---
title: "Set Up an In-House Pentest"
description: "Learn how to launch an in-house pentest on the Cobalt platform."
canonical_url: "https://docs.cobalt.io/articles/set-up-an-in-house-pentest-K9sgKIXq6Y"
md_url: "https://docs.cobalt.io/articles/set-up-an-in-house-pentest-K9sgKIXq6Y.md"
---
# Set Up an In-House Pentest

Learn how to launch an in-house pentest on the Cobalt platform.


:::info
This page is for users who manage in-house pentests for their organization. If you’re an In-House Pentester, please read [how to complete a pentest](https://cobalt-io.brainfish.ai/en-us/articles/complete-an-in-house-pentest-for-pentesters-y7RCf5izE6).

:::

An In-House Pentest is a pentest that an organization performs on the Cobalt platform without involving Cobalt pentesters. The workflow for In-House Pentests is similar to other pentests that you run on the Cobalt platform.

## Getting Started

### Set up an Asset

If you don’t yet have assets, [set up an asset](https://cobalt-io.brainfish.ai/articles/create-an-asset-9P1WPENeIC). An asset is a either a software component of value, such as a web application or API, or a network environment.

* You can run In-House Pentests on assets that you’ve already tested on the Cobalt platform.
* Learn more about the [asset types](https://cobalt-io.brainfish.ai/en-us/articles/asset-types-OQp8vLaQ85) we support.

### Prepare for a Pentest

To avoid disrupting workflows in your organization, notify your team about the upcoming pentest. Learn [how to prepare for a pentest](https://cobalt-io.brainfish.ai/en-us/articles/how-to-get-started-with-cobalt-Di38tyRXvB).

Define who will work on the pentest:

* [In-House Pentesters](/articles/how-to-get-started-with-cobalt-Di38tyRXvB) test your asset and report vulnerabilities. You can invite pentesters from your organization, a third-party company, or both.
* [Pentest Team Members](https://cobalt-io.brainfish.ai/en-us/articles/user-roles-and-permissions-oCij6uRrUR#h-pentest-team-member) collaborate on the pentest and address findings. As an Organization Owner or Member, you need to have a Pentest Team Member role to collaborate on the pentest.

## **Create an In-House Pentest**

 ![](https://docs.cobalt.io/api/attachments.redirect?id=d235d4cf-5302-48ad-bb92-60488f5d9629)

As an [Organization Owner](https://cobalt-io.brainfish.ai/en-us/articles/user-roles-and-permissions-oCij6uRrUR#h-organization-owner) or [Member](https://cobalt-io.brainfish.ai/en-us/articles/user-roles-and-permissions-oCij6uRrUR#h-organization-member), you can set up an In-House Pentest—following the same steps as for other [pentest types](https://cobalt-io.brainfish.ai/en-us/articles/overview-PXa8agvnpp#h-3-set-the-test-focus). Some parameters in the pentest wizard may slightly differ for In-House Pentests.

To launch an In-House Pentest:


1. On the **Pentests** page, select **Create a Pentest**.
2. To enroll in the beta program for the Pentest Management Platform, select **Learn more**, and then select **Enter the Beta**.
3. Under **In-House Pentest**, select or create an asset that you want to test, and then select **Continue**.

 ![](https://docs.cobalt.io/api/attachments.redirect?id=fa2a0a80-da9a-4f40-afcf-a6f535a9a40f)



4. In the pentest wizard, complete the following steps:
   * [Review your asset](https://cobalt-io.brainfish.ai/en-us/articles/asset-details-DOTnqhyuxS).
   * Set [requirements](https://cobalt-io.brainfish.ai/en-us/articles/pentest-details-LXoQDryEPD) for your pentest.
   * Define the [details](https://cobalt-io.brainfish.ai/en-us/articles/create-a-pentest-BQSirXEl9M) of your environment.
   * Schedule the pentest by setting your desired start and end date. The start date and testing period are flexible.
5. [Review your pentest](https://cobalt-io.brainfish.ai/en-us/articles/preparation-QCKhMdow4z) to make sure you’ve included all information that your pentesters need. When ready, select **Move to Planned**.
6. Invite collaborators to the pentest. Select the key for instructions.

