Back to Guides
Guide2 October 2026

What are the 5 stages of penetration testing?

Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.

In this guide
  1. Key takeaways
  2. What is the first stage: reconnaissance?
  3. How does scanning differ from reconnaissance?
  4. What happens during the vulnerability assessment?
  5. How is exploitation performed safely?
  6. Why is reporting the final and critical stage?
  7. How the five stages fit together

Key takeaways

What is the first stage: reconnaissance?

Reconnaissance, also called information - gathering, collects all publicly available data about the target before any direct interaction. Use tools like WHOIS, DNS lookups, Google dorks, and passive OSINT services to map IP ranges, subdomains, and technology stacks. Record every source and finding in a spreadsheet so you can trace later evidence.

How does scanning differ from reconnaissance?

Scanning actively probes the target to discover open ports, services, and version numbers. Run Nmap, masscan, or similar scanners with safe timing presets to avoid denial - of - service impact. Export the scan results as XML or CSV; they become the raw data for the next stage. Do not jump to exploitation before you have a clean, verified scan.

What happens during the vulnerability assessment?

Vulnerability assessment analyzes the scan output to identify exploitable weaknesses. Combine automated scanners (e.g., Nessus, OpenVAS) with manual verification of high - risk findings. Prioritize issues by CVSS score, exploitability, and business impact. Document each candidate vulnerability with its CVE identifier, affected asset, and confidence level.

How is exploitation performed safely?

Exploitation attempts to gain unauthorized access using the vulnerabilities identified earlier. Use controlled tools such as Metasploit modules, custom scripts, or manual payloads, and always obtain explicit permission before running them. Capture screenshots, session details, and any data exfiltrated as proof of concept, but limit impact to avoid production disruption.

Why is reporting the final and critical stage?

Reporting compiles all findings, methods, and remediation guidance into a clear, client - focused document. Include an executive summary, a detailed technical appendix, and a prioritized remediation plan. Attach evidence artefacts (screenshots, logs, proof - of - concept files) so the client can verify each claim and map findings to compliance frameworks.

How the five stages fit together

StageGoalPrimary Output
ReconnaissanceGather passive intelligenceOSINT spreadsheet, asset inventory
ScanningActively enumerate servicesNmap/port - scan reports
Vulnerability AssessmentIdentify exploitable weaknessesPrioritized vulnerability list
ExploitationProve risk by gaining accessProof - of - concept payloads, session data
ReportingCommunicate findings and fixesFull penetration - test report

Each stage depends on the previous one, and skipping any step reduces the reliability of the final report. Following this lifecycle ensures repeatable, auditable results that support security governance and compliance.

Free security scan

See what's actually exposed on your site.

Decloak's free scan runs in about 15 seconds, no account required, and covers:

  • HTTP/TLS security posture
  • JavaScript CVEs
  • Exposed Supabase/Lovable/Base44 misconfigurations
  • AI-written executive summary