vulnerability-reports.md (7754B)
1 --- 2 title: "Vulnerability Reports" 3 section: "Methodology" 4 sectionSlug: "methodology" 5 sourcePath: "docs/methodology/vulnerability-reports.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/methodology/vulnerability-reports.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Vulnerability Reports 12 13 > A pentest vulnerability report documents the findings of a penetration test, detailing identified security weaknesses, their potential impact, and remediation steps. It is critical for informing stakeholders about the security posture of their systems, prioritizing vulnerabilities, and guiding mitigation efforts. Effective reports enhance overall security by providing actionable insights to prevent exploitation. 14 15 ## Tools 16 17 Tools to help you collaborate and generate your reports. 18 19 * [GhostManager/Ghostwriter](https://github.com/GhostManager/Ghostwriter) - The SpecterOps project management and reporting engine 20 * [pwndoc/pwndoc](https://github.com/pwndoc/pwndoc) - Pentest Report Generator 21 22 List of penetration test reports and templates. 23 24 * [reconmap/pentest-reports](https://github.com/reconmap/pentest-reports) - Collection of penetration test reports and pentest report templates. 25 * [juliocesarfort/public-pentesting-reports](https://github.com/juliocesarfort/public-pentesting-reports) - A list of public penetration test reports published by several consulting firms and academic security groups. 26 * [xanhacks/web-pentest-reports](https://gitlab.com/xanhacks/web-pentest-reports) - List of template vulnerability reports for web pentesting. 27 * [noraj/OSCP-Exam-Report-Template-Markdown](https://github.com/noraj/OSCP-Exam-Report-Template-Markdown) - Markdown Templates for Offensive Security OSCP, OSWE, OSCE, OSEE, OSWP exam report. 28 29 ## Vulnerability Report Structure 30 31 * Executive Summary 32 * Security Findings and Recommendations 33 * Vulnerabilities (sorted by severity) 34 * Appendix (optional) 35 36 ## Vulnerability Details Structure 37 38 * **Summary**: a concise introduction to the vulnerability, providing a snapshot of the issue and its potential reach.. 39 * **Impact**: detailed insights into the potential business ramifications that could arise from exploiting this vulnerability. 40 * **Reproductions Steps**: a comprehensive, step-by-step walkthrough on how to replicate the issue,, complete with screenshots, HTTP requests or Proof of Concept code snippets. 41 * **Recommendations**: suggestions and best practices for addressing and resolving the highlighted issue. 42 * **References**: links to external content, documentation, and security guidelines, including resources like OWASP. 43 * **Severity**: Include a severity score like CVSS. 44 45 ## General Guidelines 46 47 * Use a **Passive Voice Form**. 48 * **Obfuscate** the secrets and Personal Identifiable Information: `passwords`, `token`, Identity cards, Pictures ... 49 * Include **captions** for all figures and images. 50 * Apply **shadows** to images to enhance their visual appeal. 51 * Customize the report for technical and non-technical stakeholders, ensuring clarity and comprehensibility for all readers. 52 * Explain the **business impact** and context of vulnerabilities to help prioritize remediation efforts effectively. 53 * Include **positive security practices** and areas of improvement to provide a balanced view. 54 55 ## Common Mistakes 56 57 * **Edit the pictures** before importing them in the document: 58 * A cropped picture can be `uncropped` inside the Word document 59 * Word drawings added on top of the image can be removed, and the image is still present unobfuscated inside the Word archive 60 * Most of the time you don't `blur` enough the picture, it is always better to **add a dark/red square** on top of the data you want to obfuscate. 