Skip to content

Commit 0503caa

Browse files
committed
Deployed 503d1ee with MkDocs version: 1.5.3
1 parent 28b3f2a commit 0503caa

9 files changed

Lines changed: 70 additions & 30 deletions

File tree

blog/2024/03/25/faction-app-store/index.html

Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -902,6 +902,25 @@
902902
</div>
903903
</div>
904904

905+
<div class="md-post__authors md-typeset">
906+
907+
<div class="md-profile md-post__profile">
908+
<span class="md-author md-author--long">
909+
<img src="/files/null0pProfile.png" alt="Josh Summitt">
910+
</span>
911+
<span class="md-profile__description">
912+
<strong>
913+
914+
Josh Summitt
915+
916+
</strong>
917+
<br>
918+
Founder and Chief Architect
919+
</span>
920+
</div>
921+
922+
</div>
923+
905924
<ul class="md-post__meta md-nav__list">
906925
<li class="md-nav__item md-nav__item--section">
907926
<div class="md-post__title">

blog/2024/10/22/how-to-generate-a-vulnerability-report-in-faction/index.html

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@
1414
<link rel="prev" href="../../../03/25/faction-app-store/">
1515

1616

17-
<link rel="next" href="../../../12/10/a-great-pentest-needs-a-great-report/">
17+
<link rel="next" href="../../../12/10/writing-an-automated-pentest-report/">
1818

1919

2020
<link rel="icon" href="../../../../../assets/images/favicon.png">
@@ -976,13 +976,13 @@ <h2 id="below-is-video-showing-how-to-write-a-vulnerability-report-in-under-3-mi
976976

977977

978978

979-
<a href="../../../12/10/a-great-pentest-needs-a-great-report/" class="md-footer__link md-footer__link--next" aria-label="Next: A Great Pentest Needs a Great Report">
979+
<a href="../../../12/10/writing-an-automated-pentest-report/" class="md-footer__link md-footer__link--next" aria-label="Next: Writing an Automated PenTest Report">
980980
<div class="md-footer__title">
981981
<span class="md-footer__direction">
982982
Next
983983
</span>
984984
<div class="md-ellipsis">
985-
A Great Pentest Needs a Great Report
985+
Writing an Automated PenTest Report
986986
</div>
987987
</div>
988988
<div class="md-footer__button md-icon">

blog/2024/12/10/a-great-pentest-needs-a-great-report/index.html renamed to blog/2024/12/10/writing-an-automated-pentest-report/index.html

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@
88

99

1010

11-
<link rel="canonical" href="https://docs.factionsecurity.com/blog/2024/12/10/a-great-pentest-needs-a-great-report/">
11+
<link rel="canonical" href="https://docs.factionsecurity.com/blog/2024/12/10/writing-an-automated-pentest-report/">
1212

1313

1414
<link rel="prev" href="../../../10/22/how-to-generate-a-vulnerability-report-in-faction/">
@@ -20,7 +20,7 @@
2020

2121

2222

23-
<title>A Great Pentest Needs a Great Report - Faction Docs</title>
23+
<title>Writing an Automated PenTest Report - Faction Docs</title>
2424

2525

2626

@@ -115,7 +115,7 @@
115115
<div class="md-header__topic" data-md-component="header-topic">
116116
<span class="md-ellipsis">
117117

118-
A Great Pentest Needs a Great Report
118+
Writing an Automated PenTest Report
119119

120120
</span>
121121
</div>
@@ -883,7 +883,7 @@
883883
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M12 20a8 8 0 0 0 8-8 8 8 0 0 0-8-8 8 8 0 0 0-8 8 8 8 0 0 0 8 8m0-18a10 10 0 0 1 10 10 10 10 0 0 1-10 10C6.47 22 2 17.5 2 12A10 10 0 0 1 12 2m.5 5v5.25l4.5 2.67-.75 1.23L11 13V7h1.5Z"/></svg>
884884
<span class="md-ellipsis">
885885

