munotes®

PTES: the Seven Phases

Get access to whole semester resourcesSemester Pass

Chapter One Hundred Twenty-One

Syllabus topic Module 2, "Penetration Testing Methodology and Reporting: structured testing methodology, phases of a penetration test"

Pages 553 to 556 of 578

In one line

The PTES (Penetration Testing Execution Standard) structures a test in seven phases: pre-engagement (agree scope and authorisation), intelligence gathering, threat modelling, vulnerability analysis, exploitation, post-exploitation, and reporting. The structure runs from agreeing the rules to delivering the report, with the actual intrusion only two phases in the middle, which is the methodology thesis made concrete.

In examination wording: the Penetration Testing Execution Standard defines seven phases, pre-engagement interactions, intelligence gathering, threat modelling, vulnerability analysis, exploitation, post-exploitation, and reporting; this structure ensures a test is properly authorised and scoped before it begins, systematically identifies and analyses weaknesses, exploits them within bounds to demonstrate impact, and concludes with an actionable report, embodying a structured methodology.

Why a named standard

The previous chapter argued that methodology, not tricks, gives a test its value. A named standard like PTES is how the profession makes that concrete: rather than each tester inventing their own method, a recognised standard defines the phases every test should follow, so tests are comparable, complete, and credible. PTES is one widely-recognised such standard (the next chapter covers OWASP's, which is web-focused); knowing its seven phases gives a student the backbone of what a professional test looks like, which is exactly what MU asks for by "phases of a penetration test."

The seven phases are worth learning as a sequence with a shape: the first phase is agreement and authorisation, the last is the report, and the actual technical intrusion is only phases five and six of seven. That shape itself teaches the lesson, most of a professional test is not the break-in.

The seven phases

1. Pre-engagement interactions. Before anything technical, the tester and client agree the terms: the scope (which systems, what is out of bounds), the rules of engagement, the timing, the goals, and, above all, the authorisation in writing. This phase is where the "authorisation is everything" principle lives; the test does not begin until it is properly scoped and authorised. Everything the exploit-frameworks block said about authorisation and scope is this phase.

2. Intelligence gathering. The tester gathers information about the target, within scope, to understand what they are assessing, the systems, services, and structure. This is the reconnaissance and footprinting concepts from Module I, applied as the first technical phase, and much of it uses openly available information.

3. Threat modelling. The tester thinks like the relevant attacker: what would a realistic adversary want, what are the valuable assets, and what are the likely avenues? This phase turns the gathered information into a prioritised picture of risk, so the test focuses on what matters to this client rather than testing everything blindly. It is where the test is aimed.

munotes.in553

PTES: the Seven Phases

4. Vulnerability analysis. The tester identifies the weaknesses in the in-scope systems, systematically, using the categories the whole book has taught (the injection family, access control, misconfiguration, the OWASP list) and the frameworks' catalogues of known vulnerabilities. This is the systematic search that delivers thoroughness.

5. Exploitation. The tester confirms which identified weaknesses are actually exploitable, within scope and bounds, gaining a foothold where they can. This is the phase popular imagination thinks of as the whole test, but it is one phase of seven, and it exists to verify that a weakness is real and reachable, not to cause harm.

6. Post-exploitation. The tester assesses the significance of what the exploitation achieved, strictly bounded by scope and the do-no-harm discipline of the earlier block: the minimum needed to demonstrate impact for the report. This is the "bounded by scope" chapter, sitting in its place in the sequence.

7. Reporting. The tester delivers the report: a clear, prioritised account of the findings, their risk, and how to fix them. This is the product of the whole test, as the previous chapter stressed, and the phase toward which all the others build.

The shape of the sequence

Reading the seven phases as a shape gives the examinable insight, and it is worth stating:

  • The first phase is agreement and authorisation, not technique; the test is founded on the rules before anything is touched.
  • The middle phases build understanding before intrusion: gather intelligence, model the threat, analyse vulnerabilities, so the intrusion is informed and aimed, not blind.
  • The intrusion is phases five and six, bounded and purposeful (verify exploitability, assess impact), not the point in itself.
  • The last phase is the report, the product.

So the structure runs rules, understanding, bounded intrusion, report, and the technical break-in occupies a minority of it. This shape embodies the methodology thesis: the value is in the structure that surrounds the intrusion (authorisation, systematic analysis, and reporting), not in the intrusion alone. A student who can name the seven phases and explain this shape understands professional penetration testing as MU intends.

A worked example, framed defensively

An organisation reviews a proposed penetration test structured on PTES, at concept level, checking each phase is planned.

