Skip to content
← Learn

Deliverables

What a pentest report is

The anatomy of a serious pentest report: validated findings, reproducible PoCs, ATT&CK mapping and negative controls. What to demand before signing.

The report is the product. The test is the means. Most pentesting discussions focus on the tool or the consultant’s certification, but what remains after the engagement is a document your team uses to prioritize, remediate and defend decisions to audit. That document either works or it does not.

Anatomy of a report that works

Executive summary in one page. What was tested, what was found, what it means for the business. No jargon. Validated findings. Each with severity justified by impact and exploitability, not scanner score. Reproducible PoC. Steps, evidence and exact conditions: your team must be able to repeat it. MITRE ATT&CK mapping. Which real techniques the test executed and in what order. Remediation by priority. What to close first and why, with root cause — not the vendor patch copy-pasted.

What an honest report declares

The report distinguishes verified controls, failed attempts, inconclusive tests and exclusions. An unauthenticated request returning 401 can serve as a negative authentication control for that case. It does not prove all authorization works. Documenting untested areas keeps limited coverage from becoming a guarantee.

Red flags when receiving a report

Review findings without sufficient evidence, severities without contextual justification and recommendations that do not explain what to fix. If an intrusive test was omitted to avoid harm, the report should distinguish available evidence from unproven impact. The Rekon report is hand-signed by whoever supervised the test. See how we work or request proposed scope.

Complete synthetic report

Inspect the sample report: scope, two findings, fictional evidence and a retest with one unresolved fix.

Straight answers

What sections does a pentest report have?

Executive summary, methodology and scope, findings with severity and evidence, each PoC reproducible, MITRE ATT&CK mapping, and a remediation plan prioritized by real impact. Without evidence, the rest is opinion.

What is a negative control in a report?

A test expected to be denied: for example, repeating a request without the authorized session and verifying rejection. A failed exploitation attempt is not automatically a negative control and does not prove the absence of vulnerabilities.

How do you measure report quality?

By one thing only: your team can reproduce every finding without asking the provider again. If a PoC needs a verbal explanation, the report is incomplete.

Time to test your doors?

Tell us what needs validating. We answer with proposed scope, not a brochure.

Talk to Rekon More in Learn