Learn how to launch an in-house pentest on the Cobalt platform.
:::info This page is for users who manage in-house pentests for their organization. If you’re an In-House Pentester, please read how to complete a pentest.
:::
An In-House Pentest is a pentest that an organization performs on the Cobalt platform without involving Cobalt pentesters. The workflow for In-House Pentests is similar to other pentests that you run on the Cobalt platform.
If you don’t yet have assets, set up an asset. An asset is a either a software component of value, such as a web application or API, or a network environment.
To avoid disrupting workflows in your organization, notify your team about the upcoming pentest. Learn how to prepare for a pentest.
Define who will work on the pentest:
As an Organization Owner or Member, you can set up an In-House Pentest—following the same steps as for other pentest types. Some parameters in the pentest wizard may slightly differ for In-House Pentests.
To launch an In-House Pentest:
The user gets an email invite to work on the pentest. An In-House Pentester role has the same privileges as a Pentest Team Member, with additional access to pentester functionality.
To add more collaborators, repeat these steps. You can add one user at a time.
If a user is already a Team Member on the pentest, you can change their role to In-House Pentester.
Once the pentest goes Live, pentesters can start testing your asset. You can track the progress in real time.
:::info
You can enable integrations, configure webhooks, and use the Cobalt APIfor your In-House Pentests.
:::
As a Pentest Team Member, you can collaborate on In-House Pentests to which you’re invited.
As an Organization Owner or Member, you automatically become a Pentest Team Member on all organization’s pentests, unless someone (including yourself) removes you.
Communicate with pentesters and team members in the chat throughout a pentest. To open the chat, select the chat icon on the pentest page.
Slack channels and Pentester Updates are not available for In-House Pentests.
The Cobalt coverage checklist is a list of checks that pentesters use throughout a pentest to ensure that a baseline of security controls are in place. The list is based on security standards such as OWASP Application Security Verification Standard (ASVS).
Learn more about the coverage checklist and how to use it.
As a Pentest Team Member, you can add and remove team members from a pentest. Learn how to manage pentest users.
If needed, you can move the pentest to Remediation before pentesters do so. Select Move to Remediation on the pentest brief.
When the pentest is in Remediation, pentesters can no longer submit new findings. The testing process is complete.
Users with the following roles can move a pentest to Remediation:
A finding is a vulnerability that a pentester reports during a pentest. To view findings, on the pentest page, navigate to Findings.
Once pentesters move a finding to Pending Fix, you can:
Pentesters describe findings and provide recommendations on how to fix them. Navigate to the finding page for details.
You can start to remediate findings when the pentest is Live. You don’t need to wait until it’s in Remediation.
Once you’ve fixed a finding internally, you can submit it for retest. Learn how to submit a finding for retest.
Once you’ve analyzed a finding, you may want to accept it if:
Learn how to mark a finding as Accepted Risk.
Once the pentest report is ready, you get a notification. You can view and download the report on the Report tab.
You can delete an in-house pentest in any state to keep your list organized. Deleting a pentest permanently removes all associated data, including findings, reports, collaborators, and comments.
Analyze the security posture of your assets based on the results of In-House and Cobalt PtaaS pentests.