Field kit

Deliverable practice

Finding / report writer

Fill the fields operators actually ship. Live Markdown preview with copy and download — train the muscle that turns shells into risk reduction.

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

Finding form

Markdown preview

## [Medium] Untitled finding

**Asset:** —  
**Category:** —  
**Auth context:** —  
**CVSS:** —   
**ATT&CK:** —  
**Status:** Open

### Description
_Describe what is wrong in plain language._

### Business impact
_Who is affected and what can an attacker do?_

### Technical details
_Root cause, parameter/endpoint, versions._

### Steps to reproduce
1. …
2. …
3. …

### Evidence
_Requests, screenshots, tool output filenames (redact secrets)._

### Remediation
_Specific fix: code, config, or process._

### References
_OWASP / CVE / vendor advisory_

Tip: pair with the finding template cheatsheet and reporting module.