{"id":21400661,"url":"https://github.com/cybersecurityup/pentest-consulting-creator","last_synced_at":"2026-02-04T12:32:42.838Z","repository":{"id":59947664,"uuid":"540248407","full_name":"CyberSecurityUP/PenTest-Consulting-Creator","owner":"CyberSecurityUP","description":"Repository with some necessary information for you to create your PenTest consultancy","archived":false,"fork":false,"pushed_at":"2025-01-12T22:04:17.000Z","size":15533,"stargazers_count":98,"open_issues_count":0,"forks_count":38,"subscribers_count":3,"default_branch":"main","last_synced_at":"2025-07-11T18:28:47.958Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/CyberSecurityUP.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null}},"created_at":"2022-09-23T02:25:33.000Z","updated_at":"2025-06-10T06:19:42.000Z","dependencies_parsed_at":"2025-07-13T02:02:50.991Z","dependency_job_id":null,"html_url":"https://github.com/CyberSecurityUP/PenTest-Consulting-Creator","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/CyberSecurityUP/PenTest-Consulting-Creator","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/CyberSecurityUP%2FPenTest-Consulting-Creator","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/CyberSecurityUP%2FPenTest-Consulting-Creator/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/CyberSecurityUP%2FPenTest-Consulting-Creator/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/CyberSecurityUP%2FPenTest-Consulting-Creator/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/CyberSecurityUP","download_url":"https://codeload.github.com/CyberSecurityUP/PenTest-Consulting-Creator/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/CyberSecurityUP%2FPenTest-Consulting-Creator/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":29084355,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-02-04T03:31:03.593Z","status":"ssl_error","status_checked_at":"2026-02-04T03:29:50.742Z","response_time":62,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.5:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-11-22T15:23:30.796Z","updated_at":"2026-02-04T12:32:42.811Z","avatar_url":"https://github.com/CyberSecurityUP.png","language":null,"funding_links":[],"categories":[],"sub_categories":[],"readme":"# PenTest-Consulting-Creator\nRepository with some necessary information for you to create your PenTest consultancy\n\nPwnDoc is a pentest reporting application making it simple and easy to write your findings and generate a customizable Docx report.\n- https://github.com/pwndoc/pwndoc\n\nCurated list of public penetration test reports released by several consulting firms and academic security groups.\n- https://github.com/juliocesarfort/public-pentesting-reports\n\nPenTest Calculator Cost\n- https://go.cobalt.io/roi/\n- https://www.mangoldsecurity.com/cost-estimator/\n\nPenTest Checklist\n- https://pentestbook.six2dez.com/others/web-checklist\n- https://github.com/harshinsecurity/web-pentesting-checklist\n- https://github.com/Hari-prasaanth/Web-App-Pentest-Checklist\n- https://book.hacktricks.xyz/mobile-pentesting/ios-pentesting-checklist\n- https://book.hacktricks.xyz/mobile-pentesting/android-checklist\n\nPenTest Methodology\n\nPTES\n- http://www.pentest-standard.org/index.php/Main_Page\n\nOSSTMM\n- https://www.isecom.org/OSSTMM.3.pdf\n\nNIST 800-115\n- https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-115.pdf\n\nISSAF\n- http://cuchillac.net/archivos/pre_seguridad_pymes/2_hakeo_etico/lects/metodologia_oissg.pdf\n\nOWASP Test Guide\n- https://owasp.org/www-project-web-security-testing-guide/assets/archive/OWASP_Testing_Guide_v4.pdf\n\n## Timeline PenTest\n\nPlanning – Includes the contract execution, initial deposit, scheduling of resources, and review/agreement of the project Rules of Engagement (ROE).\n\nExecution – This phase is when active testing of all in-scope targets is set to occur – the length of this phase varies by project and is directly related to the size/scope of the assessment.\n\nAnalysis, Documentation, and Quality Assurance – 1 Week: Document preparation including the Executive Summary Report and Technical Findings Report. This phase may also include some minimal testing and manual interactions with the in-scope targets to validate findings identified during the original execution of the test or gather more detail.\n\nPresentation of Findings – 1 Day: Scheduled after all documentation and QA is complete, this is the final step to review findings, address questions, and wrap up the project.\n\n## Burocracy\n\n- Understand the bureaucratic part of the country you work in, whether in opening a company, even in providing services and the proper credentials to act.\n\n- Structure your portfolio of services well in PenTest, the types of tests you do and how you perform them, what methodology is used in each one?\n\n## Certifications\n\n- CEH\n- OSCP\n- eCPPT\n- eCPTX\n- eWPT\n- GPEN\n- GWAPT\n- CREST CPSA\n- CRTO\n- CRTL\n- OSWE\n- OSEP\n- CRTP\n- CARTP\n\n## Toolkits\n\n- What tools do you use?\n\n- Do you have trading tools?\n\n- Are there partnerships for the services you have? Whether to assist in the remediation, protection and mitigation of risk\n\n- How is the licensing of your tools? If you have a Burp, Cobalt Strike, Exploit Pack and others?\n\n## CVEs, CVSS, NVD\n\n- CVE \nIs a list of entries—each containing an identification number, a description, and at least one public reference—for publicly known cybersecurity vulnerabilities. CVE does not provide severity scoring or prioritization ratings for software vulnerabilities.\n\n- CVSS\nOperated by the Forum of Incident Response and Security Teams (FIRST) used to score the severity of software vulnerabilities identified by CVE Entries.\n\n- NVD NIST\nProvides a free CVSS calculator for CVE Entries.\n\n- Report your CVE\nWhen you find a 0day you can report this vulnerability to the company that owns the solution or a third party depending on the case, so waiting for a positive result and get your cve depending on the vulnerability\n\nTutorial Report\nhttps://drive.google.com/file/d/1pfZbOm_dExehIqGHLPtjWm2GJ4UUMMJK/view?usp=sharing\n\n## PenTest Report Writing\n\n- https://www.youtube.com/watch?v=J34DnrX7dTo\n- https://www.youtube.com/watch?v=NEz4SfjjwvU\n- https://www.youtube.com/watch?v=6QIrXgPGJhM\n- https://www.cobalt.io/blog/how-to-write-an-effective-pentest-report-vulnerability-reports\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcybersecurityup%2Fpentest-consulting-creator","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fcybersecurityup%2Fpentest-consulting-creator","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcybersecurityup%2Fpentest-consulting-creator/lists"}