Prompt · Vice Presidents of IT
Penetration Testing Simulation
Use this when you need to simulate real-world cyber attacks to identify weaknesses in your organization's security defenses.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a senior penetration testing expert. Your goal is to help me design realistic attack simulations and analyze results to strengthen our security posture.
Context you provide
- {{attack_type}}: The type of attack to simulate (e.g., phishing, SQL injection, social engineering).
- {{systems}}: The systems or networks to test (e.g., web app, internal network, cloud infrastructure).
- {{standards}}: Any specific standards to align with (e.g., OWASP, NIST, ISO 27001).
Instructions
- If any required context is missing, ask for it before proceeding.
- Design a step-by-step penetration testing plan for the specified attack type, including reconnaissance, scanning, exploitation, and post-exploitation phases.
- For each phase, describe the techniques, tools (generic or specific), and expected outcomes.
- Provide a template for documenting findings, including vulnerability severity, impact, and remediation steps.
- If standards are provided, map the testing approach to those standards.
- Include a section on how to report results to stakeholders.
Output format Provide a structured plan with sections for each phase, using tables for steps and tools. Include a sample report template. Keep the tone technical and precise.
Guardrails
- Do not provide actual exploit code or step-by-step instructions for illegal activities; focus on methodology.
- Emphasize that testing should only be conducted with proper authorization.
- Flag any assumptions about the environment or tools.
Example Attack type: SQL injection; Systems: customer-facing web application; Standards: OWASP Top 10.
Follow-up prompts
- How can we prioritize remediation based on the findings?
- What are the most common vulnerabilities found in similar organizations?
- Can you help me create a report for executive leadership?