Creating a Pentest
To create a Pentest, you need to click on the “Start New Pentest” button on the right side of the top bar. When you click it, a pop-up asking for the new pentest information like start date, department, frequency, and release version will show. Department and Release Version can be used to give projects unique names to identify the engagement.
Adding an Asset
Assets have to be added while creating a pentest. During this process, you can add an existing asset by selecting them from the list by checking the checkboxes on the left side.
You can also add new Assets to the Pentest by choosing the platform (Web App, API, Mobile App, IT Infrastructure, Cloud) and filling in all the information that is required including Name, No. of User Roles, No. of Dynamic Pages.
Adding a New Member to the Team
Pentest Manager
The Pentest Manager is in charge of overseeing the entire pentest by looking after the team. Unless another person is selected or a new person is invited, the Pentest Manager will be the person who created the pentest by default.
This persona has the ability to edit all data, schedule new pentests, and invite new team members.
You can add a Pentest Manager during the onboarding process or while creating a new Pentest. After going through the initial steps of adding your and the pentests' information, you will arrive at the "Add Pentest Manager" page.
On this page, you can add a new member or select someone from the team directory.
To add a new person, simply enter their name and email address and click the "Invite" button; the New Pentest Manager will be added and a pop-up will appear confirming the invitation was sent. The newly invited person will receive an invitation in the email address provided, along with a link and OTP to begin their onboarding process.
Pentest Overseers
Pentest Overseers have access to all information related to their assigned pentest. This persona can download reports and communicate with other related members via the chat functionality.
Just like on the previous page, you can add a New Person or select someone from the team directory.
To add a new person, simply enter their name and email address and click the "Invite" button; the New Pentest Overseer will be added. The invited person will receive an invitation in the email address provided, along with a link and OTP to begin their onboarding process.
Point of Contact
The person in charge of their assigned asset is the point of contact, and they will report directly to the Pentest Manager. This persona can only see the assets assigned to them and can change the status of a finding.
On the Point of Contact page, you will see a list of all the assets that have been added to the pentest, as well as dropdown lists where you can select existing team members on the right side.
To add a new person as the Point of Contact, click the "Invite" button inside the dropdown, which should bring up a pop-up.
In the pop-up, enter the new Point of Contact's name and email address. The newly invited person will receive an invitation in the email address provided, along with a link and OTP to begin their onboarding process.
Once you click on Invite Now, a pop-up confirming the team member has been invited is shown.