What problem does it solve?
Creates a clear, auditable engagement plan before any tools or scans are run, removing uncertainty about scope, required phases, and tracking artifacts across a pentest lifecycle.
Core Features & Use Cases
- Interactive scoping: Prompts the user for quick vs full mode, target domain/IP, and in-scope/out-of-scope notes.
- Automated artifact initialization: Generates a plan.md and a session.json that initialize the Pentest Task Tree (PTT) and session tracking.
- Phase handoff guidance: Defines how subsequent phases should update session.json so recon, secrets, exploit, triage, and report phases can consume and append structured findings.
- Use Case: Start a new bug bounty or red team engagement, choose Quick mode to jump straight to recon, or Full mode to create a persistent results directory and tracking artifacts.
Quick Start
Start a full engagement plan for example.com in Full mode with scope "in-scope: example.com".