You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
<ahref="../../../12/10/a-great-pentest-needs-a-great-report/" class="md-footer__link md-footer__link--next" aria-label="Next: A Great Pentest Needs a Great Report">
979
+
<ahref="../../../12/10/writing-an-automated-pentest-report/" class="md-footer__link md-footer__link--next" aria-label="Next: Writing an Automated PenTest Report">
<p>This post will explore all the features in Faction that you can use to convert your report templates to Faction automated report templates and create boilerplate text that is easy to integrate into your reports. This will save you hours of time so you can spend more time hacking apps! This will also briefly touch on how to use Faction as an ASPM solution to track your findings to remediation. </p>
922
923
<h1id="a-great-pentest-needs-a-great-report">A Great Pentest Needs a Great Report</h1>
923
924
<p>Your pentest report is the key to building trust and credibility with your clients. It should be polished, consistent, aligned with your brand, and contain all the technical details your clients need to understand the risks behind each finding. With Faction, creating professional reports is simple, thanks to our customizable report templates.</p>
924
925
<p>Faction templates are in DOCX format, so you can easily build and update them using MS Word or LibreOffice — no fancy tools required.</p>
<h2id="a-great-pentest-needs-a-great-report"><aclass="toclink" href="../../2024/12/10/a-great-pentest-needs-a-great-report/">A Great Pentest Needs a Great Report</a></h2>
1000
+
<h2id="writing-an-automated-pentest-report"><aclass="toclink" href="../../2024/12/10/writing-an-automated-pentest-report/">Writing an Automated PenTest Report</a></h2>
1001
+
<p>This post will explore all the features in Faction that you can use to convert your report templates to Faction automated report templates and create boilerplate text that is easy to integrate into your reports. This will save you hours of time so you can spend more time hacking apps! This will also briefly touch on how to use Faction as an ASPM solution to track your findings to remediation. </p>
1002
+
<h2id="a-great-pentest-needs-a-great-report"><aclass="toclink" href="../../2024/12/10/writing-an-automated-pentest-report/#a-great-pentest-needs-a-great-report">A Great Pentest Needs a Great Report</a></h2>
1001
1003
<p>Your pentest report is the key to building trust and credibility with your clients. It should be polished, consistent, aligned with your brand, and contain all the technical details your clients need to understand the risks behind each finding. With Faction, creating professional reports is simple, thanks to our customizable report templates.</p>
1002
1004
<p>Faction templates are in DOCX format, so you can easily build and update them using MS Word or LibreOffice — no fancy tools required.</p>
1003
1005
<p>If your team has been doing this for a while, you probably already have a report theme and layout you don’t want to change. It probably has a slew of highlighted items that need to be updated on every assessment. For example: client name, executive summary, risk assessment, etc. It might look something like this:</p>
If you are just starting a pentest team and need to create a report from scratch, No Worries! Faction has several prebuilt templates you can start with. You only need to tweak your theme and move the elements around to your liking. This can get your new pentest consultancy up and running very quickly.</p>
1008
1010
<p>You can see all the variables that Faction supports <ahref="https://docs.factionsecurity.com/Custom%20Security%20Report%20Templates/">here</a>. If you need other items then you can use Faction’s Custom Variables and they will get auto-populated in the report as well.</p>
<h2id="pentesting-and-note-taking"><aclass="toclink" href="../../2024/12/10/a-great-pentest-needs-a-great-report/#pentesting-and-note-taking">Pentesting and Note-taking</a></h2>
1012
+
<h2id="pentesting-and-note-taking"><aclass="toclink" href="../../2024/12/10/writing-an-automated-pentest-report/#pentesting-and-note-taking">Pentesting and Note-taking</a></h2>
1011
1013
<p>Taking notes is an essential part of penetration testing. As you uncover issues, you’ll jot down details like URLs, parameters, and the steps to reproduce an attack. Many pen-testers rely on tools like Obsidian, OneNote, CherryTree, or similar apps to record this information. Whatever tool you choose, it needs to support rich text and make capturing screenshots quick and easy.</p>
1012
1014
<p>Typically, you’ll compile all your notes during the testing process, and at the end of the engagement, you’ll refine them into a professional report. This involves concisely documenting how to reproduce each finding, including boilerplate text to explain what the issue is, why it’s a risk, and common remediation steps. These details are critical for helping clients understand the business impact of the vulnerability while also showcasing your expertise in remediation. As ethical hackers, our mission goes beyond identifying risks — we provide actionable recommendations to strengthen the client’s security posture.</p>
1013
1015
<p>This is where Faction will save you a ton of time. Faction combines note-taking and reporting into one seamless app, eliminating the need to rewrite or reorganize your notes at the end of the assessment.</p>
<p>Faction also includes a collaborative notebook feature, enabling you to document and share noteworthy findings with your team in real time. This is perfect for capturing observations such as potentially insecure frameworks, partially successful attacks that require further exploration, reconnaissance data, and other insights gathered during the assessment.</p>
