Mutillidae Security Assessment Simulation
Quick Guide and Summary
Assessment Details
Target: Mutillidae (Metasploitable)
Activity Type: Group-Based Penetration Testing Assessment
Testing Window: June 5, 2026 (12:00 AM – 11:59 PM)
Before the Assessment
Each group must ensure the following are ready:
Technical Requirements
✅ Metasploitable VM operational
✅ Mutillidae accessible
✅ Kali Linux operational
✅ Penetration testing tools installed (Burp Suite, Nmap, SQLMap, Nikto, etc.)
✅ Screen recording software installed and tested (Screen.io recommended)
Administrative Requirements
Each group must complete:
✅ Non-Disclosure Agreement (NDA)
✅ Permission Memo and Rules of Engagement (ROE)
Important:
- All group members must sign both documents.
- Convert the signed documents to PDF.
- Upload the PDFs to Microsoft Teams before the assessment.
Required uploads:
- GroupX_NDA.pdf
- GroupX_ROE.pdf
Acknowledgment
After reading and understanding the instructions:
✅ React/Like the Teams announcement.
Your reaction confirms that you understand the assessment requirements and Rules of Engagement.
During the Assessment
Use the official VAPT Report Template provided by the instructor.
Minimum Requirement
Document at least:
One (1) validated finding for each OWASP Top 10 category
Minimum expected findings:
10 Findings Total
Additional validated findings may earn additional points.
Report Sections to Update
✅ Executive Summary
✅ Security Assessment Results
✅ Detailed Findings
Each finding should include:
- Title
- Risk Rating
- Description
- Impact
- Proof of Concept
- Recommendation
- Supporting Evidence
Proof of Concept Requirement
For every finding:
✅ Record the exploitation process
✅ Explain what is happening
✅ Explain the vulnerability and impact
Screen recordings are mandatory and will serve as evidence supporting your findings.
Final Submission
Deliverable 1 – VAPT Report
- Complete the official VAPT template
- Export as PDF
- Protect the PDF with a password
Deliverable 2 – Evidence Repository
Upload all supporting evidence to:
- OneDrive or
- Google Drive
Include:
- Screen recordings
- Screenshots
- Supporting artifacts
Deliverable 3 – Submission
Submit via Microsoft Teams:
✅ Password-protected PDF VAPT Report
✅ OneDrive/Google Drive link
✅ PDF password
Final Checklist
- NDA signed by all members
- ROE signed by all members
- NDA PDF uploaded
- ROE PDF uploaded
- Metasploitable and Kali Linux operational
- Minimum 10 findings documented
- OWASP Top 10 coverage achieved
- Executive Summary updated
- Security Assessment Results updated
- POC recordings completed
- Password-protected PDF report created
- Evidence uploaded to OneDrive/Google Drive
- Cloud storage link submitted
- Teams post reacted/liked
Good luck and approach the assessment as a professional penetration testing engagement: identify, validate, document, and communicate your findings effectively.