Web Application Attack Reconstruction through Integration of PTES and DFRWS Methods
DOI:
https://doi.org/10.33394/j-ps.v14i4.21089Keywords:
PTES, DFRWS, Digital forensics, Penetration testing, Attack reconstruction, Web application securityAbstract
This study aims to analyze the relationship between attack processes and digital artifacts through an integrated approach using the Penetration Testing Execution Standard (PTES) and the Digital Forensic Research Workshop (DFRWS), applied to a single controlled file upload attack scenario in the Simanisgizi web application. The method used includes the PTES stage as a structured penetration testing methodology to systematically identify system vulnerabilities, and the DFRWS stage to identify, collect, and analyze the resulting digital evidence. The results indicate that the system has a vulnerability in the file upload feature that allows malicious files to enter the server. However, attempts to execute commands via the webshell were unsuccessful, as indicated by an HTTP 404 response on each request. This indicates the existence of partial controls in the system that limit further exploitation. Based on log analysis, the attacker's activity patterns and sequence of events were successfully reconstructed systematically. Thus, the integration of PTES and DFRWS can provide a more comprehensive understanding of the relationship between attack techniques and the resulting digital evidence.
References
Alazmi, S., & de Leon, D. C. (2022). A systematic literature review on the characteristics and effectiveness of web application vulnerability scanners. IEEE Access, 10, 33200–33219. https://doi.org/10.1109/ACCESS.2022.3161522
Alhamed, M., & Rahman, M. M. H. (2023). A systematic literature review on penetration testing in networks: Future research directions. Applied Sciences, 13(12), Article 6986. https://doi.org/10.3390/app13126986
Alshumrani, A., Clarke, N., & Ghita, B. (2023). A unified forensics analysis approach to digital investigation. International Conference on Cyber Warfare and Security, 18(1), 466–475. https://doi.org/10.34190/iccws.18.1.972
Andhika, D. A., Slamet, & Ningsih, N. (2022). Pengujian penetrasi pada Windows 10 menggunakan model Penetration Testing Execution Standard (PTES). Journal of Technology and Informatics (JoTI), 3(2), 55–61. https://doi.org/10.37802/joti.v3i2.222
Astrida, D. N., Saputra, A. R., & Assaufi, A. I. (2022). Analysis and evaluation of wireless network security with the Penetration Testing Execution Standard (PTES). Sinkron, 7(1), 147–154. https://doi.org/10.33395/sinkron.v7i1.11249
Breitinger, F., Hilgert, J.-N., Hargreaves, C., Sheppard, J., Overdorf, R., & Scanlon, M. (2024). DFRWS EU 10-year review and future directions in digital forensic research. Forensic Science International: Digital Investigation, 48, Article 301685. https://doi.org/10.1016/j.fsidi.2023.301685
Breitinger, F., Studiawan, H., & Hargreaves, C. (2025). SoK: Timeline based event reconstruction for digital forensics: Terminology, methodology, and current challenges. Forensic Science International: Digital Investigation, 53, Article 301932. https://doi.org/10.1016/j.fsidi.2025.301932
Burhani, L. F., & Priyawati, D. (2024). Analisis pengujian keamanan website pengelolaan internet Desa Kragan menggunakan metode Penetration Testing Execution Standard (PTES). JIPI (Jurnal Ilmiah Penelitian dan Pembelajaran Informatika), 9(1), 307–319. https://doi.org/10.29100/jipi.v9i1.4455
Casino, F., Dasaklis, T. K., Spathoulas, G. P., Anagnostopoulos, M., Ghosal, A., Borocz, I., Solanas, A., Conti, M., & Patsakis, C. (2022). Research trends, challenges, and emerging topics in digital forensics: A review of reviews. IEEE Access, 10, 25464–25493. https://doi.org/10.1109/ACCESS.2022.3154059
Casey, E. (2020). Standardization of forming and expressing preliminary evaluative opinions on digital evidence. Forensic Science International: Digital Investigation, 32, Article 200888. https://doi.org/10.1016/j.fsidi.2019.200888
Dreier, L. M., Vanini, C., Hargreaves, C. J., Breitinger, F., & Freiling, F. (2024). Beyond timestamps: Integrating implicit timing information into digital forensic timelines. Forensic Science International: Digital Investigation, 49, Article 301755. https://doi.org/10.1016/j.fsidi.2024.301755
Elyas, M., Ahmad, A., Maynard, S. B., & Lonie, A. (2015). Digital forensic readiness: Expert perspectives on a theoretical framework. Computers & Security, 52, 70–89. https://doi.org/10.1016/j.cose.2015.04.003
Fadhilah, F. F. (2023). Implementasi modul otomatisasi penetration testing menggunakan Bourne Again Shell scripting pada website aplikasi Stream PT. Intikom Berlian Mustika berbasis Kali Linux [Tugas akhir diploma, Universitas Gadjah Mada]. Repositori Universitas Gadjah Mada. https://etd.repository.ugm.ac.id/penelitian/detail/225546
Fahrudin, A., & Zaida Muflih, G. (2025). Analisis forensik digital pada pesan WhatsApp yang terenkripsi dengan Pretty Good Privacy (PGP) menggunakan framework DFRWS. Jurnal Mahasiswa Teknik Informatika, 9(1). https://doi.org/10.36040/jati.v9i1.12506
Faisal, I., Budiman, A., & Fitiria, E. I. (2023). Penerapan Digital Forensics Research Workshop dalam akuisisi evidence forensik aplikasi Snack Video. Jurnal Komputer Teknologi Informasi Sistem Komputer, 2(2). https://doi.org/10.62712/juktisi.v2i2.108
Firnanda, M. Y., Wahanani, H. E., & Junaidi, A. (2025). Website security testing using PTES method and OWASP Top 10 approach. Bit-Tech, 8(1), 404–415. https://doi.org/10.32877/bt.v8i1.2564
Galang Saputra, S., & Parga Zen, B. (2023). Analisis keamanan jaringan wireless menggunakan metode Penetration Testing Execution Standard (PTES). Jurnal Sistem Informasi Galuh, 1(2). https://doi.org/10.25157/jsig.v1i2.3152
Genggam, R. M., Bintang, S., Arya Bahytsani, D., Ajuj Mudzakkar, A., Siber, R. K., Siber, P., & Negara, S. (2024). Analisis bukti digital forensik pada aplikasi Threads menggunakan metode Digital Forensic Research Workshop. Jurnal Informatika Komputer, Bisnis dan Manajemen, 22(2). https://doi.org/10.61805/fahma.v22i2.118
Ghabban, F. M., Alfadli, I. M., Ameerbakhsh, O., AbuAli, A. N., Al-Dhaqm, A. M. R., & Al-Khasawneh, M. A. (2021). Comparative analysis of network forensic tools and network forensics processes. In 2021 International Conference on Sustainable Computing and Emerging Engineering (ICSCEE). IEEE. https://doi.org/10.1109/ICSCEE50312.2021.9498226
Hargreaves, C., & Patterson, J. (2012). An automated timeline reconstruction approach for digital forensic investigations. Digital Investigation, 9(Supplement), S69–S79. https://doi.org/10.1016/j.diin.2012.05.006
Horsman, G. (2020). Opinion: Does the field of digital forensics have a consistency problem? Forensic Science International: Digital Investigation, 33, Article 300970. https://doi.org/10.1016/j.fsidi.2020.300970
Horsman, G. (2023). Digital evidence strategies for digital forensic science examinations. Science & Justice, 63(1), 116–126. https://doi.org/10.1016/j.scijus.2022.11.004
Horsman, G. (2025). GAMEPLANS: A template for robust digital evidence strategy development. Journal of Forensic Sciences, 70(1), 369–375. https://doi.org/10.1111/1556-4029.15655
Kurniawan, B., Ruslianto, I., & Bahri, S. (2023). Implementation of penetration testing on the website using the Penetration Testing Execution Standard (PTES) method. Journal of Computing Engineering, System and Science, 8(2), 518–528. https://doi.org/10.24114/cess.v8i2.47096
Listartha, I. M. E., & Saskara, G. A. J. (2024). Pengujian keamanan dengan metode Penetration Testing Execution Standard (PTES) untuk menemukan kerentanan misconfigurations pada perangkat jaringan. Electro Luceat, 10(2), 32–40. https://doi.org/10.32531/jelekn.v10i2.821
Lone, A. H., & Mir, R. N. (2019). Forensic-chain: Blockchain based digital forensics chain of custody with PoC in Hyperledger Composer. Digital Investigation, 28, 44–55. https://doi.org/10.1016/j.diin.2019.01.002
Olegård, J., Axelsson, S., & Li, Y. (2025). When is logging sufficient? Tracking event causality for improved forensic analysis and correlation. Forensic Science International: Digital Investigation, 52, Article 301877. https://doi.org/10.1016/j.fsidi.2025.301877
OWASP Foundation. (2021). WSTG: Introduction and objectives. OWASP Web Security Testing Guide. https://owasp.org/www-project-web-security-testing-guide/stable/4-Web_Application_Security_Testing/00-Introduction_and_Objectives/
Putra, B. S., & Santoso, D. B. (2025). Analisis keamanan website berbasis WordPress melalui penetration testing untuk meningkatkan keamanan digital. Jurnal JTIK (Jurnal Teknologi Informasi dan Komunikasi), 9(3), 981–990. https://doi.org/10.35870/jtik.v9i3.3692
Ridwan. (2024). Using the Penetration Testing Execution Standard method (PTES) for wireless network security analysis. Greenation Computer and Information Review, 1(1). https://doi.org/10.38035/gcir.v1i1
Rinaldi, M. A., Abdillah, R., . N., & . P. (2026). Security evaluation of the TIF dashboard using the Penetration Testing Execution Standard (PTES) methodology. Engineering and Technology Journal, 11(5). https://doi.org/10.47191/etj/v11i05.04
Ryser, E., Spichiger, H., & Casey, E. (2020). Structured decision making in investigations involving digital and multimedia evidence. Forensic Science International: Digital Investigation, 34, Article 301015. https://doi.org/10.1016/j.fsidi.2020.301015
Sokol, P., Antoni, Ľ., Krídlo, O., Marková, E., Kováčová, K., & Krajči, S. (2023). Formal concept analysis approach to understand digital evidence relationships. International Journal of Approximate Reasoning, 159, Article 108940. https://doi.org/10.1016/j.ijar.2023.108940
Soltani, S., & Hosseini Seno, S. A. (2019). A formal model for event reconstruction in digital forensic investigation. Digital Investigation, 30, 148–160. https://doi.org/10.1016/j.diin.2019.07.006
Stoykova, R., Andersen, S., Franke, K., & Axelsson, S. (2022). Reliability assessment of digital forensic investigations in the Norwegian police. Forensic Science International: Digital Investigation, 40, Article 301351. https://doi.org/10.1016/j.fsidi.2022.301351
Stoykova, R., & Franke, K. (2023). Reliability validation enabling framework (RVEF) for digital forensics in criminal investigations. Forensic Science International: Digital Investigation, 45, Article 301554. https://doi.org/10.1016/j.fsidi.2023.301554
Sulistyo, W. Y., Pratiwi, S. A., Haedar, M., & Hidayatullah, Z. (2025). Analisis forensik citra di platform X menggunakan metode Digital Forensic Research Workshop (DFRWS). Idealis: Indonesia Journal Information System, 8(1). https://doi.org/10.36080/idealis.v8i1.3293
Sunde, N. (2022). Strategies for safeguarding examiner objectivity and evidence reliability during digital forensic investigations. Forensic Science International: Digital Investigation, 40, Article 301317. https://doi.org/10.1016/j.fsidi.2021.301317
Suryaningrat, A., Ramayanti, D., Taberima, G. M., & Kurniawan, P. P. (2024). File upload security: Essential practices for programmers. CCIT Journal, 17(2). https://doi.org/10.33050/ccit.v17i2.3172
Triyanto, J., Sunardi, & Riadi, I. (2022). Analisis investigasi cyber espionage pada Facebook menggunakan Digital Forensics Research Workshop (DFRWS). Techno, 23(1), 39–46. https://doi.org/10.30595/techno.v23i1.9064
Tully, G., Cohen, N., Compton, D., Davies, G., Isbell, R., & Watson, T. (2020). Quality standards for digital forensics: Learning from experience in England & Wales. Forensic Science International: Digital Investigation, 32, Article 200905. https://doi.org/10.1016/j.fsidi.2020.200905
Vanini, C., Hargreaves, C. J., van Beek, H., & Breitinger, F. (2024). Was the clock correct? Exploring timestamp interpretation through time anchors for digital forensic event reconstruction. Forensic Science International: Digital Investigation, 49, Article 301759. https://doi.org/10.1016/j.fsidi.2024.301759
Wibowo, M., Firmansyah, M. R., & Efendi, R. S. (2024). Analisis bukti digital pada aplikasi Discord Desktop dengan menggunakan framework DFRWS. Jurnal Ilmiah Teknologi Informasi dan Komunikasi. https://doi.org/10.51903/jtikp.v15i1.826
Widianto, F., Wijaya, E. S., Harjono, H., & Wicaksono, A. P. (2025). Analisis kerentanan pada aplikasi web menggunakan metode PTES. Jurnal Pendidikan dan Teknologi Indonesia, 5(1), 155–166. https://doi.org/10.52436/1.jpti.609
Yudhana, A., Riadi, I., & Prasongko, R. Y. (2022). Forensik WhatsApp menggunakan metode Digital Forensic Research Workshop (DFRWS). Jurnal Informatika: Jurnal Pengembangan IT, 7(1), 43–48. https://doi.org/10.30591/jpit.v7i1.3639
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Danur Wijayanto, Aditya Cahyadi

This work is licensed under a Creative Commons Attribution 4.0 International License.
Authors who publish with this journal agree to the following terms:
- Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under a Creative Commons Attribution License that allows others to share the work with an acknowledgement of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgement of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work (See The Effect of Open Access).

This work is licensed under a Creative Commons Attribution 4.0 International License.

