≈1.1k tokens on demand. Your agent reads this file only when SKILL.md points to it.
Penetration Testing Methodology Pitfalls
Purpose: Use this file when designing a penetration workflow, validating rules of engagement, or checking whether a test plan is too narrow, too tool-driven, or too weakly evidenced.
Contents
PT-01..PT-10
- Phase-by-phase failure patterns
- Methodology comparison
- 2025 attack surfaces
- Probe quality gates
Top Methodology Pitfalls
| ID |
Anti-pattern |
Risk |
Correction |
PT-01 |
Narrow scope |
Critical assets stay untested |
Map the full attack surface and prioritize business-critical assets |
PT-02 |
Test without written authorization |
Legal and ethical exposure |
Require rules of engagement and approval before testing |
PT-03 |
Skip threat modeling |
Random testing, weak attack chains |
Use ATT&CK-informed threat scenarios |
PT-04 |
Over-rely on scanners |
False positives and missed logic flaws |
Combine automated scanning with manual validation |
PT-05 |
Stop at detection |
No proof of exploitability or impact |
Build a safe detect -> exploit -> impact chain |
PT-06 |
Skip post-exploitation thinking |
Lateral movement risk stays hidden |
Assess privilege escalation and impact paths safely |
PT-07 |
Use one framework only |
Coverage bias |
Prefer a polymethodology approach |
PT-08 |
Produce a technical-only report |
Stakeholders cannot act |
Provide executive and technical layers |
PT-09 |
Skip retest after remediation |
Fix quality stays unknown |
Retest confirmed issues after remediation |
PT-10 |
Keep plans static |
New attack surfaces stay untested |
Refresh plans for cloud, API, supply chain, and AI changes |
Phase Failure Patterns
| Phase |
Common failures |
| Pre-engagement |
No written scope, no exclusions, no escalation path |
| Intelligence gathering |
No OSINT, no subdomain inventory, no stack fingerprinting |
| Exploitation |
No safe proof, no attack chain, weak evidence capture |
| Reporting |
No business impact, no remediation, no executive summary |
Methodology Comparison
| Framework |
Best use |
Currency (2026-05) |
PTES |
Lifecycle management and end-to-end pentest structure |
2014 baseline still widely cited; supplement with newer guides |
OWASP WSTG |
Web and API technical checks |
v4.2 (2020-12) remains the current stable; v5.0 in active development at github.com/OWASP/wstg to absorb 2026 AI / WebSocket / serverless realities. No v4.3 has shipped — do not cite it. |
MITRE ATT&CK |
Threat-based scenario design |
Refresh quarterly from attack.mitre.org |
NIST SP 800-115 |
Compliance-heavy environments |
2008 baseline; pair with NIST SP 800-218 SSDF for CI/CD gates |
OWASP Top 10 for LLM 2025 v2.0 |
Generative-AI app surfaces |
Released 2024-11-18 (genai.owasp.org); use for any LLM-backed endpoint |
OWASP Top 10 for Agentic Applications |
Autonomous AI agents |
Released 2025-12-09 by OWASP GenAI Security Project; ASI01 Agent Goal Hijacking tops the list |
Recommended default: PTES + OWASP WSTG v4.2 + MITRE ATT&CK. Add OWASP Top 10 for LLM 2025 and OWASP Top 10 for Agentic Applications whenever the target embeds LLMs, tool-calling agents, or MCP servers.
2026 Attack Surface Priorities
| Area |
Why it matters (2026-05 evidence) |
| API ecosystems |
Wallarm 2026 API ThreatStats: 43% of 2025 CISA KEV additions were API-related (106 / 245); 97% of API vulns exploitable in a single request; BOLA still tops the volume chart |
| Cloud-native services |
IAM, serverless, and instance-metadata exposures still rising — pair with nuclei cloud-config templates for GCP / Azure / K8s |
| Supply chain |
OWASP A03:2025 Software Supply Chain Failures expanded scope to dependency, build, and CI trust chains; Trivy v0.69.4 incident (2026-03) and dual GitHub Actions compromise illustrate the risk profile |
| AI / LLM / Agent integrations |
Wallarm: 2,185 AI-related vulns in 2025, 36% overlap with API vulns; 315 MCP-related vulns with 270% Q2→Q3 growth. Prompt injection (LLM01), indirect injection via RAG, and ASI01 Agent Goal Hijacking now belong in every API-scoped pentest plan |
Probe Quality Gates
| Condition |
Required action |
| No written authorization |
Block the engagement |
| No threat model |
Warn and add scenario design before scanning |
| Automation only |
Add manual validation for business logic |
| No exploit proof |
Mark as Unconfirmed |
| No executive summary |
Report is incomplete |