Cybersecurity & Risk5.0 · 0 ratings

Penetration Test Scope And Rules Of Engagement

Drafts a rigorous pentest scope, rules of engagement, and safety guardrails before any testing begins.

Role-BasedStructured-OutputZero-Shot

Prompt

ROLE: You are a lead penetration tester drafting the scope and Rules of Engagement (RoE) document for an authorized engagement.

CONTEXT:
- Client and systems in scope: [TARGETS_IP_RANGES_APPS_URLS]
- Engagement type: [BLACK_GREY_WHITE_BOX]
- Objectives: [WHAT_THE_CLIENT_WANTS_TO_LEARN]
- Constraints: [PROD_VS_STAGING_BLACKOUT_WINDOWS]
- Compliance driver: [PCI_HIPAA_SOC2_ETC]

TASK:
1. Define in-scope and explicitly out-of-scope assets, with handling for shared/third-party infrastructure and cloud provider terms.
2. Specify allowed and forbidden techniques (e.g., no DoS, no social engineering of staff unless authorized, data exfiltration limits).
3. Define testing windows, escalation contacts, and an emergency stop ('safe word') procedure.
4. Establish evidence-handling, data-minimization, and secure-storage requirements for any sensitive data encountered.
5. List authorization sign-off requirements and a legal/permission checklist.

OUTPUT FORMAT (formal document):
1. Scope (in / out)
2. Methodology & frameworks (e.g., PTES, OWASP, MITRE)
3. Rules of Engagement (allowed / forbidden)
4. Schedule & communication plan
5. Emergency procedures & stop conditions
6. Authorization & sign-off block

CONSTRAINTS: This is strictly for authorized, contracted testing — include explicit written-authorization prerequisites. Do not provide actual exploit code. Default to the most conservative, least-disruptive options when production systems are involved.

How to use this prompt

  1. 1

    Copy the prompt above and paste it into ChatGPT, Claude, or Gemini — or open it in the visual Studio to edit each part on a canvas and run it with your own key.

  2. 2

    Replace any bracketed placeholders with your specifics. The more concrete your context and constraints, the sharper the result — see the 5-part prompt structure.

  3. 3

    Run it, then refine. Ask the model to critique and improve its own answer with self-critique prompting.

Techniques in this prompt

Role-Based

Assigns the model an expert persona so it adopts the right vocabulary, depth, and standards for the task.

Learn this technique
Structured Output

Pins the response to a defined structure so it drops straight into your workflow.

Learn this technique
Zero-Shot

Relies on one clear instruction with no examples — fast, and effective when the task is unambiguous.

Learn this technique

Recommended models

claudegpt-4ogemini

Build on this prompt

Open it in the visual Studio to wire it into a full workflow with your own API key — or learn the craft behind prompts like this.

More in Cybersecurity & Risk