daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

vulnerability-reports.md (7754B)


      1 ---
      2 title: "Vulnerability Reports"
      3 section: "Methodology"
      4 sectionSlug: "methodology"
      5 sourcePath: "docs/methodology/vulnerability-reports.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/methodology/vulnerability-reports.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Vulnerability Reports
     12 
     13 > A pentest vulnerability report documents the findings of a penetration test, detailing identified security weaknesses, their potential impact, and remediation steps. It is critical for informing stakeholders about the security posture of their systems, prioritizing vulnerabilities, and guiding mitigation efforts. Effective reports enhance overall security by providing actionable insights to prevent exploitation.
     14 
     15 ## Tools
     16 
     17 Tools to help you collaborate and generate your reports.
     18 
     19 * [GhostManager/Ghostwriter](https://github.com/GhostManager/Ghostwriter) - The SpecterOps project management and reporting engine
     20 * [pwndoc/pwndoc](https://github.com/pwndoc/pwndoc) - Pentest Report Generator
     21 
     22 List of penetration test reports and templates.
     23 
     24 * [reconmap/pentest-reports](https://github.com/reconmap/pentest-reports) - Collection of penetration test reports and pentest report templates.
     25 * [juliocesarfort/public-pentesting-reports](https://github.com/juliocesarfort/public-pentesting-reports) - A list of public penetration test reports published by several consulting firms and academic security groups.
     26 * [xanhacks/web-pentest-reports](https://gitlab.com/xanhacks/web-pentest-reports) - List of template vulnerability reports for web pentesting.
     27 * [noraj/OSCP-Exam-Report-Template-Markdown](https://github.com/noraj/OSCP-Exam-Report-Template-Markdown) - Markdown Templates for Offensive Security OSCP, OSWE, OSCE, OSEE, OSWP exam report.
     28 
     29 ## Vulnerability Report Structure
     30 
     31 * Executive Summary
     32 * Security Findings and Recommendations
     33 * Vulnerabilities (sorted by severity)
     34 * Appendix (optional)
     35 
     36 ## Vulnerability Details Structure
     37 
     38 * **Summary**: a concise introduction to the vulnerability, providing a snapshot of the issue and its potential reach..
     39 * **Impact**: detailed insights into the potential business ramifications that could arise from exploiting this vulnerability.
     40 * **Reproductions Steps**: a comprehensive, step-by-step walkthrough on how to replicate the issue,, complete with screenshots, HTTP requests or Proof of Concept code snippets.
     41 * **Recommendations**: suggestions and best practices for addressing and resolving the highlighted issue.
     42 * **References**: links to external content, documentation, and security guidelines, including resources like OWASP.
     43 * **Severity**: Include a severity score like CVSS.
     44 
     45 ## General Guidelines
     46 
     47 * Use a **Passive Voice Form**.
     48 * **Obfuscate** the secrets and Personal Identifiable Information: `passwords`, `token`, Identity cards, Pictures ...
     49 * Include **captions** for all figures and images.
     50 * Apply **shadows** to images to enhance their visual appeal.
     51 * Customize the report for technical and non-technical stakeholders, ensuring clarity and comprehensibility for all readers.
     52 * Explain the **business impact** and context of vulnerabilities to help prioritize remediation efforts effectively.
     53 * Include **positive security practices** and areas of improvement to provide a balanced view.
     54 
     55 ## Common Mistakes
     56 
     57 * **Edit the pictures** before importing them in the document:
     58     * A cropped picture can be `uncropped` inside the Word document
     59     * Word drawings added on top of the image can be removed, and the image is still present unobfuscated inside the Word archive
     60     * Most of the time you don't `blur` enough the picture, it is always better to **add a dark/red square** on top of the data you want to obfuscate.
     61 
     62 * Unreadable screenshots
     63     * Keep only the necessary elements in the screenshot
     64     * Texts in the screenshot should be readable: not too long, not too small
     65     * Avoid dark mode screenshots: people prints reports
     66     * Don't use a transparent shell
     67     * Highlight the important parts of the screenshot: [flameshot-org/flameshot](https://github.com/flameshot-org/flameshot), [greenshot/greenshot](https://github.com/greenshot/greenshot)
     68     * Include the command string in the screenshot: `./exploit.py argument1 -verbose`
     69     * Consider narrowing down the shell/browser windows for the screenshot: it will be inserted in "portrait mode" document (PDF).
