Autoattack
Start free →

How to read a penetration test report

← All guides
On this page

Start with the access the assessment was asked to establish. Then trace the access it gained and inspect the evidence behind it. A useful penetration test report connects the starting position to the systems or data you need to protect.

In AutoAttack, the campaign page becomes the report. It contains the objective outcome, recorded attack narrative and details of the steps. This guide explains how to read it. For published campaign results, see the lab research.

Separate the objective outcome from the campaign status

The objective states the access being tested, such as administrator access to a named server. Check that wording before interpreting the result. Access to a different server does not answer the same question.

The campaign status tells you whether the assessment is waiting, running, completed, stopped or failed. A completed campaign can leave its objective unreached. A stopped or failed campaign can still contain useful evidence of access gained before the interruption.

A reached objective means the campaign established the requested access. Read any coverage details beside that result, particularly when the objective concerns several domains or systems. “Not applicable to this estate” is a separate outcome for an objective whose targets the assessment established were absent. It does not certify the rest of the estate.

Distinguish access gained from attempts

A successful step records new access or a recovered credential. Reconnaissance and failed attempts describe work performed during the assessment; they do not count as access gains.

For each gain, identify the target, the identity used and what became possible afterwards. A recovered service-account password and administrator access to a server are different gains, even when one leads to the other.

AutoAttack can group repeated use of a technique and weakness across targets. Read the affected-target count and the access described together. The number of report rows is neither the number of systems assessed nor a measure of severity.

Check what the evidence actually establishes

Open the relevant step and compare its captured output with the claim. Different evidence supports different conclusions:

  • Collecting material for offline password recovery does not establish that the password was recovered.
  • A successful login establishes access as that identity. Administrator access needs evidence of the greater privilege.
  • An application error can reveal useful information. A claim that records were retrieved needs evidence of the data obtained.

These are examples of how to interpret evidence, not results from a particular campaign.

Follow the recorded route as well as the individual steps. Determine which earlier credential or permission enabled the next gain. Steps that occurred near each other are not necessarily connected. The report describes the relationships the run recorded; it is not a map of every possible attack path in the network.

Captured evidence is shown where it exists. An explanatory sentence can help interpret output, but it does not replace that output or fill a missing part of the record.

Read an unreached objective or sparse report carefully

An unreached objective means this campaign did not establish the requested access. Review the starting position, credentials, scope, exclusions and permitted actions before deciding what that result tells you.

Look for the recorded reason the run stopped and the furthest access it achieved. An unreachable target, an unsuccessful attempt and an interrupted campaign leave different questions open. When the record does not establish a cause, do not infer that a security control blocked the attack.

A report with no gains does not prove that the environment has no weaknesses. Confirm that the agent connected and the assessment ran. Then check what was reached and attempted. Supported techniques and the access available to the campaign limit what it can establish.

Turn the route into remediation work

Use the weaknesses and remediation advice beside the steps to identify the condition that enabled access. An exposed password, an excessive permission and a reused credential call for different changes. The system owner should decide how to make the change and what dependencies it affects.

Afterwards, define what would demonstrate that the condition has changed. A repeat assessment must reach and test the relevant system or permission again. If an earlier step now fails, the campaign may never test the later weakness.

AutoAttack campaigns are independent. A weakness disappearing from a later report is not automatic verification of a fix, and closing one recorded route does not establish that every route is closed.

Know what the free report includes

Before subscribing, you can read the campaign's recorded steps, technique and weakness labels, counts and access kinds. Anonymous target labels stay consistent within that campaign, so you can follow the same target across steps.

A subscription reveals target identities, captured evidence and remediation advice. See annual host pricing and the quickstart to prepare your first campaign.

Start a free campaign → See the benchmark →
Menu

Press Esc to close