1. Engagement design
Define objectives, attack surface, constraints, critical assets, access assumptions, and communication paths.
2. Reconnaissance
Map the target environment using passive and active discovery appropriate to the agreed scope.
3. Testing and exploitation
Use targeted automation for breadth and manual techniques for deeper validation, context, authentication, authorization, privilege, and attack chaining.
4. Evidence and impact
Confirm findings with enough evidence to demonstrate risk while minimizing operational impact.
5. Reporting and debrief
Prioritize what matters, explain why, document reproduction detail, and meet with stakeholders to work through remediation questions.
6. Retest
Validate fixes and update status so the assessment has a clear closure path.
Related next step
Use this resource as a starting point, then adapt it to the systems, business constraints, and threat model that actually apply to your organization.