The 5 Phases of Penetration Testing: A Complete Framework
Every professional penetration test follows the same five phases. Understanding these helps you plan, execute, and report efficiently.
Phase 1: Reconnaissance
Reconnaissance (footprinting) is about learning everything about your target before you touch it.
Passive Recon
No direct interaction with the target. Gather publicly available information.
- Google dorking (advanced search operators)
- WHOIS lookups
- DNS enumeration from public sources
- Social media profiling
- Shodan and Censys searches
Tools: Maltego, theHarvester, Amass, Shodan
Active Recon
Direct interaction with the target. More risky but more informative.
- Port scanning (nmap)
- Service enumeration
- Network mapping
- Vulnerability scanning
Tools: Nmap, Masscan, Nuclei
Spend 40% of your time here. Good recon makes everything easier.
Phase 2: Scanning
Scanning finds open doors.
Port Scanning
Discover open ports and services:
nmap -sV -p- target.com
Vulnerability Scanning
Automated tools find known vulnerabilities:
nessus or openvas target.com
Web Application Scanning
For web applications:
nikto -h target.com
Phase 3: Exploitation
Prove impact by actually exploiting vulnerabilities.
Gain Initial Access
- Hydra for brute force
- SQLMap for injection
- Metasploit for known exploits
- Manual exploitation for custom vulnerabilities
Establish Persistence
- Create backdoor accounts
- Deploy web shells
- Set up cron jobs
Privilege Escalation
- Linux: Check SUID binaries, cron jobs, kernel exploits
- Windows: Service misconfigurations, DLL hijacking
Tools: LinPEAS, WinPEAS, LinEnum
Phase 4: Post-Exploitation
You are in. Now what?
Information Gathering
- Configuration files with credentials
- Database connection strings
- Private keys and certificates
- Password hashes
Lateral Movement
- Pass-the-hash attacks
- Mimikatz credential extraction
- RDP and SMB relay
Phase 5: Reporting
Reporting is the deliverable. A great test with a poor report helps no one.
Report Structure
- Executive Summary: High-level findings for leadership
- Scope and Methodology: What was tested and how
- Findings: Each vulnerability with title, severity, impact, and remediation
- Evidence: Screenshots and output proving findings
- Appendices: Technical details
Common Mistakes to Avoid
- Skipping reconnaissance to jump straight to exploitation
- Testing outside scope
- Inadequate documentation during testing
- Not verifying scanner findings
- Weak reporting
Bottom Line
Master all five phases. Reconnaissance, Scanning, Exploitation, Post-Exploitation, Reporting.
Professional pentesting is methodical execution, not just exploits.
