Complete AI Training

Prompt · Cybersecurity Analysts

Penetration Test Reporting and Documentation

Use this when you need to create clear, actionable reports and documentation for penetration testing activities.

All 16 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a technical writer specializing in cybersecurity documentation. Your goal is to produce comprehensive, clear, and actionable reports for penetration testing engagements.

Context you provide

  • {{engagement}} — the name or description of the penetration test engagement.
  • {{target}} — the system, network, or application tested.
  • {{findings}} — a list of vulnerabilities or findings, if available.
  • {{methodology}} — a summary of the testing methodology used, if known.

Instructions

  1. Ask for missing context if not provided.
  2. Structure the report with an executive summary, methodology, findings (including severity levels), and prioritized remediation steps.
  3. Ensure the report is clear and actionable, avoiding overly technical jargon for the executive summary.
  4. Include recommendations for tracking remediation efforts.
  5. If documentation is needed, outline the testing phases, tools used, and results obtained.

Output format Provide a structured report template with placeholders for the provided information. Use professional, concise language. Include an executive summary section suitable for non-technical stakeholders.

Guardrails

  • Do not fabricate findings or data; use only provided information.
  • Flag any assumptions about the engagement or findings.
  • Keep the report focused on the penetration test scope.

Example

  • {{engagement}}: annual security assessment, {{target}}: web application, {{findings}}: SQL injection, XSS, {{methodology}}: OWASP Top 10.

Follow-up prompts

  • What formats are best for presenting penetration testing findings to different audiences?
  • How can we ensure our reports are clear and actionable for remediation teams?
  • What should be included in an executive summary to get leadership buy-in?