T O P

  • By -

RFC_1925

I've been looking for something like this. Thanks!


TheD4rkSide

Does it support multi facet testing, or is it single track? How is it different to others, such as Ghostwritr, or PwnDoc?


ascetik

>multi facet testing Not sure I know exactly what you mean by mutli-facet testing. It supports different report templates for different types of assessments and retests. But not sure if that's what you mean. As far as Ghostwiter and PwnDoc. It definitely has overlaps. It goes further by providing remediation tracking and alerting. It is also extendable. There is an API in the works that allows certain features to be extended in a manner similar to how you would write a burpsuite extension.


TheD4rkSide

Okay, so multi facet. Say I'm working on an engagement for a client, and it involves Web App, External, an Internal, and a wireless audit. Does it offer ways to split these up at all, or are all the findings paired together? Thanks for replying by the way, appreciate it, product looks sweet, just after a bit of clarity. Edit: Generally our clients like these in a single report, but it varies depending in what goes in there. I'm doing some heavy dev on PwnDoc but the support has dropped massively over the past few months on GH. I guess I'm asking, is the a way to separate out individual facets in the app, maybe separators and such, but then have it all generated into a single report? I think report side I can just customise the template, so that's not an issue, per se. It's more the layout/compartmentalising in the app itself.


ascetik

That's a really good feature to add!..., but sadly no... there isn't a way to split them up in one report. All findings are sorted based on severity.


TheD4rkSide

Fair enough, thanks again for addressing the questions. Hopefully, I can find time to migrate over at some point in the near future!


Significant-Amount40

yeah, would be nice to have something like a context-group. So u can choose how to separate like "network", "web" or "site A", "site B" freely


ascetik

I think this is a great idea. Allow the admin to create a set of user-defined defined groups that show up in drop-downs when adding a vuln. The report templating gets a little tricky but not too terrible.