Create Test Finding
This guide is for organizations looking to test their integrations in a non-production environment. It provides detailed steps to populate an in-house pentest with test findings.
Prerequisites
- Cobalt staff must have created and set up a test organization for you. If not, please contact your customer success manager.
- You must be invited to the test organization, accept the invitation, and have an Owner role.
Create In-House Pentest
:::info Users must have the Team Member role to create a pentest.
:::
:::info Refer to the Pentest Team Member section of the product documentation for more details.
:::
-
Open the Pentests page from the sidebar and click Create Pentest.
:::info If the Create Pentest button is disabled, the user role must be changed to Team Member. Learn how to switch the user role for an In-House Pentest.
:::
-
Click Get Started if the In-House Pentest Beta feature is not yet enabled for your organization.
:::info Skip this step if the In-House Pentest Beta feature is already enabled.
:::
- Click Enter the Beta to enable the In-House Pentest Beta feature.
:::info Skip this step if the In-House Pentest Beta feature is already enabled.
:::
-
Select the In-House Pentest type and asset you want to test, then click Continue.
:::info You can create a dedicated asset for testing or use an existing one.
:::
- No changes are required on the Asset page. Click Next to proceed.
:::info Renaming the pentest is optional but helps distinguish test pentests. Click the pencil icon next to the pentest name and confirm with Done.
:::
- On the Requirements page, set the following fields:
- Targets
- Objectives
- Technology stack
:::info The input content is irrelevant.
:::
- No changes are required on the Details page. Click Next to proceed.
- On the Scope & Plan page, select the required Start and End dates, then click Save & Exit to create the pentest.
:::info You can check the I’m a point of contact for this pentest checkbox.
:::
- The In-House pentest is now in the draft state. Click Move to Planned.
- Confirm by clicking Move to Planned in the modal dialog.
Switch the User’s Role of an In-House Pentest
:::info Refer to the public documentation for more about user roles and associated permissions.
:::
- Go to the sidebar and select Pentests.
- Choose an In-House Pentest from the list.
- Open the Collaborators tab.
- Click the dropdown for Role next to your username and select the desired role for the In-House Pentest.
:::info The application will automatically reload after changing your pentest collaborator role.
:::
Launch In-House Pentest
:::info The user must have the In-House Pentester role.
:::
:::info Refer to the In-House Pentester section of the product documentation for more details.
:::
- Select Pentests from the sidebar.
- Choose the In-House Pentest you want to launch.
:::info The pentest should be in the planned state.
:::
- Click the Launch Pentest button.
:::info The pentest state changes to live.
:::
:::info If the Launch Pentest button is disabled, the user role must be changed to In-House Pentester. Learn how to switch the user role for an In-House Pentest.
:::
Create Test Finding
:::info The pentest must be live to submit findings.
:::
:::info The user must have the In-House Pentester role.
:::
:::info Refer to the In-House Pentester section of the product documentation for more details.
:::
- Select Pentests from the sidebar.
- Choose an In-House Pentest from the list to populate with test findings.
- Click Submit Finding.
:::info If the Submit Finding button is disabled, the user role must be changed to In-House Pentester. Learn how to switch the user role for an In-House Pentest.
:::
Provide the following information to create a test finding:
- Vulnerability type
- Description
- Proof of Concept
- Severity
- Suggested fix
:::info The input content is irrelevant but must meet validation constraints. For example, the severity must contain at least 3 characters.
:::
- Click Submit for Triaging at the bottom of the page when all required information is set.
- The pentest finding is now in the Triaging state.
-
Change the finding state to Pending Fix from the State dropdown and submit the evaluation.
-
Set the Likelihood and the Business Impact values by clicking the circles (●) and then the Submit evaluation button.
-
The pentest finding is now in the Pending Fix state.
- View all pentest findings.
:::info Once you have added test findings to the In-House Pentest, remember to switch the user role back to Team Member. If you remain in the In-House Pentester role, certain integration-related UI elements, such as external tickets or the Integrations tab, will be hidden.
:::
