Exploit categorisation and targeted CVE visibility
The pen testing tool currently shows pass/fail outcomes without surfacing which specific exploits or attack vectors were tested. Customers with security expertise want to know exactly what the tool probed for — which CVEs, which OWASP categories, which attack techniques — so they can assess the depth of coverage and map findings to their own vulnerability management processes.
Proposed Solution:
1. For each pen test finding, display the specific exploit or CVE targeted (e.g. CVE-2024-XXXX).
2. Categorise findings by attack vector or framework (OWASP Top 10, MITRE ATT&CK technique, CWE).
3. Provide a test coverage summary showing which exploit categories were tested and which were out of scope.
4. Allow filtering and grouping of results by exploit category, severity, and CVE.
Acceptance Criteria:
1. Each finding includes the targeted CVE or exploit identifier.
2. Findings are categorised by OWASP / MITRE ATT&CK / CWE.
3. A coverage summary shows tested vs out-of-scope categories.
4. Results can be filtered and grouped by exploit category and severity.
Log in to comment and vote
No comments yet
Be the first to share your thoughts.