Writing Penetration Test Reports
The Report Is the Product
A client does not pay for hacking. They pay for clear, actionable information. The report is what the CEO reads to decide on budget, and what the engineers use to fix problems. A brilliant test with a poor report has little value, and a well-written report makes even a modest test useful.
Structure of a Good Report
| Section | Audience | Contents |
|---|---|---|
| Executive summary | Leadership | 1 page, plain language: what was tested, overall risk, top issues, what to do first. No jargon |
| Scope and methodology | Everyone | Systems tested, dates, tools, limits, standards followed (OWASP, PTES) |
| Findings summary | Managers | A table of all findings sorted by severity |
| Detailed findings | Engineers | One section per finding (see below) |
| Recommendations / roadmap | Managers and engineers | Prioritised fixes, quick wins first |
| Appendices | Technical | Raw tool output, scan results, evidence |
Anatomy of a Finding
Every finding should answer: what, where, how bad, how do I see it, and how do I fix it.
Title: SQL Injection in Login Form
Severity: Critical (CVSS 9.8)
Affected: https://portal.example.com/login (parameter: username)
Description: The username field is concatenated into a SQL query without sanitising...
Impact: An unauthenticated attacker can bypass login and read all customer records.
Evidence: Request: username=' OR '1'='1' -- Response: 302 redirect to /admin
[screenshot 4.2]
Steps to reproduce:
1. Open the login page. 2. Enter ' OR '1'='1' -- as the username...
Recommendation: Use parameterised queries. Add input validation. Deploy a WAF as a
temporary control. Retest after the fix.
References: OWASP A03:2021, CWE-89
Tips:
- Evidence is essential. Screenshots, requests and timestamps, with sensitive data redacted.
- Be specific and reproducible. Another engineer should be able to repeat it.
- Explain business impact, not just technical detail. "Attackers could read every customer's account balance" beats "SQLi present".
- Be fair and precise. No exaggeration, no blame. Mention what was done well.
- Recommendations must be practical: what to change, how, and in what order.
Rating Risk with CVSS
The Common Vulnerability Scoring System (CVSS) gives a score from 0.0 to 10.0 so that everyone rates severity the same way. The base score comes from these metrics:
| Metric | Question |
|---|---|
| Attack Vector (AV) | Network, Adjacent, Local or Physical? |
| Attack Complexity (AC) | Low or High? |
| Privileges Required (PR) | None, Low or High? |
| User Interaction (UI) | None or Required? |
| Scope (S) | Does it affect other components (Changed) or not (Unchanged)? |
| Confidentiality / Integrity / Availability (C, I, A) | None, Low or High impact? |
| Score | Severity |
|---|---|
| 0.0 | None |
| 0.1 to 3.9 | Low |
| 4.0 to 6.9 | Medium |
| 7.0 to 8.9 | High |
| 9.0 to 10.0 | Critical |
A vector looks like CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, which scores 9.8 (Critical): reachable over the network, easy, no login and full impact.
Remember that CVSS measures technical severity. Add business context: a Medium bug on the payments system may deserve more urgency than a High bug on a test server. Many teams also consider whether an exploit is already being used in the wild.
Professional Habits
- Write as you test. Take notes and screenshots during the engagement, not afterwards.
- Protect the report: it is a roadmap for attackers, so share it securely and limit copies.
- Offer a debrief call and a retest after fixes.
- Use a template so that every report looks consistent. Free examples exist on GitHub (search "public pentest reports") and from companies such as Offensive Security and TCM Security.
A Nigerian and Global View
Whether the client is a Nigerian bank preparing for a regulatory review, a fintech seeking a partner's approval, or a European startup doing due diligence, the report is what they will show to auditors, boards and customers. Clear writing is one of the fastest ways to stand out as a junior tester, and it is a skill that transfers to bug bounty reports, where a well-written report gets paid faster.
Try It: CVSS Calculator
In the editor on the right, choose the metrics for a finding and see the score and severity. Try these:
- SQL injection on a login page: AV Network, AC Low, PR None, UI None, Scope Unchanged, C High, I High, A High. Expect 9.8.
- Reflected XSS: AV Network, AC Low, PR None, UI Required, Scope Changed, C Low, I Low, A None. Expect 6.1.
- IDOR letting a logged-in user read others' data: AV Network, AC Low, PR Low, UI None, Scope Unchanged, C High, I None, A None. Expect 6.5.
Try it yourself
Key Takeaways
- The report is the product: an executive summary for leaders and detailed findings for engineers, plus scope, methodology and a fix roadmap.
- Every finding needs a title, severity, affected asset, description, impact, evidence, steps to reproduce, recommendation and references.
- CVSS rates technical severity from 0.0 to 10.0 (Low, Medium, High, Critical) using metrics like attack vector, complexity, privileges, user interaction, scope and CIA impact.
- Add business context to the score. A Medium bug on a payments system can be more urgent than a High bug on a test server.
- Take notes as you test, redact sensitive data, protect the report and offer a debrief and retest. Clear writing sets you apart from other testers.
Quick Quiz
1.Who is the executive summary written for, and how should it read?
2.A finding has the CVSS vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. What is the rating?
3.Which item is essential in every detailed finding so the client can act on it?
Ready to go further?
CareerEx gives you structured 12-week training, live classes every Saturday and Sunday, real tutor feedback, and a certificate. Join the next cohort.
Join CareerEx