Individual techniques — scanning a port, injecting a query, bypassing a login — are only useful inside a larger plan. A professional engagement is not a random walk through tricks. It is a repeatable process: a defined order of phases that starts with written authorization and ends with a report the client can act on.
That process is what separates a penetration test from vandalism, and it is what makes results complete, consistent, and defensible:
- Coverage - a phase checklist stops you forgetting authentication or business logic just because the first injection was exciting.
- Repeatability - two testers following the same method reach comparable conclusions.
- Defensibility - every action maps to an agreed phase and an authorized scope, so you can prove the work was sanctioned.
- Communication - clients and blue teams understand phases; "we are in enumeration" tells everyone where things stand.
This lesson is a synthesis, not a new vulnerability. It gives a frame that holds earlier lessons in place, and it bridges hacking-ethics-and-authorization to vulnerability-reporting-cvss.
In this lesson you will:
- See the recognized lifecycle phases and the published standards (PTES, OWASP WSTG) they come from.
- Recognise the cyber kill chain — a seven-stage model describing how a real adversary moves from initial reconnaissance through to completing their objective — as the same events seen from the attacker's side.
- Map the lessons you have already completed onto their phases and sketch a one-page test plan for NovaCart.
Estimated time: ten minutes. No exploitation is performed here - this is a planning and synthesis lesson.
When you are ready, send the Continue signal.