Course overview
Lesson 2 of 8 · 3 promptsAI for Penetration Testers
LESSON 02 OF 8

Recon And Scan Triage

3 prompts for Penetration Testers

Prompts for Penetration Testers: copy one, fill it in, paste it into your AI.

Track progress as a member

In this lesson

  1. 01Summarize Vulnerability Scan ResultsUse this when you have a large vulnerability scan export and need key findings, affected hosts, and likely severity grouped for triage.
  2. 02Prioritize Scan Findings By ExploitabilityUse this when you need to rank scan findings by real-world attack path rather than raw CVSS alone.
  3. 03Draft Recon Checklist For TargetUse this when you are starting a new engagement and need a repeatable list of DNS, subdomain, and service checks.
1Copy the promptClick Copy on the prompt you need.
2Paste it into your AIChatGPT, Claude, Gemini or Copilot.
3Fill in the {{brackets}}Your own details, or let the AI ask you.
4Follow up and checkUse the follow-ups, then check the facts.
01

Summarize Vulnerability Scan Results

Use this when you have a large vulnerability scan export and need key findings, affected hosts, and likely severity grouped for triage.

Prompt

Role You are a penetration testing lead who turns raw vulnerability scan exports into a prioritized triage summary. Optimize for accurate grouping, clear severity, and defensible next steps.

Context you provide

  • {{scan_export}}: pasted scan output, CSV, or row list
  • {{scan_tool}}: scanner name and version, if known
  • {{scope}}: hosts, subnets, or asset groups included
  • {{business_context}}: critical services, data sensitivity, internet exposure
  • {{severity_source}}: vendor severity, CVSS, or internal rating scale
  • {{remediation_window}}: SLA or deadline for fixes
  • {{audience}}: client contact, engineer, or manager
  • {{output_length}}: target word or page count

Instructions

  1. Ask for any missing inputs, then wait for my reply before analyzing.
  2. Parse the scan export and remove duplicate rows and informational noise.
  3. Group findings by affected host and by vulnerability class.
  4. Map each finding to the stated severity source without inventing scores or IDs.
  5. Separate confirmed exploitable issues from items needing manual validation.
  6. Rank hosts by exposure and business impact using the context given.
  7. Note scanner gaps, credential failures, or unreachable hosts.

Output format

  • Executive summary: 3 to 5 bullets, plain language.
  • Host table: host, key findings, severity, status.
  • Findings grouped by severity: name, affected hosts, evidence, recommended fix.
  • Gaps and assumptions section.
  • Next steps in priority order.
  • Keep tone factual. Omit raw banner grabs and unrelated scanner warnings.

Guardrails

  • Do not invent CVE IDs, CVSS scores, hostnames, or product names; mark unknown data as unknown.
  • Flag any finding that needs manual validation before it goes to the client.
  • Remind me to confirm written authorization and check vendor advisories before retesting.

Example {{scan_export}} = scanner CSV, 412 rows; {{scope}} = 10.20.0.0/24; {{severity_source}} = CVSS v3.1 base.

Open as its own page

02

Prioritize Scan Findings By Exploitability

Use this when you need to rank scan findings by real-world attack path rather than raw CVSS alone.

Prompt

Role You are a penetration testing lead triaging vulnerability scan results. You optimise for ranking findings by real-world exploitability and attack path, not raw severity scores alone.

Context you provide

  • {{scan_findings}} - raw output from vulnerability scanner, including host, port, service, and finding description.
  • {{asset_inventory}} - list of in-scope hosts with roles, criticality, and owner.
  • {{network_topology}} - diagram or description of network segments, trust boundaries, and reachable paths.
  • {{business_context}} - what the systems do, data sensitivity, and outage tolerance.
  • {{compensating_controls}} - existing controls such as firewalls, segmentation, EDR, or authentication requirements.
  • {{exploit_availability}} - known public exploits or proof-of-concept code for the findings.
  • {{cvss_scores}} - base scores from the scanner or your own scoring.
  • {{previous_findings}} - related issues from past assessments that affect exploitability.

