Pentest Process
2min read
Learn about the pentest lifecycle.
:::info Explore the stages of the Cobalt Pentest as a Service (PtaaS) program.
:::
| Stage | Description | |
|---|---|---|
| 1 | Discover | Prepare for the pentest engagement. \n•Map the attack surface of your software. \n•Create an account on the Cobalt platform following our invitation. Our CSM team will get in touch with you. |
| 2 | Plan | Plan, scope, and schedule your pentest. \n•See our Getting Started guide to learn how to launch a pentest. If you need help, contact us. \n•Prepare the environment for our pentesters, such as set up test credentials for them. Note: Your organization is responsible for deleting/disabling or rotating any credentials issued during this test once the testing process is complete. \n•Alert the stakeholders in your organization about the upcoming pentest. \n•Once you’ve submitted the pentest, we’ll assign pentesters based on your technology stack. |
| 3 | Test | Pentesters test your asset using various pentest methodologies and techniques. \n•Pentesters share vulnerabilities that they discover in real time, in Slack and in the Cobalt app. Learn more about collaborating on a pentest. \n•At this stage, you can start remediating findings that pentesters discover. \n•The standard testing period is 14 days. It may vary depending on the pentest scope and other factors. |
| 4 | Remediate | The testing process is complete. Remediate findings that pentesters discovered. \n•You can submit a finding for retest or accept the risk. \n•Retesting is included in the pentest program. Learn more about the free retesting duration. \n•We recommend that you remediate findings promptly to minimize any potential security incidents that may arise from the identified vulnerabilities. \n•At this stage, the Pentest Lead works on the pentest report. For Agile Pentests, you get an Automated Report. \n•You can configure integrations to post findings to your preferred task management software. |
| 5 | Report | Download the pentest report to view a summary of vulnerabilities in your software. Share the report with stakeholders. \n•The report will be available 2 to 3 business days after the pentest is complete. \n•The content of the report differs depending on the report type. |
| 6 | Analyze | Once the pentest is complete, analyze the security posture of your asset. \n•Deep dive into the pentest report to assess discovered vulnerabilities with your development and security teams. \n•Take the required remediation actions. \n•Identify what you expect from your next pentest for this asset. |
