Prompt

Cybersecurity & RiskPromptFree

Penetration Test Scope And Rules Of Engagement

Drafts a rigorous pentest scope, rules of engagement, and safety guardrails before any testing begins.

  • Role-Based
  • Structured-Output
  • Zero-Shot
Download .mdOpen in Studio~183 words
ROLE: You are a lead penetration tester drafting the scope and Rules of Engagement (RoE) document for an authorized engagement.

CONTEXT:
- Client and systems in scope: [TARGETS_IP_RANGES_APPS_URLS]
- Engagement type: [BLACK_GREY_WHITE_BOX]
- Objectives: [WHAT_THE_CLIENT_WANTS_TO_LEARN]
- Constraints: [PROD_VS_STAGING_BLACKOUT_WINDOWS]
- Compliance driver: [PCI_HIPAA_SOC2_ETC]

TASK:
1. Define in-scope and explicitly out-of-scope assets, with handling for shared/third-party infrastructure and cloud provider terms.
2. Specify allowed and forbidden techniques (e.g., no DoS, no social engineering of staff unless authorized, data exfiltration limits).
3. Define testing windows, escalation contacts, and an emergency stop ('safe word') procedure.
4. Establish evidence-handling, data-minimization, and secure-storage requirements for any sensitive data encountered.
5. List authorization sign-off requirements and a legal/permission checklist.

OUTPUT FORMAT (formal document):
1. Scope (in / out)
2. Methodology & frameworks (e.g., PTES, OWASP, MITRE)
3. Rules of Engagement (allowed / forbidden)
4. Schedule & communication plan
5. Emergency procedures & stop conditions
6. Authorization & sign-off block

CONSTRAINTS: This is strictly for authorized, contracted testing — include explicit written-authorization prerequisites. Do not provide actual exploit code. Default to the most conservative, least-disruptive options when production systems are involved.

How to use it

  1. Read it, then replace anything in [BRACKETS] with your details — the more concrete the context, the sharper the answer. The Studio lists the blanks for you and can add your project's background.
  2. Copy it (or download the .md) and paste it into the AI you already use — it knows your work, so that is where the prompt does the most.
  3. Not sure what it produces? Give it a test run in the Studio first, then refine with self-critique prompting.

Techniques in this prompt

Role-Based

Assigns the model an expert persona so it adopts the right vocabulary, depth, and standards for the task.

Learn this technique
Structured Output

Pins the response to a defined structure so it drops straight into your workflow.

Learn this technique
Zero-Shot

Relies on one clear instruction with no examples — fast, and effective when the task is unambiguous.

Learn this technique

Works with

Any chat AI — ChatGPT, Claude, Gemini, Copilot, Grok, Mistral or a local model. The structure does the work, so you are not tied to one vendor or one model version.

New to structured prompts? Start with how to prompt AI, the RCTCO prompt framework this prompt is built on, and role prompting examples.

More in Cybersecurity & Risk