Prompt engineering is the process of crafting precise input prompts for LLMs that achieve the highest-quality results. In general there are the following components that make up an effective prompt.

Role

Defining a role for the model helps guide its behavior. It can activate a subset of its learned patterns and establishes a baseline for the tone, depth, and vocabulary.

You are an experienced penetration tester.

# giving more context reduces ambiguity and increases factual alignment
You are performing reconnaissance in a security assessment.

# combine role and context
You are a penetration tester performing reconnaissance.

Instruction

Defines the main task the model should perform. We should be clear and concise and avoid amiguity.

# bad instruction
Analyze this stack trace. How do I exploit it?

# good instruction
Given the following stack trace, do two things:
1. List sensitive details exposed in the stack trace (software, versions, paths, etc.)
2. Analyze if the stack trace indicates misconfigurations or contains vulnerability indicators.

We should define a success criteria.

Constraints

Provide further guidance to the model, steering it in the right direction. Deliverables, output format, task constraints. The constraint should be as detailed as possible.

# bad constraint
Respond with a short summary consisting of a few sentences only

# good constraint
Respond with a 3-5 sentence summary.

Examples

Descriptive examples steer the model in the right direction and help produce more accurate results. Provide concrete demonstration of the expected output format, structure, and style. All examples should follow the same structure, no inconsistencies.

Data

Models should have all the data necessary to perform the task. Tool Outputs, scoping information, other background information. Depending on the amount of data, we should ensure seperation between different artifacts (YAML style syntax, XML-style texts, or just headers).


A good prompt in all should look like

You are a penetration tester performing reconnaissance.

Analyze the following Nmap scan output and identify:  
- Open ports and associated services
- Potential security risks based on service versions
- Recommended next enumeration steps
- Do not speculate beyond the provided information

Output the results in a structured bullet-point format.

[ARTIFACT] Nmap scan
Target: 10.10.10.10
Content:
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 8.9p1 Ubuntu 3 (Ubuntu Linux; protocol 2.0)
80/tcp open http Apache httpd 2.4.52 (Ubuntu)
443/tcp open ssl/http Apache httpd 2.4.52 (Ubuntu)