01
phase/recon
Map it before you touch it
Passive recon and OSINT first: what's already public about a target, from domains and tech stack to people and exposed services. The quietest phase is often the most revealing.
$ shodan host lab.target
ports 22, 80, 443, 3306
server nginx · php
[!] database port reachable from the internet
// Shodan · Maltego · OSINT
02
phase/scan
Find every open door
Network scanning to map live hosts, open ports and running services, so nothing in scope is left unknown.
$ nmap -sV 10.0.0.0/24
22/tcp open ssh OpenSSH
80/tcp open http nginx
8080/tcp open http admin panel ← why is this exposed?
// Nmap · Zenmap
03
phase/enumerate
Read it like the developer who built it
Service enumeration and vulnerability scanning, plus the part most testers skip: reading client-side code, configs and headers with 8+ years of builder's instinct.
[!] outdated component in bundle
[!] missing security headers
[!] stack traces on error pages
// Nessus · OpenVAS · DevTools
04
phase/exploit
Prove it, carefully
Validate findings inside scope, with evidence and without collateral damage, and watch the traffic while doing it.
msf6 > check
[+] target appears vulnerable
[*] proof captured · no damage done
// Metasploit · Wireshark
05
phase/report
Make it fixable
Clear findings, real impact and fixes developers can actually ship. I've been the developer on the receiving end of a report, so I write the one I'd want to get.
$ cat report.md | head -3
critical 2 fixes included
medium 5 fixes included
status ready for the dev team
// clear writing · developer empathy