Hack the Notes: Exploring Pen-Test Documentation

No ratings

Presented at Wild West Hackin' Fest 2026 by

To watch this talk virtually, go to the "Thursday AM Track 1 Livestream Session" My name is Christian Duncan, and I am a security tester with Secure Ideas. I want to share knowledge that I learned along the way when getting into the field. By sharing little pieces of knowledge that have been shared with me I hope to help others find a path into the world of cybersecurity. I thought about things I do every day no matter what the test or task at hand. With that I think the best place to start is with documentation as it is a tool every tester has and constantly is developing. Documentation is one of the most important parts of a tester’s skill set. From note taking during engagements to even how we share new knowledge with others. Our documentation and screenshots can make a huge difference. When I was starting out, I was lost or nervous to ask questions because they might seem dumb. But what I learned is that really everyone else was just as lost at one point and willing to help share knowledge they had.At this point let me give a shout out to the people still rocking a simple .txt document with all your notes. You are in fact mad men and i am all about it. However, I am a little more OCD, and I wanted to find a long-term solution to build out my own personal wiki. Along the way incorporating how I write notes with reporting created a better breakdown to reference during testing and retesting.Through this blog I hope to help share some of the things that I have learned and also been shared with me when it comes to note taking. No one option is perfect, you must find what works best for you. Do your own research and most of all ask questions! The more we ask and share the more that others get to learn and cybersecurity just like anything else is a community. But where do we start when it comes to documentation?*Please note, Christian Duncan will be speaking virtually.