### To invite an In-House Pentester:


1. On the pentest page, go to **Collaborators**.
2. Enter the user’s email address, select the arrow next to **Add Team Member**, and then select **In-House Pentester**. Select **Add In-House Pentester** to confirm.  ![](https://docs.cobalt.io/api/attachments.redirect?id=ba34d24b-c625-4517-b90b-8071f29fab25)

The user gets an email invite to work on the pentest. An In-House Pentester role has the same privileges as a [Pentest Team Member](https://cobalt-io.brainfish.ai/en-us/articles/user-roles-and-permissions-oCij6uRrUR#h-pentest-team-member), with additional access to pentester functionality.

### To invite a Pentest Team Member:


1. On the pentest page, go to **Collaborators**.
2. Enter the user’s email address, and select **Add Team Member**.

To add more collaborators, repeat these steps. You can add one user at a time.

If a user is already a Team Member on the pentest, you can change their role to In-House Pentester.

 ![](https://docs.cobalt.io/api/attachments.redirect?id=0a1e457f-d113-40b9-a812-32c301fc5819)


7. When ready, select **Launch Pentest**. Your pentest goes Live.

* To launch a pentest, you need to assign at least one In-House Pentester.

Once the pentest goes Live, pentesters can start testing your asset. You can track the progress in real time.


:::info
## Note

You can enable [integrations](https://cobalt-io.brainfish.ai/en-us/articles/cobalt-integrations-t57LnbF8QD), configure [webhooks](https://cobalt-io.brainfish.ai/en-us/articles/webhooks-OuuDXWwHRm), and use the [Cobalt API](https://cobalt-io.brainfish.ai/en-us/articles/documentation-HpuTyV4OBO)for your In-House Pentests.

:::

## Collaborate on the Pentest  ![](https://docs.cobalt.io/api/attachments.redirect?id=4d9382e4-88c3-4478-ab7a-2ed816b5e374)

As a [Pentest Team Member](https://cobalt-io.brainfish.ai/en-us/articles/user-roles-and-permissions-oCij6uRrUR), you can collaborate on In-House Pentests to which you’re invited.

As an Organization Owner or Member, you automatically become a Pentest Team Member on all organization’s pentests, unless someone (including yourself) removes you.

### Communicate in the Chat

Communicate with pentesters and team members in the chat throughout a pentest. To open the chat, select the chat icon on the pentest page.

 ![](https://docs.cobalt.io/api/attachments.redirect?id=08454a8e-8ef1-4f61-87cd-bc8164ff5968)

[Slack channels](https://cobalt-io.brainfish.ai/en-us/articles/collaborate-on-pentests-ILbpm2juqQ#h-use-slack-for-communication) and [Pentester Updates](https://cobalt-io.brainfish.ai/en-us/articles/collaborate-on-pentests-ILbpm2juqQ#h-read-updates-from-pentesters) are not available for In-House Pentests.

### Use the Coverage Checklist

The Cobalt coverage checklist is a list of checks that pentesters use throughout a pentest to ensure that a baseline of security controls are in place. The list is based on security standards such as [OWASP Application Security Verification Standard (ASVS)](https://owasp.org/www-project-application-security-verification-standard/).

Learn more about the [coverage checklist](https://cobalt-io.brainfish.ai/en-us/articles/coverage-checklist-xstsQp965q) and [how to use it](https://cobalt-io.brainfish.ai/en-us/articles/coverage-checklist-xstsQp965q#h-how-to-use-the-coverage-checklist).

### Manage Pentest Collaborators

As a Pentest Team Member, you can add and remove team members from a pentest. Learn [how to manage pentest users](https://cobalt-io.brainfish.ai/en-us/articles/manage-pentest-collaborators-2pjt0NS56E).

## Move the Pentest to Remediation  ![](https://docs.cobalt.io/api/attachments.redirect?id=395d81c0-942c-4d09-a866-c272cd500a8f)

If needed, you can move the pentest to Remediation before pentesters do so. Select **Move to Remediation** on the pentest brief.

