Skip to content

SANS

The SANS penetration testing framework: a structured, widely taught methodology for conducting an engagement end to end.

Why It Matters

The SANS framework covers the same ground as PTES with an explicit cleanup phase at the end, which is a useful reminder that an engagement is not finished until tools and artifacts are removed and the environment is restored.

Reference

Phases

Phase What Happens
Pre-engagement Define scope, goals, and rules of engagement
Intelligence Gathering Collect information about the target environment
Threat Modeling Identify likely attack vectors and scenarios
Vulnerability Analysis Assess the environment for vulnerabilities
Exploitation Exploit identified vulnerabilities to gain access
Post-Exploitation Maintain access and escalate privileges
Reporting Document findings and recommend remediation
Cleanup Remove tools and artifacts, restore the environment

How I Use It

I use the SANS phases much like PTES, and I keep the cleanup phase explicit on my own checklist: every tool dropped, account created, or change made during the test gets recorded so it can be removed and reported.

Resources