886-
6 min read
886+
7 min read
887887

888888
</span>
889889
</div>
@@ -919,6 +919,7 @@
919919

920920

921921

922+
<p>This post will explore all the features in Faction that you can use to convert your report templates to Faction automated report templates and create boilerplate text that is easy to integrate into your reports. This will save you hours of time so you can spend more time hacking apps! This will also briefly touch on how to use Faction as an ASPM solution to track your findings to remediation. </p>
922923
<h1 id="a-great-pentest-needs-a-great-report">A Great Pentest Needs a Great Report</h1>
923924
<p>Your pentest report is the key to building trust and credibility with your clients. It should be polished, consistent, aligned with your brand, and contain all the technical details your clients need to understand the risks behind each finding. With Faction, creating professional reports is simple, thanks to our customizable report templates.</p>
924925
<p>Faction templates are in DOCX format, so you can easily build and update them using MS Word or LibreOffice — no fancy tools required.</p>

blog/archive/2024/index.html

Lines changed: 22 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -794,9 +794,9 @@
794794
<ul class="md-nav__list" data-md-component="toc" data-md-scrollfix>
795795

796796
<li class="md-nav__item">
797-
<a href="#a-great-pentest-needs-a-great-report" class="md-nav__link">
797+
<a href="#writing-an-automated-pentest-report" class="md-nav__link">
798798
<span class="md-ellipsis">
799-
A Great Pentest Needs a Great Report
799+
Writing an Automated PenTest Report
800800
</span>
801801
</a>
802802

@@ -909,9 +909,9 @@
909909
<ul class="md-nav__list" data-md-component="toc" data-md-scrollfix>
910910

911911
<li class="md-nav__item">
912-
<a href="#a-great-pentest-needs-a-great-report" class="md-nav__link">
912+
<a href="#writing-an-automated-pentest-report" class="md-nav__link">
913913
<span class="md-ellipsis">
914-
A Great Pentest Needs a Great Report
914+
Writing an Automated PenTest Report
915915
</span>
916916
</a>
917917

