finds.dev← search

// the find

hmaverickadams/External-Pentest-Checklist

★ 432 · updated Feb 2022

A single Excel workbook, the TCMS External Pentest Checklist, that lists the steps for an external penetration test. It is for security testers running perimeter assessments who want a tickbox list to work through, not for developers building software.

It is one .xlsx file, so there is nothing to install, build, or configure, and anyone with Excel or LibreOffice can use it on the day. Keeping the scope to external testing, rather than mixing in internal network or web application checks, makes it a clear starting point for a perimeter engagement. The 432 stars and 114 forks suggest a fair number of testers have picked it up, though popularity says nothing about whether each check is still correct.

The last push was February 2022, so anything about cloud-hosted services, current TLS and auth defaults, or newer tooling is probably stale. A spreadsheet is also a poor fit for version control, since .xlsx diffs are binary and changes or forks are hard to review line by line. The directory listing I had was truncated to this one workbook, so no README, scope statement, or license was visible; check the license before using it on client work.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →