Cybersecurity & RiskPromptFree
Penetration Test Scope And Rules Of Engagement
Drafts a rigorous pentest scope, rules of engagement, and safety guardrails before any testing begins.
ROLE: You are a lead penetration tester drafting the scope and Rules of Engagement (RoE) document for an authorized engagement.
CONTEXT:
- Client and systems in scope: [TARGETS_IP_RANGES_APPS_URLS]
- Engagement type: [BLACK_GREY_WHITE_BOX]
- Objectives: [WHAT_THE_CLIENT_WANTS_TO_LEARN]
- Constraints: [PROD_VS_STAGING_BLACKOUT_WINDOWS]
- Compliance driver: [PCI_HIPAA_SOC2_ETC]
TASK:
1. Define in-scope and explicitly out-of-scope assets, with handling for shared/third-party infrastructure and cloud provider terms.
2. Specify allowed and forbidden techniques (e.g., no DoS, no social engineering of staff unless authorized, data exfiltration limits).
3. Define testing windows, escalation contacts, and an emergency stop ('safe word') procedure.
4. Establish evidence-handling, data-minimization, and secure-storage requirements for any sensitive data encountered.
5. List authorization sign-off requirements and a legal/permission checklist.
OUTPUT FORMAT (formal document):
1. Scope (in / out)
2. Methodology & frameworks (e.g., PTES, OWASP, MITRE)
3. Rules of Engagement (allowed / forbidden)
4. Schedule & communication plan
5. Emergency procedures & stop conditions
6. Authorization & sign-off block
CONSTRAINTS: This is strictly for authorized, contracted testing — include explicit written-authorization prerequisites. Do not provide actual exploit code. Default to the most conservative, least-disruptive options when production systems are involved.- Built from
- Role
- Context
- Task
- Output format
- Constraints
How to use it
- Read it, then replace anything in [BRACKETS] with your details — the more concrete the context, the sharper the answer. The Studio lists the blanks for you and can add your project's background.
- Copy it (or download the .md) and paste it into the AI you already use — it knows your work, so that is where the prompt does the most.
- Not sure what it produces? Give it a test run in the Studio first, then refine with self-critique prompting.
Techniques in this prompt
Role-Based
Assigns the model an expert persona so it adopts the right vocabulary, depth, and standards for the task.
Learn this techniqueStructured Output
Pins the response to a defined structure so it drops straight into your workflow.
Learn this techniqueZero-Shot
Relies on one clear instruction with no examples — fast, and effective when the task is unambiguous.
Learn this techniqueWorks with
Any chat AI — ChatGPT, Claude, Gemini, Copilot, Grok, Mistral or a local model. The structure does the work, so you are not tied to one vendor or one model version.
New to structured prompts? Start with how to prompt AI, the RCTCO prompt framework this prompt is built on, and role prompting examples.