Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <CANo=s0ZesZj2nzHGxeG4CEjcB+dAxBF8pMDWB_mAMvgSm_gnSA@mail.gmail.com>
Date: Thu, 22 Jun 2023 18:05:14 +0530
From: Jyoti Raval <jenyraval@...il.com>
To: oss-security@...ts.openwall.com
Subject: Open Source Tool | MPT: Pentest In Action!

Managing Pentest (MPT: Pentest In Action) [image: HITBSecConf HITB2022SIN]
<https://conference.hitb.org/hitbsecconf2022sin/session/mpt-pentest-in-action/>

MPT aims to provide one stop solution for managing all pentests that are
running across organisation.
<https://github.com/jenyraval/MPT#why>Why?

Security penetration testing is more than necessary. If not all, most
organisations either have their own penetration testing team in-house or
they have third party pentesters. In any fast paced organisation with
multiple product lines and development planning timelines, it becomes
challenging for security teams to efficiently manage all these pentest
activities and effectively produce security assessment reports and track
them.

In order to solve above challenges I have developed a solution called
‘Managing Pentest (MPT: Pentest in Action)’
<https://github.com/jenyraval/MPT#what>What?

MPT helps us solve various problems:

   - Asset DB to know all organisation assets that are in pentest process.
   You can’t secure what you are not aware of!
   - Tracking each pentest
   - Pentesting activity knowledge which comprises of what particular let
   say application does, or the purpose of hardware that we are testing
   - When next pentester takes over the testing, all they have to do is
   view the asset and associated information which is already there.
   - Time taken for each pentest
   - Real time tracking of activity
   - Issue status
   - Common issues that are observed

MPT also has security pentest analytics which helps us not only track and
view everything in single pane of glass but also helps with:

   - Finding improvement areas to boost pen tester productivity
   - Understand the current risk posture
   - Understand recurring issues
   - Average amount of time taken for each pentest vs asset size
   - Average high/medium/low fixing time
   - Most number of vulnerabilities fixed in a year
   - Class of new vulnerabilities discovered
   - Developer trends
   - Open findings
   - Critical assessments
   - Asset health
   - Top pentester reported findings
   - Average busy time for each pentester

Github - https://github.com/jenyraval/MPT

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.