Loading...

Pen test management and reporting platform for manual assessments
Pen test management and reporting platform for manual assessments
SaltMiner Community is a penetration test management and reporting solution designed to centralize manual security assessments. The platform provides a centralized dashboard for managing penetration tests across multiple applications, testers, and engagements. The solution addresses common challenges in managing manual assessments by replacing spreadsheets and word documents with a unified system for tracking, sharing, and recreating test results. It supports an unlimited number of applications, tests, and users while manually aggregating and normalizing security findings. Built on the ELK framework, the platform provides a common logging repository that enables users to search, analyze, and visualize application security data in real time. It uses the Elastic Common Schema (ECS) data format to ensure results are portable between different tools and testers while enforcing enterprise-wide standards. The reporting engine allows users to add business context to vulnerabilities, including compliance information, and sort results by customizable parameters such as business unit, prioritization, and trends over time. Users can save workflows for repeatable tests, share them via links, and include screenshots with comment tracking. The platform integrates with the commercial SaltMiner product to combine manual testing results with other application security data for comprehensive reporting across all stakeholders.
Common questions about SaltWorks SaltMiner Community including features, pricing, alternatives, and user reviews.
SaltWorks SaltMiner Community is Pen test management and reporting platform for manual assessments developed by Saltworks. It is a Vulnerability Management solution designed to help security teams with Open Source.
Get strategic cybersecurity insights in your inbox
Open-source platform for pentest reporting and security team collaboration
NoSQLMap is an open source Python tool that automates NoSQL injection attacks and exploits configuration weaknesses in NoSQL databases to disclose or clone data.
A virtual host scanner with the ability to detect catch-all scenarios, aliases, and dynamic default pages, presented at SecTalks BNE in September 2017.
FuzzDB is an open-source dictionary of attack patterns and predictable resource locations for dynamic application security testing and vulnerability discovery.