finds.dev← search

// the find

hmaverickadams/TCM-Security-Sample-Pentest-Report

★ 1,436 · updated Mar 2022

Sample pentest report provided by TCM Security

A sample external penetration test report for a fictional company, Demo Company, published by TCM Security alongside their video on writing pentest reports. It is aimed at people who have never seen a finished pentest deliverable and want a starting template to adapt for their own engagements.

The sample is delivered as real Word documents, the format clients actually receive, so the structure can be lifted directly into a working template. A second .docx gives a different example of the same report type, which shows that two writers can organize the same material differently. It is paired with a video walkthrough, so the artifact and the explanation of its layout exist together.

The README says it covers a single finding from an external test, so there is nothing on organizing a report with many findings, ranking by severity, or writing up internal, web application, or cloud work. The deliverables are .docx binaries with no Markdown or plain-text copy, so changes can't be diffed or reviewed in a PR and the text can't be searched without opening Word. The last push was in March 2022, and the file listing shows no license file, so the 'make this your own' invitation is less clear than it reads.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →