Ethical Hacking & Penetration Testing Coach
Cybersecurity & Pentesting. Which area of security (OWASP web vulnerabilities, network reconnaissance, OSCP certification preparation) do you want to dive into today?
What this persona helps with (Core Capabilities)
- ◆Web application security (OWASP Top 10), reconnaissance, vulnerability analysis, CEH/OSCP certifications, and audits
- ◆Drives a structured step-by-step process
- ◆Delivers immediate, practical results
How it works proactively — without waiting to be asked
Asks one sharp question in every round
Helps you put the agreed steps into practice
Tracks your progress and distills the essence of the conversation
Install in 60 seconds
- 1Copy the system prompt above with one click.
- 2Paste it into a Claude Project, ChatGPT Custom Instructions / Custom GPT or a Gemini Gem. (You can also just paste it as the first message in a new chat.)
- 3Install the prompt in Claude Projects, ChatGPT, or Gemini. Answer the assistant's first question and start putting your daily micro-steps into practice.
A sample dialogue in practice
The Full System Prompt
482 words · Ready to use right away
Methodology & LLM Verification
This prompt is engineered for high precision on GPT-4o, Claude 3.5 Sonnet and Gemini 1.5 Pro. It uses Chain-of-Thought, few-shot prompting and strict role framing.
Frequently Asked Questions (FAQ)
What exactly does the Ethical Hacking & Penetration Testing Coach prompt specialize in?+
Web application security (OWASP Top 10), reconnaissance, vulnerability analysis, CEH/OSCP certifications, and audits Drives a structured step-by-step process Delivers immediate, practical results
How do I put this persona to work every day?+
Copy the prompt and add it to a Claude or ChatGPT project. The persona is tuned for 5 min/day of focused interaction.
Is access to the persona free?+
Yes. All 250 prompts in SUPERMIND are 100% free and open to use.
Does it replace professional advice or therapy?+
No. It is a tool that supports self-reflection, productivity and strategic thinking. It does not replace medical, legal or financial advice from a professional.
Do I need written permission to test a system?+
Always, with the scope, the time window, and the systems explicitly named, signed by someone authorized to give it. Testing without it is a crime in most jurisdictions regardless of intent. Bug bounty programs count as permission only within their stated scope.
Where should a beginner start?+
Networking and Linux fundamentals, then web basics, then the OWASP Top 10 with hands-on labs such as PortSwigger Academy or TryHackMe. Certifications like CEH are theory-heavy; OSCP and its labs are what employers read as evidence you can actually test.
What are the most common real-world findings?+
Broken access control, missing authorization on API endpoints, secrets in client code or repositories, outdated dependencies, and misconfigured storage buckets. Injection still appears, but authorization failures now dominate the reported lists and payouts.
How do I write a report that gets the issue fixed?+
Summary for management, then per finding: description, reproduction steps, impact in business terms, evidence, severity, and a specific remediation. A finding without reproduction steps is a claim. Include what you tested and could not break — it shows coverage.
What is off limits in practice?+
Production data beyond what proves the finding, denial-of-service tests unless explicitly agreed, social engineering of employees, and third-party services outside scope. Stop at proof, document the timestamp, and never download more data than the minimum needed.
Related Assistants and Recommendations
Personas that complement the skills and method of Ethical Hacking & Penetration Testing Coach