---
title: "Collaborate on Pentests"
description: "Work with pentesters and your team."
canonical_url: "https://cobalt-io.brainfish.ai/articles/collaborate-on-pentests-ILbpm2juqQ"
md_url: "https://cobalt-io.brainfish.ai/articles/collaborate-on-pentests-ILbpm2juqQ.md"
---
# Collaborate on Pentests

Work with pentesters and your team.

:::info
**Collaborate with pentesters, your teammates, and Cobalt Staff throughout the pentest.**
:::

You can use the following communication channels:

* `Beta` Messaging in the Cobalt app
* A Slack channel dedicated for your pentest
* **Pentester Updates** sidebar in the Cobalt app 

As our pentesters test your asset, they update you on their progress in real time. Here’s what to expect:

* Pentesters report vulnerabilities that they discover in your software.
* You may get questions from our pentesters.
* You can submit comments to pentesters and your teammates.
* [Cobalt Staff](https://cobalt-io.brainfish.ai/en-us/articles/user-roles-and-permissions-oCij6uRrUR#h-cobalt-staff) members may get in touch to ask you for help.

## Collaborate in the Cobalt App

:::info
**Note**

**Beta**

To enable this feature, contact your Customer Success Manager (CSM) or <support@cobalt.io>.
:::

Communicate with pentesters and [pentest collaborators](https://cobalt-io.brainfish.ai/en-us/articles/user-roles-and-permissions-oCij6uRrUR) in the Cobalt platform, without using third-party tools.

Navigate to **Pentests**, select a pentest, and then select the chat icon ![Chat icon](https://cobalt-io.brainfish.ai/api/attachments.redirect?id=d6999766-9942-41a2-9318-dad1555e4fd1)

![](https://cobalt-io.brainfish.ai/api/attachments.redirect?id=045ba170-3e71-4a51-8f98-30078bc7689c)

In the sidebar that opens, you can see two tabs:

* **Pentester Updates**: Read updates from our pentesters as they test your [asset](https://cobalt-io.brainfish.ai/en-us/articles/assets-are-what-we-pentest-09RgsvQ7zv). On this tab, you can only view what pentesters posted. To start a conversation, go to the **Chat** tab.![](https://cobalt-io.brainfish.ai/api/attachments.redirect?id=043b03c3-fd4c-4129-8e1c-e6dfb56c212b)
* **Chat**: Communicate with pentesters, pentest collaborators, and [Cobalt Staff](https://cobalt-io.brainfish.ai/en-us/articles/user-roles-and-permissions-oCij6uRrUR#h-cobalt-staff) in real time.

  * To send a message, enter it in the input field, and then select **Comment**.
  * To mention a user in your message, type @, and select a user. Users get email notifications for each mention.
  * You can add emoji to your messages.
  * You can edit or delete your comments once posted.![](https://cobalt-io.brainfish.ai/api/attachments.redirect?id=f4ec3ba8-3521-4ac6-8b3e-9a5ac9b3ac46)

As our pentesters share vulnerabilities that they find in real time, you can start [remediating findings](https://cobalt-io.brainfish.ai/en-us/articles/remediate-findings-22WPR0Fnlv) before the pentest is complete. Review and analyze each [finding](https://cobalt-io.brainfish.ai/en-us/articles/finding-states-De6IE4W5Zw). You can:

* Fix the finding and [submit it for retest](https://cobalt-io.brainfish.ai/en-us/articles/remediate-findings-22WPR0Fnlv#h-submit-a-finding-for-retest)
* [Mark the finding as Accepted Risk](https://cobalt-io.brainfish.ai/en-us/articles/remediate-findings-22WPR0Fnlv#h-mark-a-finding-as-accepted-risk)

## Use Slack for Communication

You can communicate with pentesters and your teammates in a Slack channel dedicated for your pentest. To learn more about Slack channels, read the [Slack documentation](https://slack.com/intl/en-gb/help/articles/360017938993-What-is-a-channel).

:::info
**Note**

**The Slack channel is available until your pentest is** **[Closed](https://cobalt-io.brainfish.ai/en-us/articles/pentest-states-KfXxlt4Re2).**
:::

The image below illustrates how to use Slack throughout a pentest.![](https://cobalt-io.brainfish.ai/api/attachments.redirect?id=06ba5eab-b81f-4307-b2a2-da9380329e72)

1. Once we move your pentest to [In Review](https://cobalt-io.brainfish.ai/en-us/articles/pentest-states-KfXxlt4Re2), we create a dedicated Slack channel. On the pentest page, select the Slack icon and then select **Open Slack Channel #**. ![Slack icon](https://cobalt-io.brainfish.ai/api/attachments.redirect?id=4a665439-e1be-4bd1-824f-2f9507e6ec26)

* If you don’t have access to the Slack channel, contact your Customer Success Manager (CSM) or <support@cobalt.io>.
* If you’re new to Slack, read the [Slack documentation](https://slack.com/intl/en-gb/help/categories/360000049043) for help.![](https://cobalt-io.brainfish.ai/api/attachments.redirect?id=3374e2e6-cf21-4c2a-83fb-47d92c6f3e87)

  2.  Add the colleagues of your choice to the Slack channel. Choose colleagues who can benefit from direct communication with our pentesters. To learn more about adding users to Slack, read the [Slack documentation](https://slack.com/intl/en-gb/help/articles/201980108-Add-people-to-a-channel).

  1. Once we’ve moved your pentest to [Planned](https://cobalt-io.brainfish.ai/en-us/articles/pentest-states-KfXxlt4Re2), you’ll see your pentesters in the Slack channel.
  2. When the pentest goes [Live](https://cobalt-io.brainfish.ai/en-us/articles/pentest-states-KfXxlt4Re2), our pentesters share vulnerabilities that they find in real time. Start [remediating findings](https://cobalt-io.brainfish.ai/en-us/articles/remediate-findings-22WPR0Fnlv) before the pentest is complete. Here’s an example message from a pentester in Slack.![](https://cobalt-io.brainfish.ai/api/attachments.redirect?id=e1663158-ea8c-4f8d-9272-8f8269e19117)

<br />

1. Review and analyze each [finding](https://cobalt-io.brainfish.ai/en-us/articles/findings-6prkG67iav). You can:

* Fix the finding and [submit it for retest](https://cobalt-io.brainfish.ai/en-us/articles/remediate-findings-22WPR0Fnlv#submit-a-finding-for-retest)
* [Mark the finding as Accepted Risk](https://cobalt-io.brainfish.ai/en-us/articles/remediate-findings-22WPR0Fnlv#h-mark-a-finding-as-accepted-risk)

1. We keep the Slack channel open until you resolve all findings, which includes the following [states](https://cobalt-io.brainfish.ai/en-us/articles/finding-states-De6IE4W5Zw):

   * Accepted Risk
   * Fixed
2. We archive the Slack channel once we move the pentest to [Closed](https://cobalt-io.brainfish.ai/en-us/articles/finding-states-De6IE4W5Zw).

   * If you need access to the archived channel, contact your Customer Success Manager (CSM) or <support@cobalt.io>.

## Read Updates from Pentesters

Read updates from our pentesters as they test your [asset](https://cobalt-io.brainfish.ai/en-us/articles/assets-are-what-we-pentest-09RgsvQ7zv).

Navigate to **Pentests**, select a pentest, and then select the chat icon. You can view messages from pentesters in the sidebar that opens.![](https://cobalt-io.brainfish.ai/api/attachments.redirect?id=9a052b25-faf4-4a2c-9fd1-9998892af46f)

<br />

<br />
