Public Pentesting Reports is a curated collection of publicly available penetration test reports from security consulting firms and academic research groups.
The repository addresses the need for real-world examples of professional security assessments and their findings. By aggregating reports that organizations have chosen to publish, it provides a centralized resource for understanding how penetration testing is conducted, what vulnerabilities are typically discovered, and how security assessments are documented and communicated. This approach allows security professionals and organizations to learn from actual engagements without needing to search across multiple firm websites or academic publications.
Security professionals preparing for penetration testing work, organizations planning their first security assessment, and students studying applied security can use this collection to understand industry practices and expectations. The repository is particularly valuable for those seeking to see how real vulnerabilities are identified and reported in professional contexts. It serves as a reference for what a quality penetration test report should contain and how findings are typically presented to stakeholders.
The project maintains a straightforward structure as a curated list, with contributions accepted to keep the collection current as new reports become publicly available. The maintenance approach focuses on identifying and adding newly published reports from established security firms and academic groups rather than generating original content.