Saltar al contenido principal

Module 2 — Planning & Rules of Engagement

You know how to attack a machine in your lab. This module teaches you to do the same thing against a client's real infrastructure without endangering your career, the client's, or either of your freedoms. Everything comes down to one document — the RoE — that most beginners sign without reading, to their detriment.

What you will be able to do at the end of the module​

  • Tell apart the five contractual documents of a pentest engagement: NDA, SOW, RoE, letter of authorization, master service agreement.
  • Draft a scope that stands up before a lawyer and before your technical team — CIDR ranges, subdomains, test accounts, explicit exclusions.
  • Frame an ethical phishing campaign without ever actually stealing a credential, in compliance with Law 25, GDPR, and the RSS.
  • Anticipate the critical cases: discovery of a preexisting intrusion, personal data leak, outage caused by a scan.
  • Cleanly refuse a poorly framed engagement before signing it.

The four lessons of the module​

  1. 2.1 — Concepts — the five contractual pieces, the eight sections of a minimal RoE, the vocabulary (CIDR, DPA, DFIR, scope creep), the red flags of an engagement to refuse. Five expandable definition blocks unpack each tricky notion.
  2. 2.2 — Guided walkthrough — we take an e-commerce SMB and draft a full RoE line by line with the notes an experienced pentester would slip in. Three distinct zones, ethical phishing included, critical procedures written in advance.
  3. 2.3 — Hands-on lab — your turn. A medical practice, eight traps to spot, an RoE and a negotiation note to draft on your own. Self-assessment grid provided.
  4. 2.4 — Module quiz — five questions to check that you will refuse a poorly framed engagement before earning yourself a lawsuit.

Three ideas to take away right now​

A pentest without written authorization is a computer intrusion. Not "it depends." Not "if I am careful." A criminal offense in every developed jurisdiction. The paper exists for that single reason: to turn your attack into a service that was ordered.

The real boss of a pentest is the lawyer. What is not written down does not exist. An oral agreement does not survive an incident, an unsigned email does not either. Every question asked before signing spares you ten problems afterward.

The client can authorize you to attack only what belongs to them. A subdomain that points to Google Workspace, a VPS on OVH, a Shopify SaaS — you have no rights over any of it, no matter how convinced the client is. Lesson 2.2 shows how to map those borders in practice.

Next step​

Lesson 2.1 — Concepts starts the theory of scoping. It calls for reading, not commands. That is normal: this week, we launch nothing. We draft.