Are there partnerships for the services you have? Whether to assist in the remediation, protection and mitigation of risk

  • How is the licensing of your tools? If you have a Burp, Cobalt Strike, Exploit Pack and others?

CVEs, CVSS, NVD

  • CVE Is a list of entries—each containing an identification number, a description, and at least one public reference—for publicly known cybersecurity vulnerabilities. CVE does not provide severity scoring or prioritization ratings for software vulnerabilities.

  • CVSS Operated by the Forum of Incident Response and Security Teams (FIRST) used to score the severity of software vulnerabilities identified by CVE Entries.

  • NVD NIST Provides a free CVSS calculator for CVE Entries.

  • Report your CVE When you find a 0day you can report this vulnerability to the company that owns the solution or a third party depending on the case, so waiting for a positive result and get your cve depending on the vulnerability

Tutorial Report https://drive.google.com/file/d/1pfZbOm_dExehIqGHLPtjWm2GJ4UUMMJK/view?usp=sharing

PenTest Report Writing

pentest-consulting-creator's People

Contributors

cybersecurityup avatar

Stargazers

 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.