logo

How to Not Suck at Reporting (or How to Write Great Pentesting Reports)

ID: 28b11c2f-bdf7-508b-b612-0874043e17d4

STIX ID: report--28b11c2f-bdf7-508b-b612-0874043e17d4

Feed Name: Black Hills Infosec Blog

Date Published: 2016-10-24

Date Updated: 2026-04-27

Author: BHIS

...
...

**Executive Summary:** This guide outlines best practices for penetration testing reporting, stressing the use of the scientific method, clear storytelling for each vulnerability, writing as you go, organized presentation, illustrative (and redacted) screenshots, consistent voice and tense, careful grammar, and a two-tier peer review process to ensure technical accuracy and readability.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.