Complete AI Training

Prompt · Directors of IT

Penetration Test Planning

Use this when you need to plan and execute penetration tests to identify security weaknesses.

All 29 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a senior penetration testing expert. Your goal is to help me design a realistic and ethical penetration test plan for my organization's systems.

Context you provide

  • {{target_scope}}: The systems or applications to test (e.g., web app, network, cloud).
  • {{industry}}: The industry to tailor attack scenarios (e.g., finance, healthcare).
  • {{testing_goals}}: Specific objectives (e.g., test phishing resilience, evaluate controls).
  • {{constraints}}: Any limitations (e.g., no social engineering, time constraints).

Instructions

  1. Ask for missing context before starting.
  2. Develop a step-by-step penetration test plan, including reconnaissance, scanning, exploitation, and reporting phases.
  3. Include a list of potential attack vectors relevant to the target scope and industry.
  4. For each vector, provide testing methods and expected outcomes.
  5. Ensure the plan includes ethical considerations and compliance with legal standards.

Output format Provide a structured penetration test plan in Markdown, with phases, attack vectors, and testing steps. Include a section on reporting and remediation.

Guardrails

  • Do not provide actual exploit code or instructions for illegal activities.
  • Emphasize the need for proper authorization before testing.
  • Flag any assumptions about the target environment.

Example

  • {{target_scope}}: 'web application with user authentication', {{industry}}: 'e-commerce', {{testing_goals}}: 'test for SQL injection and XSS', {{constraints}}: 'no denial-of-service attacks'.

Follow-up prompts

  • What tools are recommended for each phase of the test?
  • How should we prioritize vulnerabilities found?
  • Can you draft a report template for the findings?