What problem does it solve?
Organizations need to identify exploitable vulnerabilities in their internet-facing infrastructure before attackers do, but ad-hoc scanning produces unverified findings and missed attack surface. This Skill provides a structured, phase-by-phase external penetration testing workflow that covers the full engagement lifecycle with reproducible evidence for every finding.
Core Features & Use Cases
- Full PTES Methodology Coverage: Guides pre-engagement scoping, passive and active reconnaissance, vulnerability analysis, exploitation, post-exploitation, and reporting with concrete commands for each phase.
- Commonly Missed Attack Surface Checklist: Highlights frequently skipped vectors such as VPN edge appliances, UDP services, default credentials on admin panels, cloud storage exposure, and lockout-safe password spraying.
- Evidence-Based Reporting: Provides CVSS v3.1 finding classification, report structure templates, and remediation priority matrices tied to timelines.
- Use Case: A security consultant is engaged to test a client's perimeter. Using this Skill, they enumerate subdomains with subfinder and amass, scan with Nmap and Nuclei, validate CVEs against identified service versions, exploit confirmed weaknesses with Metasploit, and deliver a report where every finding includes proof of exploitation.
Quick Start
Ask the AI to perform an external network penetration test against your authorized target scope following the PTES methodology, starting with reconnaissance and subdomain enumeration.