> For the complete documentation index, see [llms.txt](https://evolvingsysadmin.gitbook.io/red-team-toolkit/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://evolvingsysadmin.gitbook.io/red-team-toolkit/methodology.md).

# Methodology

There are several methodology frameworks for penetration testing that are widely used by security professionals. Here are some of the best:

* [MITRE ATT\&CK](/red-team-toolkit/methodology/mitre.md)
* [NIST SP 800-115](/red-team-toolkit/methodology/nist.md)
* [OWASP Testing Guide](/red-team-toolkit/methodology/owasp.md)
* [Penetration Testing Execution Standard (PTES)](/red-team-toolkit/methodology/ptes.md)
* [SANS Penetration Testing Framework](/red-team-toolkit/methodology/sans.md)

It is important to use a methodology framework for penetration testing for several reasons:

* Structured approach: helps ensure necessary steps are taken to identify and exploit vulnerabilities
* Consistency: helps ensure consistency across different tests and testers
* Best practices: helps reduce risk of unintended consequences
* Communication: structured communication helps set expectations to ensure all are on the same page
* Compliance: many standards require penetration tests be conducted via methodology framework
