Skip to content

Methodology

Frameworks that give an engagement structure, so testing is repeatable, defensible, and mapped to recognized standards.

Why It Matters

A methodology keeps an engagement consistent from tester to tester, makes sure phases are not skipped under time pressure, and gives findings a shared vocabulary that clients and blue teams already understand. Many compliance requirements also expect testing to follow a recognized framework.

Frameworks

Framework Use
MITRE ATT&CK Catalog of adversary tactics and techniques, used to plan coverage and map findings to real behavior
PTES Penetration Testing Execution Standard: an end-to-end engagement model from pre-engagement to reporting
OWASP Testing Guide Standard methodology for web application testing
NIST SP 800-115 Technical guide to information security testing and assessment
SANS SANS penetration testing framework and resources

How I Use It

I pick the framework that fits the engagement: ATT&CK to plan and report technique coverage, the OWASP Testing Guide for web app work, and PTES as the overall spine from scoping through reporting. The framework keeps the work organized; the technique pages in the other sections are how each phase gets executed.