@@ -988,7 +988,7 @@ <h1 id="2024">2024</h1>
988988

989989
<li class="md-meta__item">
990990

991-
6 min read
991+
7 min read
992992

993993
</li>
994994

@@ -997,7 +997,9 @@ <h1 id="2024">2024</h1>
997997
</div>
998998
</header>
999999
<div class="md-post__content md-typeset">
1000-
<h2 id="a-great-pentest-needs-a-great-report"><a class="toclink" href="../../2024/12/10/a-great-pentest-needs-a-great-report/">A Great Pentest Needs a Great Report</a></h2>
1000+
<h2 id="writing-an-automated-pentest-report"><a class="toclink" href="../../2024/12/10/writing-an-automated-pentest-report/">Writing an Automated PenTest Report</a></h2>
1001+
<p>This post will explore all the features in Faction that you can use to convert your report templates to Faction automated report templates and create boilerplate text that is easy to integrate into your reports. This will save you hours of time so you can spend more time hacking apps! This will also briefly touch on how to use Faction as an ASPM solution to track your findings to remediation. </p>
1002+
<h2 id="a-great-pentest-needs-a-great-report"><a class="toclink" href="../../2024/12/10/writing-an-automated-pentest-report/#a-great-pentest-needs-a-great-report">A Great Pentest Needs a Great Report</a></h2>
10011003
<p>Your pentest report is the key to building trust and credibility with your clients. It should be polished, consistent, aligned with your brand, and contain all the technical details your clients need to understand the risks behind each finding. With Faction, creating professional reports is simple, thanks to our customizable report templates.</p>
10021004
<p>Faction templates are in DOCX format, so you can easily build and update them using MS Word or LibreOffice — no fancy tools required.</p>
10031005
<p>If your team has been doing this for a while, you probably already have a report theme and layout you don’t want to change. It probably has a slew of highlighted items that need to be updated on every assessment. For example: client name, executive summary, risk assessment, etc. It might look something like this:</p>
@@ -1007,7 +1009,7 @@ <h2 id="a-great-pentest-needs-a-great-report"><a class="toclink" href="../../202
10071009
If you are just starting a pentest team and need to create a report from scratch, No Worries! Faction has several prebuilt templates you can start with. You only need to tweak your theme and move the elements around to your liking. This can get your new pentest consultancy up and running very quickly.</p>
10081010
<p>You can see all the variables that Faction supports <a href="https://docs.factionsecurity.com/Custom%20Security%20Report%20Templates/">here</a>. If you need other items then you can use Faction’s Custom Variables and they will get auto-populated in the report as well.</p>
10091011
<p><img alt="" src="/files/Pasted%20image%2020241210181739.png" /></p>
1010-
<h2 id="pentesting-and-note-taking"><a class="toclink" href="../../2024/12/10/a-great-pentest-needs-a-great-report/#pentesting-and-note-taking">Pentesting and Note-taking</a></h2>
1012+
<h2 id="pentesting-and-note-taking"><a class="toclink" href="../../2024/12/10/writing-an-automated-pentest-report/#pentesting-and-note-taking">Pentesting and Note-taking</a></h2>
10111013
<p>Taking notes is an essential part of penetration testing. As you uncover issues, you’ll jot down details like URLs, parameters, and the steps to reproduce an attack. Many pen-testers rely on tools like Obsidian, OneNote, CherryTree, or similar apps to record this information. Whatever tool you choose, it needs to support rich text and make capturing screenshots quick and easy.</p>
10121014
<p>Typically, you’ll compile all your notes during the testing process, and at the end of the engagement, you’ll refine them into a professional report. This involves concisely documenting how to reproduce each finding, including boilerplate text to explain what the issue is, why it’s a risk, and common remediation steps. These details are critical for helping clients understand the business impact of the vulnerability while also showcasing your expertise in remediation. As ethical hackers, our mission goes beyond identifying risks — we provide actionable recommendations to strengthen the client’s security posture.</p>
10131015
<p>This is where Faction will save you a ton of time. Faction combines note-taking and reporting into one seamless app, eliminating the need to rewrite or reorganize your notes at the end of the assessment.</p>
@@ -1017,18 +1019,18 @@ <h2 id="pentesting-and-note-taking"><a class="toclink" href="../../2024/12/10/a-
10171019
<p><img alt="" src="/files/Pasted%20image%2020241210181844.png" /></p>
10181020
<p>Faction also includes a collaborative notebook feature, enabling you to document and share noteworthy findings with your team in real time. This is perfect for capturing observations such as potentially insecure frameworks, partially successful attacks that require further exploration, reconnaissance data, and other insights gathered during the assessment.</p>
10191021
<p><img alt="" src="/files/Pasted%20image%2020241210181856.png" /></p>
1020-
<h2 id="writing-the-executive-summary"><a class="toclink" href="../../2024/12/10/a-great-pentest-needs-a-great-report/#writing-the-executive-summary">Writing the Executive Summary</a></h2>
1022+
<h2 id="writing-the-executive-summary"><a class="toclink" href="../../2024/12/10/writing-an-automated-pentest-report/#writing-the-executive-summary">Writing the Executive Summary</a></h2>
10211023
<p>When writing a penetration test report, it’s essential to consider the audience who will be reading it. So far, we’ve focused on the <strong>Technical Findings</strong> section. This section, including Exploit Steps, is vital for technical teams, as they need detailed information to fully understand the issues and implement effective fixes.</p>
10221024
