Access0day  /  Sample Report

Sample Deliverable — Penetration Test Report

What’s Inside a Real Penetration Test Report

A real Access0day engagement report follows this structure: a plain-language executive summary your board can read, a severity-ranked findings list, and step-by-step remediation guidance your team can act on the same day. Client identity and technical detail below are illustrative — every real report is unique to the environment we test.

Report TypeExternal Web Application VAPT
Engagement Window7 business days
MethodologyBlack-box, manual + automated
FormatPDF + live findings call
Every Access0day report is delivered under NDA. Client name, assets, and findings shown here are illustrative composites — not a real client engagement.

Executive Summary

Access0day performed a black-box external web application assessment against the client’s customer-facing platform, combining automated scanning with manual exploitation to validate real-world impact — not just theoretical CVEs.

Testing identified weaknesses across authentication, access control, and input handling that, if left unremediated, could allow an external attacker to access sensitive data or disrupt service. Every finding below includes business impact in plain language first, technical detail second — written for the people who have to explain risk upward, not just patch it.

11
Total findings identified
High7
Medium3
Low1

Sample Findings — Report Format

Broken Access Control on Administrative API Endpoint High

An internal administrative function was reachable through the public API without verifying that the calling user held administrator privileges. A standard authenticated account — not just an admin account — could invoke the function and change settings normally restricted to administrators.

Business Risk
  • Any compromised standard account becomes a path to administrative control
  • Undermines segregation-of-duties controls required by SOC 2 / ISO 27001
  • No detection trail without dedicated authorization logging
Remediation Summary
  • Enforce server-side role checks on every privileged endpoint
  • Default to deny; require explicit allow per role
  • Add audit logging for all administrative actions
Evidence Captured In Full Report
Request showing role check bypass
FIG 1 — REDACTED FOR SAMPLE
Admin action confirmed from standard account
FIG 2 — REDACTED FOR SAMPLE
Reference OWASP — Broken Function-Level Authorization
Outdated Third-Party Library With Known CVE Medium

A client-side JavaScript dependency in production was several versions behind, with a publicly disclosed CVE affecting the in-use version. The vulnerable code path was confirmed present, though full exploitation was not attempted within the agreed rules of engagement.

Business Risk
  • Publicly known exploit code lowers the skill bar for attackers
  • Dependency risk often missed by internal patch cycles
  • Same library may be shared across multiple internal applications
Remediation Summary
  • Upgrade to the patched library version
  • Add dependency scanning to the CI/CD pipeline
  • Track third-party libraries in an asset inventory
Evidence Captured In Full Report
Vulnerable library version identified in bundle
FIG 1 — REDACTED FOR SAMPLE
Reference National Vulnerability Database (NVD) — CVE record
Missing HTTP Security Headers Low

Several browser-enforced security headers were absent from server responses, including protections against clickjacking and MIME-type sniffing. No direct exploit was demonstrated, but the missing headers reduce the browser’s ability to contain client-side attacks if another vulnerability is later introduced.

Business Risk
  • Weakens defense-in-depth for login and payment-related pages
  • Commonly flagged in compliance and third-party security reviews
Remediation Summary
  • Add Strict-Transport-Security, X-Content-Type-Options, and a Content-Security-Policy
  • Validate header configuration with an automated header scanner post-fix
Evidence Captured In Full Report
Response headers from live scan
FIG 1 — REDACTED FOR SAMPLE
Reference OWASP Secure Headers Project

A full engagement typically returns 8–15 findings of this depth, organized High → Medium → Low.

How We Get There

01

Scope & Rules

Define targets, exclusions, and engagement window in writing before testing starts.

02

Recon & Mapping

Profile the application the way an outside attacker would, before touching it.

03

Manual Exploitation

Certified engineers validate findings by hand — not just scanner output.

04

Impact Validation

Confirm real business impact for every finding before it’s reported.

05

Reporting & Walkthrough

Plain-language report plus a live call to walk your team through fixes.

What’s In The Full Report

Executive Summary

Board-ready overview of risk posture, written for non-technical stakeholders.

Severity-Ranked Findings

Every vulnerability scored by business risk and technical exploitability, not just CVSS.

Step-by-Step Remediation

Concrete fix guidance your engineering team can action without back-and-forth.

Retest on Fix

We verify each remediated finding so you can close out the audit trail with confidence.

About Access0day

Access0day is a cybersecurity firm specializing in offensive security — penetration testing, red teaming, and zero-day risk assessment for businesses that can’t afford to find out about a vulnerability from an attacker first.

Every engagement is performed by certified human security engineers, not automated scanners alone. Reports are written so a technical team can act immediately and a non-technical leader can understand the risk without a translator.

100%
NDA-Protected Engagements
24h
Response Time
Manual
Human-Verified Testing

Want to see how this looks for your environment?

Get a free, no-commitment security assessment. We’ll scope your environment and show you what a real Access0day report looks like for your business.

Request a Call
No commitment. Response within 24 hours. 100% confidential.

Vulnerability Assessment vs. Penetration Testing: What Matters to the Business

Vulnerability assessments highlight potential weaknesses, but they do not show which issues can realistically impact the business. Penetration testing focuses on what an attacker can actually exploit to cause financial loss, regulatory exposure, or operational disruption. While many vulnerabilities exist in any environment, only a small number represent real business risk. Penetration testing helps leadership prioritize investment on the issues that matter most. This approach reduces wasted security spend and provides clearer control over risk and cost.

Talk to us Unparalleled ExpertiseCutting-Edge TechniquesTailored SolutionsProactive ApproachTrusted Partnership

Ready to uncover real-world vulnerabilities before attackers do? Start your PTaaS journey with continuous, expert-led penetration testing.

Do you have a complete oversight of your Security Posture?

Unlock Insights by Scheduling Your Comprehensive Discovery Call Now