Mutillidae Security Assessment Simulation

Quick Guide and Summary

Assessment Details

Target: Mutillidae (Metasploitable)

Activity Type: Group-Based Penetration Testing Assessment

Testing Window: June 5, 2026 (12:00 AM – 11:59 PM)


Before the Assessment

Each group must ensure the following are ready:

Technical Requirements

✅ Metasploitable VM operational

✅ Mutillidae accessible

✅ Kali Linux operational

✅ Penetration testing tools installed (Burp Suite, Nmap, SQLMap, Nikto, etc.)

✅ Screen recording software installed and tested (Screen.io recommended)


Administrative Requirements

Each group must complete:

Non-Disclosure Agreement (NDA)

Permission Memo and Rules of Engagement (ROE)

Important:

  • All group members must sign both documents.
  • Convert the signed documents to PDF.
  • Upload the PDFs to Microsoft Teams before the assessment.

Required uploads:

  • GroupX_NDA.pdf
  • GroupX_ROE.pdf

Acknowledgment

After reading and understanding the instructions:

✅ React/Like the Teams announcement.

Your reaction confirms that you understand the assessment requirements and Rules of Engagement.


During the Assessment

Use the official VAPT Report Template provided by the instructor.

Minimum Requirement

Document at least:

One (1) validated finding for each OWASP Top 10 category

Minimum expected findings:

10 Findings Total

Additional validated findings may earn additional points.


Report Sections to Update

✅ Executive Summary

✅ Security Assessment Results

✅ Detailed Findings

Each finding should include:

  • Title
  • Risk Rating
  • Description
  • Impact
  • Proof of Concept
  • Recommendation
  • Supporting Evidence

Proof of Concept Requirement

For every finding:

✅ Record the exploitation process

✅ Explain what is happening

✅ Explain the vulnerability and impact

Screen recordings are mandatory and will serve as evidence supporting your findings.


Final Submission

Deliverable 1 – VAPT Report

Deliverable 2 – Evidence Repository

Upload all supporting evidence to:

  • OneDrive or
  • Google Drive

Include:

  • Screen recordings
  • Screenshots
  • Supporting artifacts

Deliverable 3 – Submission

Submit via Microsoft Teams:

✅ Password-protected PDF VAPT Report

✅ OneDrive/Google Drive link

✅ PDF password


Final Checklist

  • NDA signed by all members
  • ROE signed by all members
  • NDA PDF uploaded
  • ROE PDF uploaded
  • Metasploitable and Kali Linux operational
  • Minimum 10 findings documented
  • OWASP Top 10 coverage achieved
  • Executive Summary updated
  • Security Assessment Results updated
  • POC recordings completed
  • Password-protected PDF report created
  • Evidence uploaded to OneDrive/Google Drive
  • Cloud storage link submitted
  • Teams post reacted/liked

Good luck and approach the assessment as a professional penetration testing engagement: identify, validate, document, and communicate your findings effectively.