00
About this phase
A strong deliverable speaks to two audiences at once. The executive summary tells leadership what the risk means to the business in plain language. The technical findings give engineers exactly what they need to reproduce and remediate each issue: evidence, affected systems, a clear risk rating, and concrete fix guidance. Good writing, accurate severity, and actionable remediation are what separate a useful report from a noisy one.
Severity ratings here lean on CVSS, and the overall structure follows the reporting guidance in NIST SP 800-115. Reporting is the phase too many testers treat as an afterthought — these lessons give it the weight it deserves, then hand you a tool to practice on.
Lessons
4 + tool
Phase
08 of 08
Status
Complete
01
Lessons & tools in this phase
08.01Live →
08.02Live →
08.03Live →
08.04Live →
LABLab →
Anatomy of a Pentest Report
The standard sections and what belongs in each — executive summary, methodology, attack narrative, findings, recommendations, and appendices — plus the process that turns notes into a deliverable.
Writing a Finding
Title, severity, observation, impact, evidence, affected assets, and remediation — the repeatable structure of a credible finding, what is not a finding, and the anti-patterns to avoid.
Executive Summary vs Technical Detail
Writing the same engagement for the boardroom and the engineering team — bridged by the attack narrative — without ever contradicting yourself.
Risk Rating & Remediation
Turning CVSS severity into prioritized business risk with likelihood and impact, and remediation that is outcome-focused and realistic to execute.
Report Builder
Compose a finding field by field, get its risk rated from likelihood and impact, and watch a live quality checker flag vague titles, missing evidence, exposed passwords, and product-naming remediation.