     70 
     71 * Always **distribute a PDF** file to your customer, not a Word, LaTeX or Markdown file
     72     * Word is an archive file, you can rename it as .zip to explore the content
     73     * For sensitive files, you might want to **add a password** on the file
     74 
     75 * Sending data on a uncontrolled LLM
     76     * Using a **LOCAL** Large Language Model to help you is fine. For example, you can use `ollama` + `openwebui` + `llama3` model on an on-premise machine disconnected from Internet
     77     * Never send customer data or sensitive information on ChatGPT, Mistral AI, Gemini, etc, you don't know how the data will be processed and stored.
     78 
     79 * Neglecting **Proof of Concepts** (PoCs)
     80     * Failing to include PoCs or detailed reproduction steps can hinder the remediation process.
     81     * If the PoC is small, like a `curl` command, add it inside the Reproductions Steps. Otherwise add it to the Appendix and reference it inside the Reproductions Steps.
     82 
     83 * Bad writing
     84     * Typos/Mispellings: use a writing aid
     85     * Poor grammar
     86     * Too much jargon
     87     * Convoluted sentences
     88     * No clear narrative, the report should tell a story.
     89     * Avoid emotionally loaded terms: awful, bad, good, etc.
     90     * Specify and quantify whenever possible, e.g: replace "several" by the amount of affected systems.
     91 
     92 * Lists
     93     * Lists should be sorted alphabetically, numerically, by octet or by domain
     94     * De-duping your list
     95 
     96 ## Template Improvement
     97 
     98 * Use headings to format the document
     99 * Create and use templates, custom styles:
    100     * One custom style for inline code: `./myprogram -debug`
    101     * One custom style for code block, including syntax highlighting and darker background.
    102 
    103         ```java
    104         // Your First Program
    105         class HelloWorld {
    106             public static void main(String[] args) {
    107                 System.out.println("Hello, World!"); 
    108             }
    109         }
    110         ```
    111 
    112 ## References
    113 
    114 * [Best Practices for Writing Quality Vulnerability Reports - Krzysztof Pranczk](https://itnext.io/best-practices-for-writing-quality-vulnerability-reports-119882422a27)
    115 * [Overview of technical writing courses - Google Technical Writing](https://developers.google.com/tech-writing/overview)
    116 * [Part 1 - Things NOT to Do in Pentest Reports: Tips, Tricks, & Traps in Report Writing - Bronwen Aker- Feb 6, 2023](https://youtu.be/eWNqaFf60fg)
    117 * [Part 2 - Things NOT to Do in Pentest Reports: Tips, Tricks, & Traps in Report Writing - Bronwen Aker- Feb 7, 2023](https://www.youtube.com/watch?v=2Op9Q2CY2lA)
    118 * [Part 3 - Things NOT to Do in Pentest Reports: Tips, Tricks, & Traps in Report Writing - Bronwen Aker- Feb 7, 2023](https://www.youtube.com/watch?v=mZom07etvSk)
    119 * [Part 1 - Professional Pentest Reporting - A Model for Clear Communication - Brian (BB) King - May 16, 2023](https://youtu.be/rM-MVSe4MiA)
    120 * [Part 2 - Professional Pentest Reporting - A Model for Clear Communication - Brian (BB) King - May 17, 2023](https://www.youtube.com/watch?v=Uu3pardnHiI)
    121 * [BHIS | Hack for Show, Report For Dough: Part 2 w/ BB King (1-Hour) - Brian (BB) King - Oct 28, 2021](https://youtu.be/bJ4gJVXPAS0)
    122 * [Sort Your Lists - Penetration Test Reporting Tips - Bronwen Aker - Aug 15, 2022](https://br0nw3n.com/2022/08/sort-your-lists-penetration-test-reporting-tips/)
    123 * [Things NOT to Do in Your Pentest Report | Offensive Con 2023 - Bronwen Aker - Aug 17, 2023](https://youtu.be/o2MOuM4JF4U)