Skip to main content
Built for real engagements

PentestingChecklist

The penetration tester's companion. A comprehensive, hands-on collection of security assessment checklists you actually work through, across 26 platforms and every layer of a real engagement.

Runs entirely in your browser. No login, no backend, no telemetry.

A checklist you operate

Not docs to read. Expand a category, drill into a technology, and tick checks as you go. Progress and per-check notes are tracked at every level.

Find any check instantly

Press ⌘K from any page to search every platform, category, technology, check, tool, and reference. Select a result and it expands and highlights the exact check.

Private & offline

No accounts, no database, no telemetry. Your progress and findings live in your browser. Export to Markdown, CSV, Excel, or JSON, and re-import to resume.

Built to scale as data

Every check is a typed object. Add a check, a technology, or a whole platform by editing one data file, and the type system and CI validate it. The UI never changes.

The knowledge base behind the checklist

Powered by PentestingEverything

Every check in this tool is the operational front end of PentestingEverything, a dedicated knowledge base covering web, mobile, API, cloud, and every other platform in this checklist. The checklist covers what to test. PentestingEverything holds the deep how and why behind each one, kept close and in sync with the checks here.

Visit the website →View on GitHub2,065 checks mapped to one shared body of knowledge.

Every platform, one framework

Across 26 platforms, from web, API, and mobile to Active Directory, cloud, Kubernetes, LLM, and forensics. Each is its own checklist organised by category, technology, and check. Pick where you're testing and work top to bottom.