---
task: runPentest()
responsavel: "@peter-kim"
responsavel_type: Agent
atomic_layer: Task
elicit: true

Entrada:
  - campo: engagement_scope
    tipo: string
    origem: User Input
    obrigatorio: true
  - campo: authorization_document
    tipo: string
    origem: User Input
    obrigatorio: true

Saida:
  - campo: pentest_report
    tipo: string
    destino: Console
    persistido: false

Checklist:
  - "[ ] Authorization gate passed with documented approval"
  - "[ ] Exploitation attempts documented with evidence"
  - "[ ] Report delivered with attack narratives and remediation plan"
---

# Task: Penetration Test Engagement

**Task ID:** CYBER-002
**Version:** 1.0.0
**Command:** `*run-pentest`
**Agent:** Peter Kim (peter-kim)
**Purpose:** Execute a structured penetration test following industry methodology with mandatory authorization gates.

---

## Inputs

| Input | Source | Required |
|-------|--------|----------|
| `engagement_scope` | Client/user | YES |
| `authorization_document` | Written approval | YES |
| `target_systems` | Scope definition | YES |
| `rules_of_engagement` | Engagement agreement | YES |
| `previous_findings` | Prior assessments | NO |
| `compliance_context` | Regulatory needs | NO |

## Preconditions

1. **MANDATORY:** Written authorization exists and is verified
2. Rules of engagement define time windows, restricted targets, and escalation contacts
3. Emergency contact information is available
4. Scope boundaries are unambiguous
5. Legal review completed (if applicable)

## Execution Phases

### Phase 1: Pre-Engagement & Authorization Gate

1. Verify written authorization document covers all target systems
2. Confirm scope boundaries — IP ranges, domains, applications, excluded hosts
3. Establish rules of engagement — testing windows, DoS restrictions, data handling
4. Set up secure communication channel for findings
5. Prepare testing environment and tooling
6. **AUTHORIZATION GATE:** If any scope item lacks explicit authorization, STOP and request clarification
7. Document pre-engagement checklist sign-off

### Phase 2: Reconnaissance

1. **Passive recon** — OSINT, WHOIS, DNS enumeration, certificate transparency
2. **Active recon** — Port scanning (nmap), service fingerprinting, version detection
3. **Web recon** — Directory enumeration (gobuster/ffuf), technology fingerprinting
4. **Network mapping** — Topology discovery, trust relationships, routing
5. Correlate findings into target profile document
6. Identify high-value targets and potential attack vectors

### Phase 3: Exploitation

1. Vulnerability identification — Match services against CVE databases, run Nuclei/Nikto
2. Manual verification — Confirm exploitability of identified vulnerabilities
3. Exploitation — Attempt controlled exploitation of confirmed vulnerabilities
4. **SAFETY CHECK:** Before each exploit, verify target is in-scope and technique is non-destructive
5. Credential attacks — Password spraying, hash cracking (if in scope)
6. Web application attacks — SQL injection, XSS, auth bypass, IDOR (if in scope)
7. Document each successful exploitation with evidence (screenshots, logs)

### Phase 4: Post-Exploitation & Lateral Movement

1. Assess impact of compromised systems
2. Attempt privilege escalation (local and domain)
3. Lateral movement — Identify accessible systems from compromised hosts
4. Data access assessment — What sensitive data is reachable?
5. Persistence evaluation — How easily could an attacker maintain access?
6. **CLEANUP:** Remove all test artifacts, backdoors, and temporary accounts
7. Document attack chain from initial access to final impact

### Phase 5: Reporting

1. Executive summary — Business impact in non-technical terms
2. Attack narrative — Step-by-step story of each attack chain
3. Findings matrix — All vulnerabilities with CVSS, evidence, remediation
4. Risk heat map — Visual severity distribution
5. Remediation priorities — Ordered by risk and effort
6. Retest recommendations — Which findings need verification after remediation

## Output Format

```yaml
pentest_report:
  engagement_id: "{id}"
  target: "{target}"
  tester: "peter-kim"
  methodology: "PTES / OWASP"
  date_range: "{start} — {end}"
  executive_summary: |
    {Business impact overview}
  attack_chains:
    - chain_id: "AC-001"
      initial_access: "{method}"
      privilege_escalation: "{method}"
      lateral_movement: "{path}"
      impact: "{data/systems accessed}"
      evidence: ["{screenshots, logs}"]
  findings:
    - id: "PT-001"
      title: "{vulnerability}"
      severity: "CRITICAL | HIGH | MEDIUM | LOW"
      cvss: 0.0
      evidence: "{proof}"
      remediation: "{fix}"
      retestable: true
  cleanup_confirmation: |
    {All artifacts removed, accounts deleted}
```

## Veto Conditions

- **NEVER** begin testing without verified written authorization
- **NEVER** test systems outside the defined scope
- **NEVER** use destructive techniques (DoS, data deletion, ransomware simulation)
- **NEVER** exfiltrate real sensitive data — document access, do not extract
- **NEVER** leave persistent backdoors or test accounts after engagement
- **NEVER** share findings outside authorized channels

## Completion Criteria

- [ ] Authorization gate passed with documented approval
- [ ] Reconnaissance completed within scope boundaries
- [ ] Exploitation attempts documented with evidence
- [ ] Post-exploitation impact assessed
- [ ] All test artifacts cleaned up
- [ ] Report delivered with attack narratives and remediation plan
- [ ] Retest recommendations provided