Instructions

  1. Ask for any missing inputs, then confirm scope and rules of engagement.
  2. Parse the scan findings and map each to assets and services.
  3. For each finding, assess exploitability by considering attack vector, access required, exploit maturity, and whether compensating controls block the path.
  4. Build attack paths that chain findings where one enables another.
  5. Rank findings into tiers: critical (direct pre-auth remote code execution or trivial credential abuse on a critical asset), high (exploitable with low effort or chained to critical), medium (requires authenticated access or specific conditions), low (theoretical or blocked by controls).
  6. Explain the reasoning for each tier.
  7. Recommend validation steps for top-tier findings.
  8. Output a prioritized list.

Output format Provide a ranked table or numbered list with columns: rank, finding, asset, exploitability rating, attack path summary, recommended validation. Tone: concise, factual, for a technical client. Length: under 600 words unless asked. Leave out generic scanner output and unverified assumptions.

Guardrails

  • Do not invent CVE IDs, CVSS scores, or exploit code.
  • Flag any assumption about network reachability or controls as needing confirmation.
  • Tell the user to validate findings manually before reporting to the client.

Example scan_findings=scanner_output.csv, asset_inventory=web-servers.csv, network_topology=dmz-to-internal.pdf, business_context=payment processing, compensating_controls=WAF and MFA on admin portal, exploit_availability=public exploit for the identified service version, cvss_scores=from scanner, previous_findings=none.

Open as its own page

03

Draft Recon Checklist For Target

Use this when you are starting a new engagement and need a repeatable list of DNS, subdomain, and service checks.

Prompt

Role You are a penetration testing assistant that drafts reconnaissance checklists for security engagements. Optimise for thoroughness, repeatability, and clear sequencing.

Context you provide

  • {{target_domain}}: primary domain or IP range to assess.
  • {{engagement_scope}}: authorized scope, including any excluded hosts or networks.
  • {{known_subdomains}}: any subdomains already identified, if any.
  • {{dns_servers}}: DNS servers to query for enumeration.
  • {{service_ports}}: specific ports or service types to scan.
  • {{available_tools}}: tools or scripts you can use.
  • {{time_budget}}: maximum time for reconnaissance.

Instructions

  1. Ask for any missing inputs, then draft a reconnaissance checklist.
  2. Organize the checklist into three sections: DNS enumeration, subdomain discovery, and service scanning.
  3. For each section, list specific checks or command patterns to run, using placeholders for target-specific values.
  4. Include a brief note on what to record for each check (e.g., output, timestamps, anomalies).
  5. Add a final review section to consolidate findings and prioritize follow-up actions.
  6. Keep the checklist tool-agnostic but reference common tool categories where helpful.
  7. Ensure the checklist is repeatable and can be adapted to different targets.

Output format Provide the checklist as a markdown document with three main sections (DNS, Subdomains, Services) and a final review section. Use bullet points and numbered lists. Keep each item concise, one line per check. Tone: professional, direct, instructional. Length: around 300 to 500 words. Leave out explanations of why each check matters; focus on actions. Do not include specific tool names unless provided in inputs.

Guardrails

  • Do not invent domain names, IP addresses, or tool commands that are not derived from the provided inputs.
  • Flag any assumptions about scope or permissions.
  • Remind the user to verify that all reconnaissance activities are within the authorized scope and comply with engagement rules of engagement.

Example Target: example.com, Scope: *.example.com and 192.0.2.0/24, Known subdomains: www, mail, DNS servers: 8.8.8.8, Service ports: 80,443,22, Tools: dig, nmap, time budget: 2 hours.

Open as its own page

Skills for these tasks

Give your AI these skills and it does these tasks the expert way. Connect your AI once and it picks them up by itself.