> For the complete documentation index, see [llms.txt](https://pnpt.adot8.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://pnpt.adot8.com/external-pentest-playbook/before-starting/checklists.md).

# Checklists

## Overview

There should always be some kind of checklist for any engagement.

The check list should have the following:

* &#x20;To Do list
* IP ranges scope
* Targets to attack
  * Host IP
  * URL
  * Open Port
  * Findings
* Password Spraying attempts
  * &#x20;Website
  * Account and Password tried
* Breached Accounts
  * Users and their breached passwords
* Login Portals found
* &#x20;Findings and Strengths
  * Findings/issues - System name/IP - Screenshot - Comment
  * Strengths Identified - System name/IP - Screenshot - Comment

Documentation is important for yourself while attacks and the client afterwards in a report

<figure><img src="/files/Pc01FnBWo0qTbv2YxRoH" alt=""><figcaption><p>TCM Security checklist example</p></figcaption></figure>
