For Report Writing first of all we gotta choose a template i chose the template from this repository here :

https://github.com/noraj/OSCP-Exam-Report-Template-Markdown

and this will help us write Report in Markdown and to set this up i highly recommend watching the Video from John Hammond who explains the note taking and using this template in a very nice way:

https://www.youtube.com/watch?v=MQGozZzHUwQ&t=411s

And now lets look at the composition of a Report :

  1. Introduction
  2. Executive Summary
  3. Reporting Summary (Technical)
  4. Remediation Summary

Introduction

For the Introduction Part you can use examples from a few templates and edit them This Section Basically covers information and summary of what task you are given, the Confidentiality Statement so stuff like who has access to this, A disclaimer, and then an Assessment Overview where we basically define the date from which we will be doing the assessment, the activities in a very General Form like Planning, Discovery, Attack, Reporting.

Next in this section, we define the criteria we will be evaluating the system by for example if you are giving a Risk Value for each Vulnerability you can write how you would evaluate that like what is Low Risk, What is a medium risk, and so on and how are you classifying so like are you using a generic low → Medium → High scale or something else you can also use a standard like CVE-Scores to define your Risk Values and state them here.

For getting an example on this i would highly recommend checking out this repository from The Cyber Mentor who has a sample report again that report will also give you a very good idea of what a report should consist of.

Then a small summary of the scope we were allocated and our task should also be included in a section called scope.

Powered by Fruition