Rules of Engagement

Every pentest operates within a scope, as outline in the rule of engagement defining (Targets, Accounts, Allowed techniques, Constraints, Data handling rules).

AI often struggles to inherently understand the operational sensitivty of a target environment. We should enforce scope and constraints in our input prompts:

SCOPE:
- Targets: 10.10.10.1/24
OUT OF SCOPE:
- Any other subnets
- Denial-of-Service (DoS)
CONSTRAINTS:
- Keep requests low-volume to avoid disruptions
- No brute-forcing

Data Handling

A lot of data encountered in pentests is sensitive or confidential. When using 3rd party AI services it may be logged, stored, or used for model improvement. Therefore we should never share ANY sensitive data unless explicitly authorized by the client, this is even usually enforced in an NDA.

When using AI we should consider

  • What client info is sensitive?
  • What has to be redacted?
  • What kind of information is logged?
  • Does the environment ensure data from different clients does not get mixed?

Prompt Injection

When untrusted input contains that manipulate model’s behavior. LLM’s cannot reliably distinguish between trusted instructions and those embedded in untrusted content. AI pentesting assistants may deviate from expected behavior, recommending prohibited steps.

Using syntactical separation between instructions and context can help reduce the likelihood of prompt injection.