What problem does it solve? Penetration testers and security assessors often lack a consistent, end-to-end methodology for planning and executing engagements, leading to missed phases, weak authorization practices, and poor-quality reports. ## Core Features & Use Cases - Seven-Phase Methodology: Covers pre-engagement, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation, and reporting with per-phase reference documents. - Modern Infrastructure Adaptations: Provides phase-by-phase adjustments for cloud (AWS/Azure/GCP), Kubernetes, and API/microservices environments. - Compliance Mapping: Maps testing activities to PCI DSS, HIPAA, GDPR, SOC 2/ISO 27001, and FedRAMP requirements, including cloud provider authorization policies. - Use Case: When scoping a web application pentest, load the pre-engagement reference to build the ROE document, then follow the intelligence gathering and vulnerability analysis phases with concrete tool commands like Nmap, Amass, and Nuclei. ## Quick Start Ask the agent to plan a penetration test for a target scope using the PTES methodology and load the relevant phase reference for detailed guidance.