Part 3—Things NOT to Do in Pentest Reports: Tips, Tricks, & Traps in Report Writing | Bronwen Aker

preview_player
Показать описание


Ever wonder what makes the difference between just a pentest report and a great pentest report? Doing testing well is important, but your report is the product you deliver and there are lots of ways you can shoot yourself in the foot without meaning to. Poor word choices, unreadable screenshots, and too much jargon are common mistakes that will destroy the value of your report. And that is an easy way to ruin your credibility as a professional pentester. Take your pentest reports to the next level by hacking them as if they were an unpatched server using default creds!

Chapters
00:00 - Part 3 Begin: #5. Random Lists
00:39 - Word Sucks at Sorting Lists
01:30 - Ways to Improve Your Lists
03:18 - 6. Irrelevant Guidance
05:08 - 7. Info From Another Customer
06:11 - Other Tips & Tricks
10:06 - But Wait! There’s More!
11:05 - At the End of the Day
12:03 - Remember…
12:53 - Conclusions
14:55 - BONUS Rapid Fire Questions

Black Hills Infosec Socials

Black Hills Infosec Shirts & Hoodies

Black Hills Infosec Services

Backdoors & Breaches - Incident Response Card Game

Antisyphon Training

Educational Infosec Content

Рекомендации по теме
Комментарии
Автор

I think this talk/series is an absolute goldmine. One sad thing I've come across multiple times is that some pentesters just don't seem to take anything to do with communication/psychology serious or don't see it as the job. So you definitely need a management that's backing the QA process and people 100%

bilmantender
Автор

Thank you so much for your time on this, Bronwen (and BHIS).. this really did teach me a good bit that I will definitely be using in the future.

RVZORBVCK
Автор

Your eyes WILL skate over typos on a screen but not on a page. There's something about the texture of actual paper that pulls you to it and creates the minor friction you need to not skip along so fast. That friction helps you find problems.

vcbgljn
Автор

I really enjoyed this talk, I learned so much thanks everyone for this great content. How can I join future webcasts?

bigbooduh