<p>The <strong>Executive Summary</strong>, on the other hand, serves a different purpose. It is tailored for managers and non-technical stakeholders, enabling them to evaluate the business risks, make informed prioritization decisions, and grasp the overall significance of the findings at a high level.</p>
10231025
<p>A strong Executive Summary addresses these concerns in clear, concise terms, avoiding technical jargon. It should provide a straightforward explanation of why the identified issues matter and offer guidance on prioritizing the findings outlined in the report.</p>
10241026
<p>Certain sections of the high-level summary can often be standardized, requiring only minor adjustments for each specific assessment. To streamline this process, Faction offers <strong>global boilerplate templates</strong> that can be effortlessly incorporated into the Executive Summary. These templates can automatically populate variables, saving time and ensuring consistency.</p>
10251027
<p>In the screenshot below, you’ll see how easy it is — simply select the <strong>Executive Summary template</strong> from the menu on the right, and it instantly populates the text editor. The template includes customizable variables, such as severity and assessment type, to tailor the content to the current engagement. Best of all, these templates are fully customizable to align with the unique needs of your penetration testing program.</p>
10261028
<p><img alt="" src="/files/Pasted%20image%2020241210181909.png" /></p>
1027-
<h2 id="peer-review-the-report"><a class="toclink" href="../../2024/12/10/a-great-pentest-needs-a-great-report/#peer-review-the-report">Peer Review the Report</a></h2>
1029+
<h2 id="peer-review-the-report"><a class="toclink" href="../../2024/12/10/writing-an-automated-pentest-report/#peer-review-the-report">Peer Review the Report</a></h2>
10281030
<p>Once all <strong>Technical Findings</strong> have been documented and the <strong>Executive Summary</strong> is finalized, the next step is to polish your assessment report. Faction’s <strong>Peer Review</strong> feature makes this process seamless by allowing your team to collaborate, suggest edits, and comment on each section of the report. This ensures the final deliverable is free of typos, accurately reflects risk calculations, and maintains a professional appearance.</p>
10291031
<p>When you submit a report for Peer Review, your team members are notified via the <strong>Peer Review Queue</strong>. This queue facilitates collaborative editing, enabling multiple reviewers to provide input and make adjustments. The process functions similarly to the <strong>Track Changes</strong> feature found in modern document editors, offering an intuitive way to finalize your report with precision and professionalism.</p>
10301032
<p><img alt="" src="/files/Pasted%20image%2020241210181921.png" /></p>
1031-
<h2 id="finalize-the-report-and-track-the-risk"><a class="toclink" href="../../2024/12/10/a-great-pentest-needs-a-great-report/#finalize-the-report-and-track-the-risk">Finalize the Report and Track the Risk</a></h2>
1033+
<h2 id="finalize-the-report-and-track-the-risk"><a class="toclink" href="../../2024/12/10/writing-an-automated-pentest-report/#finalize-the-report-and-track-the-risk">Finalize the Report and Track the Risk</a></h2>
10321034
<p>Once the report has been peer-reviewed, it’s time to finalize it in Faction. Generate the final version of the report to share with the client and schedule your <strong>report-out meeting</strong>. This meeting is a critical step in the process, as it provides an opportunity to review all findings with the client, explain the associated risks to their business, and address any questions or concerns.</p>
10331035
<p>During this meeting, you’ll also discuss <strong>remediation SLAs</strong> — the timelines for addressing each finding based on its severity. For example, critical vulnerabilities might need to be remediated within 30 days, while high-severity issues could have a 60-day window.</p>
10341036
<p>Faction streamlines this by supporting <strong>custom SLAs</strong> for different risk categories. Tracking begins as soon as the report is finalized. You can configure settings to track only Critical and High findings while excluding Medium and Low findings if desired.</p>
@@ -1040,11 +1042,11 @@ <h2 id="finalize-the-report-and-track-the-risk"><a class="toclink" href="../../2
10401042
</ul>
10411043
<p>This proactive tracking ensures nothing falls through the cracks, helping both you and your clients maintain accountability and prioritize risk mitigation effectively.</p>
10421044
<p><img alt="" src="/files/Pasted%20image%2020241210181938.png" /></p>
1043-
<h2 id="additional-information"><a class="toclink" href="../../2024/12/10/a-great-pentest-needs-a-great-report/#additional-information">Additional Information</a></h2>
1045+
<h2 id="additional-information"><a class="toclink" href="../../2024/12/10/writing-an-automated-pentest-report/#additional-information">Additional Information</a></h2>
10441046
<p>Faction is free and open-source you can download it directly from GitHub here: <a href="https://github.com/factionsecurity/faction">https://github.com/factionsecurity/faction</a>.</p>
10451047
<p>There is additional documentation on the main website: <a href="https://www.factionsecurity.com/">https://www.factionsecurity.com</a></p>
10461048
<nav class="md-post__action">
1047-
<a href="../../2024/12/10/a-great-pentest-needs-a-great-report/">
1049+
<a href="../../2024/12/10/writing-an-automated-pentest-report/">
10481050
Continue reading
10491051
</a>
10501052
</nav>
@@ -1086,6 +1088,14 @@ <h3 id="below-is-video-showing-how-to-write-a-vulnerability-report-in-under-3-mi
10861088
<article class="md-post md-post--excerpt">
10871089
<header class="md-post__header">
10881090

1091+
<nav class="md-post__authors md-typeset">
1092+
1093+
<span class="md-author">
1094+
<img src="/files/null0pProfile.png" alt="Josh Summitt">
1095+
</span>
1096+
1097+
</nav>
1098+
10891099
<div class="md-post__meta md-meta">
10901100
<ul class="md-meta__list">
10911101
<li class="md-meta__item">

0 commit comments

Comments
 (0)