defining-pentest-scope
Parse the ROE scope definition, enumerate every in-scope target
(hostnames, IPs, CIDRs, URLs, cloud accounts, SaaS tenants),
validate syntax, detect overlap with out-of-scope or known
third-party SaaS ranges, and emit a normalized target list plus
IP allowlist for scanning tools. Runs after confirming-pentest-
authorization and before any cluster 1-4 scan.
Use when: starting an engagement, expanding scope mid-engagement,
validating that a target list matches the ROE, or generating an
allowlist for an external scanner.
Threshold: malformed syntax, in-scope overlap with out-of-scope,
reserved or third-party SaaS ranges without acknowledgement.
Trigger with: "define scope", "enumerate targets", "validate
target list", "generate IP allowlist".
Cloud & DevOps⭐ 2.4k4 files