  • Pre-engagement: scope, rules of engagement, timing and written authorisation are agreed. The organisation confirms this is the foundation and that out-of-bounds systems are named.
  • Intelligence gathering and threat modelling: the tester will map the in-scope systems and model the realistic threats, so the test is aimed at what matters (the organisation's valuable assets).
  • Vulnerability analysis: the tester will systematically identify weaknesses across the taught categories, giving thoroughness.
  • Exploitation and post-exploitation: the tester will confirm which weaknesses are real and assess their impact, bounded by scope and do-no-harm, to evidence risk for the report.
  • Reporting: the deliverable will be a clear, prioritised report, the product the organisation is actually commissioning.
  • The organisation notes that only two of seven phases are the intrusion, and that most of the test's value is in the authorisation, analysis and report around it, confirming the methodology thesis.
munotes.in554

PTES: the Seven Phases

The review checks a professional test against the seven phases, seeing authorisation first and the report last with bounded intrusion between. The organisation is planning a defensive assessment; nothing offensive is detailed.

What beginners get wrong

  • Thinking the test is the exploitation phase. Exploitation is one of seven phases; the test runs from authorisation (phase one) to the report (phase seven), with intrusion a bounded minority.
  • Skipping pre-engagement. The first phase is agreeing scope and authorisation in writing; without it there is no lawful test, so it is the foundation, not a formality.
  • Testing blindly. The middle phases (intelligence, threat modelling, vulnerability analysis) build an informed, aimed picture before intrusion, so the test focuses on what matters.
  • Treating exploitation as the goal. It exists to verify that a weakness is real and reachable, not to cause harm; post-exploitation then assesses impact, bounded by scope.
  • Underrating reporting. The last phase is the product; all the others build toward the clear, prioritised report the client can act on.
  • Ignoring the shape. Rules, understanding, bounded intrusion, report, with intrusion a minority, is the insight the seven phases teach, embodying the methodology thesis.

Quick revision

  • PTES (Penetration Testing Execution Standard) gives seven phases: 1 pre-engagement (scope, rules, written authorisation), 2 intelligence gathering (map the target, in scope), 3 threat modelling (aim the test at realistic risks), 4 vulnerability analysis (systematically identify weaknesses, thoroughness), 5 exploitation (verify which are actually exploitable, bounded), 6 post-exploitation (assess impact, bounded by scope, do no harm), 7 reporting (the clear, prioritised product).
  • The shape: rules, understanding, bounded intrusion, report; the technical break-in is only phases 5 and 6, a minority.
  • The shape embodies the methodology thesis: value is in the structure around the intrusion (authorisation, analysis, report), not the intrusion.

Test yourself

  1. What are the seven phases of PTES, in order?

Pre-engagement interactions, where scope, rules of engagement and written authorisation are agreed; intelligence gathering, where information about the in-scope target is collected; threat modelling, where realistic adversaries and valuable assets are identified to aim the test; vulnerability analysis, where weaknesses are systematically identified; exploitation, where the tester confirms which weaknesses are actually exploitable within bounds; post-exploitation, where the significance of the access is assessed, bounded by scope and do-no-harm; and reporting, where the clear, prioritised account of findings and fixes is delivered. The sequence runs from agreement and authorisation to the report, with the intrusion in the middle.

munotes.in555

PTES: the Seven Phases

  1. Why is pre-engagement the essential first phase?

Because it is where the test is properly scoped and authorised before anything technical happens: the tester and client agree which systems are in and out of bounds, the rules of engagement, the timing and goals, and above all the written authorisation. This phase is where the principle that authorisation is everything lives, so without it there is no lawful test at all; it is the foundation on which the technical phases rest, which is why it comes first and why it is a substantive phase rather than a formality.

  1. Why do the middle phases build understanding before the intrusion?

Because a test aimed by understanding is thorough and focused, whereas a blind intrusion is neither. Intelligence gathering maps the in-scope systems, threat modelling identifies what a realistic attacker would want and the valuable assets so the test is aimed at what matters to this client, and vulnerability analysis systematically identifies weaknesses across the taught categories. Only after this informed picture is built does exploitation confirm which weaknesses are real, so the intrusion is purposeful and comprehensive rather than a scattershot attempt, which is how the method delivers thoroughness.

  1. What is the purpose of the exploitation and post-exploitation phases, and how are they bounded?

Exploitation exists to verify which identified weaknesses are actually exploitable and reachable, confirming that a vulnerability is real rather than merely theoretical, and post-exploitation exists to assess the significance of that access so the report can convey the true impact. Both are bounded by the scope and rules of engagement agreed in pre-engagement and by the do-no-harm discipline: the tester acts only within the authorised systems, does the minimum needed to demonstrate impact, causes no harm, and stops, because the goal is evidence for the report, not exploitation for its own sake.

  1. What does the shape of the seven-phase sequence teach about penetration testing?

The shape runs rules, understanding, bounded intrusion, report: the first phase is agreement and authorisation, the middle phases build an informed picture, the intrusion is only phases five and six and is bounded and purposeful, and the last phase is the report that is the product. It teaches that most of a professional test is not the break-in, and that a test's value lies in the structure surrounding the intrusion, the authorisation, systematic analysis and reporting, rather than in the intrusion itself, which is the methodology thesis made concrete in a recognised standard.

munotes.in556

The rest of this subject

These notes are cut from the University's printed syllabus. Open the syllabus itself for the same subject.

Issue
Done!