@TechEmiiily
P!bbl3 โ“‹
3 years
How the fuck do yโ€™all write these 20 page pen-test reports? I talk a lot irl but trying to fill this shit out to fit more pages is not working out for me. ๐Ÿ˜…
51
10
214

Replies

@pry0cc
pry0cc
3 years
@TechEmiiily Pictures & recommendations, you welcome ;) Also an attack narrative section is usually pretty chunky.
1
1
17
@TechEmiiily
P!bbl3 โ“‹
3 years
@pry0cc Thatโ€™s my chunkiest section so ayeeeee
0
0
3
@AccidentalCISO
Accidental CISO
3 years
@TechEmiiily 20 pages of text? Or 20 pages including tables, graphics, screenshots, tool output, and vulnerability information?
1
1
15
@TechEmiiily
P!bbl3 โ“‹
3 years
@AccidentalCISO 20 pages in general between all of what you stated is the average of samples I see
0
1
1
@0xTib3rius
Tib3rius
3 years
@TechEmiiily If your company have a minimum length for reports, that's ridiculous. Report the issues, recommendations, add the executive summary, graphs, appendices if you need them, and be done with it. Who do they think the extraneous content is going to help?
1
0
10
@TechEmiiily
P!bbl3 โ“‹
3 years
@0xTib3rius My company doesnโ€™t have a minimum limit Iโ€™m just seeing averages from samples and theyโ€™re all 20-50 pages minimum ๐Ÿ˜ญ
2
1
2
@CyberSnark
Jabs
3 years
@TechEmiiily I write 70+ page reports quarterly where do I sign up? *cracks knuckles*
1
0
12
@TechEmiiily
P!bbl3 โ“‹
3 years
@CyberSnark How do I spin off of a bunch of fluff for a physical test that isnโ€™t too repetitive from a cyber test? They already submitted the cyber test so now Iโ€™m reading it over like โ€œsheesh I feel like Iโ€™m repeating myselfโ€
3
0
4
@drb0n3z
Bones ๐Ÿณ๏ธโ€๐ŸŒˆ
3 years
@TechEmiiily APA formatting helps ๐Ÿคฃ
1
1
3
@TechEmiiily
P!bbl3 โ“‹
3 years
@drb0n3z Iโ€™ve smoked away that part of my memory banks, back to Google!
2
1
3
@CurtBraz
๐‚๐ฎ๐ซ๐ญ๐ข๐ฌ ๐๐ซ๐š๐ณ๐ณ๐ž๐ฅ๐ฅ
3 years
@TechEmiiily 20 pages?! I think I've only had one that short in my career. ๐Ÿ˜„
1
0
7
@TechEmiiily
P!bbl3 โ“‹
3 years
@CurtBraz Wait are you the author from M is for Malware?!
3
0
4
@Kurt_theTurk
The Turk needs a vacation
3 years
@TechEmiiily *Me who just presented an 85 page purple team report...
1
0
3
@TechEmiiily
P!bbl3 โ“‹
3 years
@Kurt_theTurk Heck yea go you! Thatโ€™s badass!
0
0
2
@_th1nk3r
#ไธ…แ•ผแŽฅแ‘Žแ›•แ—ดแ–‡ ...will be at #DEFCON ๐Ÿ•‰๏ธ ; {apt} โ“‹
3 years
@TechEmiiily Every pentest report I have ever seen is at least a page per item that was in scope for the test. Screenshots, narrative, recommendation is the formula given.
0
0
8
@zeampzpvy
Richard Ward ์ง€์•ฐํ”„
3 years
@TechEmiiily Bullet lists. Comic Sans.
0
0
1
@dimitrimckay
Run DMc
3 years
@TechEmiiily My reports are between 40 and 60 pages. Thereโ€™s also a very short PowerPoint presentation that summarizes the findings.
1
0
1
@GlennPegden
Glenn Pegden
3 years
@TechEmiiily You know what most pentest companies miss in their reports which is super valuable(well, to an org like ours, maybe not everyone), what you tested and *didnโ€™t* find anything wrong with. โ€˜Great, you popped a DC, did you fail to pop the other 9 or didnโ€™t have time to try them?โ€™
2
0
7
@TechEmiiily
P!bbl3 โ“‹
3 years
@cricket_hippo This was a physical test so I donโ€™t even have the luxury of putting fluff like that in there. ๐Ÿ˜ญ
0
0
1