61 62 * Unreadable screenshots 63 * Keep only the necessary elements in the screenshot 64 * Texts in the screenshot should be readable: not too long, not too small 65 * Avoid dark mode screenshots: people prints reports 66 * Don't use a transparent shell 67 * Highlight the important parts of the screenshot: [flameshot-org/flameshot](https://github.com/flameshot-org/flameshot), [greenshot/greenshot](https://github.com/greenshot/greenshot) 68 * Include the command string in the screenshot: `./exploit.py argument1 -verbose` 69 * Consider narrowing down the shell/browser windows for the screenshot: it will be inserted in "portrait mode" document (PDF). 70 71 * Always **distribute a PDF** file to your customer, not a Word, LaTeX or Markdown file 72 * Word is an archive file, you can rename it as .zip to explore the content 73 * For sensitive files, you might want to **add a password** on the file 74 75 * Sending data on a uncontrolled LLM 76 * Using a **LOCAL** Large Language Model to help you is fine. For example, you can use `ollama` + `openwebui` + `llama3` model on an on-premise machine disconnected from Internet 77 * Never send customer data or sensitive information on ChatGPT, Mistral AI, Gemini, etc, you don't know how the data will be processed and stored. 78 79 * Neglecting **Proof of Concepts** (PoCs) 80 * Failing to include PoCs or detailed reproduction steps can hinder the remediation process. 81 * If the PoC is small, like a `curl` command, add it inside the Reproductions Steps. Otherwise add it to the Appendix and reference it inside the Reproductions Steps. 82 83 * Bad writing 84 * Typos/Mispellings: use a writing aid 85 * Poor grammar 86 * Too much jargon 87 * Convoluted sentences 88 * No clear narrative, the report should tell a story. 89 * Avoid emotionally loaded terms: awful, bad, good, etc. 90 * Specify and quantify whenever possible, e.g: replace "several" by the amount of affected systems. 91 92 * Lists 93 * Lists should be sorted alphabetically, numerically, by octet or by domain 94 * De-duping your list 95 96 ## Template Improvement 97 98 * Use headings to format the document 99 * Create and use templates, custom styles: 100 * One custom style for inline code: `./myprogram -debug` 101 * One custom style for code block, including syntax highlighting and darker background. 102 103 ```java 104 // Your First Program 105 class HelloWorld { 106 public static void main(String[] args) { 107 System.out.println("Hello, World!"); 108 } 109 } 110 ``` 111 112 ## References 113 114 * [Best Practices for Writing Quality Vulnerability Reports - Krzysztof Pranczk](https://itnext.io/best-practices-for-writing-quality-vulnerability-reports-119882422a27) 115 * [Overview of technical writing courses - Google Technical Writing](https://developers.google.com/tech-writing/overview) 116 * [Part 1 - Things NOT to Do in Pentest Reports: Tips, Tricks, & Traps in Report Writing - Bronwen Aker- Feb 6, 2023](https://youtu.be/eWNqaFf60fg) 117 * [Part 2 - Things NOT to Do in Pentest Reports: Tips, Tricks, & Traps in Report Writing - Bronwen Aker- Feb 7, 2023](https://www.youtube.com/watch?v=2Op9Q2CY2lA) 118 * [Part 3 - Things NOT to Do in Pentest Reports: Tips, Tricks, & Traps in Report Writing - Bronwen Aker- Feb 7, 2023](https://www.youtube.com/watch?v=mZom07etvSk) 119 * [Part 1 - Professional Pentest Reporting - A Model for Clear Communication - Brian (BB) King - May 16, 2023](https://youtu.be/rM-MVSe4MiA) 120 * [Part 2 - Professional Pentest Reporting - A Model for Clear Communication - Brian (BB) King - May 17, 2023](https://www.youtube.com/watch?v=Uu3pardnHiI) 121 * [BHIS | Hack for Show, Report For Dough: Part 2 w/ BB King (1-Hour) - Brian (BB) King - Oct 28, 2021](https://youtu.be/bJ4gJVXPAS0) 122 * [Sort Your Lists - Penetration Test Reporting Tips - Bronwen Aker - Aug 15, 2022](https://br0nw3n.com/2022/08/sort-your-lists-penetration-test-reporting-tips/) 123 * [Things NOT to Do in Your Pentest Report | Offensive Con 2023 - Bronwen Aker - Aug 17, 2023](https://youtu.be/o2MOuM4JF4U)