When the pentest is in Remediation, pentesters can no longer submit new findings. The testing process is complete.

Users with the following roles can move a pentest to Remediation:

* [In-House Pentester](https://cobalt-io.brainfish.ai/en-us/articles/user-roles-and-permissions-oCij6uRrUR#h-in-house-pentester)
* [Pentest Team Member](https://cobalt-io.brainfish.ai/en-us/articles/user-roles-and-permissions-oCij6uRrUR#h-pentest-team-member)

## Remediate Findings  ![](https://docs.cobalt.io/api/attachments.redirect?id=35752c75-0bdd-49fb-8666-062e59f3e923)

A finding is a vulnerability that a pentester reports during a pentest. To view [findings](https://cobalt-io.brainfish.ai/en-us/articles/findings-6prkG67iav), on the pentest page, navigate to **Findings**.

Once pentesters move a finding to Pending Fix, you can:

* Fix the finding and [submit it for retest](https://cobalt-io.brainfish.ai/en-us/articles/set-up-an-in-house-pentest-K9sgKIXq6Y#h-submit-a-finding-for-retest)
* [Mark the finding as Accepted Risk](https://cobalt-io.brainfish.ai/en-us/articles/set-up-an-in-house-pentest-K9sgKIXq6Y#h-mark-a-finding-as-accepted-risk)

Pentesters describe findings and provide recommendations on how to fix them. Navigate to the finding page for details.

You can start to remediate findings when the pentest is Live. You don’t need to wait until it’s in Remediation.

### Submit a Finding for Retest

Once you’ve fixed a finding internally, you can submit it for retest. Learn [how to submit a finding for retest](https://cobalt-io.brainfish.ai/en-us/articles/remediate-findings-22WPR0Fnlv#h-submit-a-finding-for-retest).

### Mark a Finding as Accepted Risk

Once you’ve analyzed a finding, you may want to accept it if:

* The risk associated with the vulnerability is low; or
* You plan to mitigate the finding in a way that doesn’t involve an actual technical fix.

Learn [how to mark a finding as Accepted Risk](https://cobalt-io.brainfish.ai/en-us/articles/remediate-findings-22WPR0Fnlv#h-mark-a-finding-as-accepted-risk).

## Download the Pentest Report  ![](https://docs.cobalt.io/api/attachments.redirect?id=663b3781-9c84-45c2-9b7d-920b6e803d39)

Once the pentest report is ready, you get a notification. You can view and download the report on the **Report** tab.

* For In-House Pentests, you get the same [report types](https://cobalt-io.brainfish.ai/en-us/articles/reports-YkC2da1roR) as for Comprehensive Pentests.
* You can [customize](https://cobalt-io.brainfish.ai/en-us/articles/customize-your-report-uqGyfWEzaa) the contents of pentest reports.
* Learn more about the [report contents](https://cobalt-io.brainfish.ai/en-us/articles/customize-your-report-uqGyfWEzaa).

## **Delete an In-House Pentest**

You can delete an in-house pentest in any state to keep your list organized. Deleting a pentest permanently removes all associated data, including **findings, reports, collaborators, and comments**.

### **How to delete**


1. In the Cobalt app, navigate to the **Pentests** page.
2. Locate the pentest and select the **three-dot menu** on the right.
3. Select **Delete**.
4. Confirm the action in the pop-up modal.

### **Permissions**

* Only **Org Owners** and **Org Members** can delete in-house pentests.
* You can only delete pentests that you have permission to access.
* Staff cannot delete these pentests unless they hold an Org Owner or Org Member role within your specific organization.

## What’s Next

Analyze the security posture of your assets based on the results of In-House and Cobalt PtaaS pentests.

* Navigate to [Cobalt Insights](https://docs.cobalt.io/en-us/articles/insights-r4Jw78EcgA) to view aggregated data.
* Share pentest reports with stakeholders.
* Plan your next pentest to keep your security strong.
