Outline detailed requirements and reasons for your pentest.
On the Pentest Details page, we will ask you to provide requirements. All mandatory fields must be filled out prior to submitting the test for review.
Add reasons for wanting to conduct this pentest or any concerns that our team should be aware of for example:
Adjust the targets in scope if you want to focus the pentest on a specific part of the asset.
Typically, all you need is a URL, IP address, or link.
| Asset Type | Typical Target |
|---|---|
| Web | Fully-Qualified Domain Name (FQDN) such as www.example.com. May also specify an IP or network address. |
| Mobile | URL where anyone can download a mobile app, such as on Google Play or the Apple App Store. |
| API | Base URL of the API. You can define the endpoints / queries in the Instructions text box. |
| External Network | IP addresses or the IP network address. |
| Internal Network | IP network address. External IP address for the Jump Box. |
| Cloud Network | IP address(es) and FQDNs of your cloud components. |
Technologies that you selected on the asset details page populate in the Technology Stack field in the pentest workflow. You can add more technologies for your pentest, in addition to those that you specified for your asset earlier. For guidelines on our technology stack see create an asset.
Provide credential instructions for testers to access the application or environment.
Enter credentials in Access Instructions (Access Instructions is the next field on the brief)
Send credentials to testers through encrypted email (You can find email addresses within the brief once your pentest is in the Planned state)
Testers can create their own credentials
Authentication is not required
Provide Credentials and/or Access Instructions as required.
Credentials should be provided for each user role planned for your pentest, include the following:
Access instructions includes how to access the target environment (if any/needed, e.g. if it is an internal network test, you can give info on the jumpbox)
Our pentesters need to know about the environment that they’re testing, as well as whether they can find production data on the test system.
We need to know the environment of the pentest asset. The standard options are:
Our pentesters also need information on test data. If your apps contain:
Our pentesters take extra care to protect that information.
:::info Note
All Cobalt pentesters have signed a Non-Disclosure Agreement (NDA). :::
This question is optional but can provide helpful information for testers. While you’re not required to include any such details, we encourage you to include concerns that affect your production systems.
Provide any instructions related to the pentest like:
Our Cobalt team and pentesters will have updates and questions for you as your pentest progresses. Select your preferred communication channel:
Cobalt Staff may reach out to the point of contact with questions regarding the pentest.
Optionally, you can specify special requirements for pentesters. For example, if industry, company, or national regulations require that you limit pentesters to residents of one or more countries, you can request this. If you select one of these options, be sure to include details in the field below.
We can’t guarantee that we’ll accept your additional request. This may also delay scheduling the pentest.
Based on the methodology selected on the Overview page, you will be required to check which specifications apply to your asset. If the specification applies, please provide details in the text box provided.
By providing this, you’ll ensure a more effective and targeted pentest.