<h2id="writing-the-executive-summary"><aclass="toclink" href="../../2024/12/10/a-great-pentest-needs-a-great-report/#writing-the-executive-summary">Writing the Executive Summary</a></h2>
1022
+
<h2id="writing-the-executive-summary"><aclass="toclink" href="../../2024/12/10/writing-an-automated-pentest-report/#writing-the-executive-summary">Writing the Executive Summary</a></h2>
1021
1023
<p>When writing a penetration test report, it’s essential to consider the audience who will be reading it. So far, we’ve focused on the <strong>Technical Findings</strong> section. This section, including Exploit Steps, is vital for technical teams, as they need detailed information to fully understand the issues and implement effective fixes.</p>
1022
1024
<p>The <strong>Executive Summary</strong>, on the other hand, serves a different purpose. It is tailored for managers and non-technical stakeholders, enabling them to evaluate the business risks, make informed prioritization decisions, and grasp the overall significance of the findings at a high level.</p>
1023
1025
<p>A strong Executive Summary addresses these concerns in clear, concise terms, avoiding technical jargon. It should provide a straightforward explanation of why the identified issues matter and offer guidance on prioritizing the findings outlined in the report.</p>
1024
1026
<p>Certain sections of the high-level summary can often be standardized, requiring only minor adjustments for each specific assessment. To streamline this process, Faction offers <strong>global boilerplate templates</strong> that can be effortlessly incorporated into the Executive Summary. These templates can automatically populate variables, saving time and ensuring consistency.</p>
1025
1027
<p>In the screenshot below, you’ll see how easy it is — simply select the <strong>Executive Summary template</strong> from the menu on the right, and it instantly populates the text editor. The template includes customizable variables, such as severity and assessment type, to tailor the content to the current engagement. Best of all, these templates are fully customizable to align with the unique needs of your penetration testing program.</p>
<h2id="peer-review-the-report"><aclass="toclink" href="../../2024/12/10/a-great-pentest-needs-a-great-report/#peer-review-the-report">Peer Review the Report</a></h2>
1029
+
<h2id="peer-review-the-report"><aclass="toclink" href="../../2024/12/10/writing-an-automated-pentest-report/#peer-review-the-report">Peer Review the Report</a></h2>
1028
1030
<p>Once all <strong>Technical Findings</strong> have been documented and the <strong>Executive Summary</strong> is finalized, the next step is to polish your assessment report. Faction’s <strong>Peer Review</strong> feature makes this process seamless by allowing your team to collaborate, suggest edits, and comment on each section of the report. This ensures the final deliverable is free of typos, accurately reflects risk calculations, and maintains a professional appearance.</p>
1029
1031
<p>When you submit a report for Peer Review, your team members are notified via the <strong>Peer Review Queue</strong>. This queue facilitates collaborative editing, enabling multiple reviewers to provide input and make adjustments. The process functions similarly to the <strong>Track Changes</strong> feature found in modern document editors, offering an intuitive way to finalize your report with precision and professionalism.</p>
<h2id="finalize-the-report-and-track-the-risk"><aclass="toclink" href="../../2024/12/10/a-great-pentest-needs-a-great-report/#finalize-the-report-and-track-the-risk">Finalize the Report and Track the Risk</a></h2>
1033
+
<h2id="finalize-the-report-and-track-the-risk"><aclass="toclink" href="../../2024/12/10/writing-an-automated-pentest-report/#finalize-the-report-and-track-the-risk">Finalize the Report and Track the Risk</a></h2>
1032
1034
<p>Once the report has been peer-reviewed, it’s time to finalize it in Faction. Generate the final version of the report to share with the client and schedule your <strong>report-out meeting</strong>. This meeting is a critical step in the process, as it provides an opportunity to review all findings with the client, explain the associated risks to their business, and address any questions or concerns.</p>
1033
1035
<p>During this meeting, you’ll also discuss <strong>remediation SLAs</strong> — the timelines for addressing each finding based on its severity. For example, critical vulnerabilities might need to be remediated within 30 days, while high-severity issues could have a 60-day window.</p>
1034
1036
<p>Faction streamlines this by supporting <strong>custom SLAs</strong> for different risk categories. Tracking begins as soon as the report is finalized. You can configure settings to track only Critical and High findings while excluding Medium and Low findings if desired.</p>
<p>This proactive tracking ensures nothing falls through the cracks, helping both you and your clients maintain accountability and prioritize risk mitigation effectively.</p>
<p>Faction is free and open-source you can download it directly from GitHub here: <ahref="https://github.com/factionsecurity/faction">https://github.com/factionsecurity/faction</a>.</p>
1045
1047
<p>There is additional documentation on the main website: <ahref="https://www.factionsecurity.com/">https://www.factionsecurity.com</a></p>
0 commit comments