SlideShare a Scribd company logo
Adrian Furtunã
Founder & CEO
https://pentest-tools.com
Let's make pentesting fun again!
Report writing in 5 minutes.
Fab România
Pentest reporting
2018 https://pentest-tools.com 2
Pentest reporting
2018 https://pentest-tools.com 3
Background info
2018 https://pentest-tools.com 4
About me
2018 https://pentest-tools.com 5
# Ex-fulltime pentester
 10+ years of experience in ethical hacking & IT security
 Reformed programmer
# Founder of Pentest-Tools.com
# Associate professor @ MTA, UPB
# Speaker at security events and conferences:
 Hack.lu - Luxembourg
 Hacktivity – Budapest
 ZeroNights - Moscow
 Defcamp - Bucharest
 OWASP Romania, etc
Pentest-Tools.com
# We help companies become resilient against cyber attacks
 Self-security assessment service
 Periodic scans & notifications
 Recommendation for fixing the issues
 25+ essential tools
• Updated
• Configured
• Ready to run
2018 https://pentest-tools.com 6
20% Effort
80%
Security
Coverage
Website activity
# 1,4 million users last year
# Organic growth
2018 https://pentest-tools.com 7
Audience Overview (Google Analytics)
Company
started
Our customers
# > 3000 customers
# 120 countries
# 80% companies (SMEs)
# 20% individuals
2018 https://pentest-tools.com 8
Back to pentest reporting
2018 https://pentest-tools.com 9
Solution 1
# Copy-paste from previous reports
 What was the latest good version?
 Search for findings in multiple reports
 Adapt to the current client (!)
2018 https://pentest-tools.com 10
Solution 2
# Make your own report generator tool
 Who makes it?
 Who maintains it (bug fixing, new features, updated,
etc)?
 Who keeps it updated and clean with the latest
findings?
2018 https://pentest-tools.com 11
Solution 3
# Use a third-party report generation tool
 Serpico:
• https://www.serpicoproject.com
• https://github.com/SerpicoProject/Serpico
 VulnReport:
• http://vulnreport.io/
• https://github.com/salesforce/vulnreport
# Challenges:
 Deployment & Initial configuration
 Learning a new reporting tool
 Importing scan results
2018 https://pentest-tools.com 12
Our solution
# Cloud-based
# Scanning Tools => Results => Reporting (.docx)
2018 https://pentest-tools.com 13
Pentest-Tools.com
# DEMO
2018 https://pentest-tools.com 14
Vouchers - 300 Free Credits
# https://pentest-tools.com/register
 Voucher code: DEFCAMP2018
 Obtain 300 Free Credits into your new account
2018 https://pentest-tools.com 15
Our team
2018 https://pentest-tools.com 16
Vlad Turcanu Eusebiu Boghici George Pitis Adrian Furtuna
Advisors
Andrei Pitis Diana Olar
Mihai Burduselu Andrei Damian
Thank you!
17https://pentest-tools.com
Adrian Furtunã
adrian.furtuna@pentest-tools.com
2018
Fab România

More Related Content

PDF
Deepali's resume
PPTX
ATAGTR2017 Test the REST
PDF
Anchore webinar thursday 21st july 2016
PPT
Sri monthly presentation 2016
PDF
A Modeling Editor and Code Generator for AsyncAPI
PPTX
ATAGTR2017 Detect Layout Bugs by Simulating Human Eye
PPTX
Azure deployment techniques By Arindam
PDF
This Week in Neo4j - 15th December 2018
Deepali's resume
ATAGTR2017 Test the REST
Anchore webinar thursday 21st july 2016
Sri monthly presentation 2016
A Modeling Editor and Code Generator for AsyncAPI
ATAGTR2017 Detect Layout Bugs by Simulating Human Eye
Azure deployment techniques By Arindam
This Week in Neo4j - 15th December 2018

Similar to Let's Make Pentesting Fun Again! Report writing in 5 minutes. (20)

PDF
Penetration Testing Services_ Comprehensive Guide 2024.pdf
PPTX
Web application Testing
PDF
ProActive Security
PDF
ProActive Security
PPTX
The Hacking Game - Think Like a Hacker Meetup 12072023.pptx
PDF
Penetration Testing Services - Redfox Cyber Security
PPT
List of Penetration Testing Tools -.ppt
PPTX
Penentration testing
DOCX
Web App Penetration Testing Essential Strategies for a Secure Pentest Website...
PDF
Top 3 reasons why infosec specialists write their on security tools
PPTX
Top 10 Penetration Testing Tools(Pen test tools).pptx
PPTX
Penetration testing dont just leave it to chance
PPTX
Becoming a better pen tester overview
PDF
DEF CON 23 - BRENT - white hacking web apps wp
PDF
penetration testing
PPTX
Penetration Testing; A customers perspective
PDF
COVID-19 free penetration tests by Pentest-Tools.com
PPTX
Keeping the wolf from 1000 doors.
PPTX
Vulnerability assessment and penetration testing
Penetration Testing Services_ Comprehensive Guide 2024.pdf
Web application Testing
ProActive Security
ProActive Security
The Hacking Game - Think Like a Hacker Meetup 12072023.pptx
Penetration Testing Services - Redfox Cyber Security
List of Penetration Testing Tools -.ppt
Penentration testing
Web App Penetration Testing Essential Strategies for a Secure Pentest Website...
Top 3 reasons why infosec specialists write their on security tools
Top 10 Penetration Testing Tools(Pen test tools).pptx
Penetration testing dont just leave it to chance
Becoming a better pen tester overview
DEF CON 23 - BRENT - white hacking web apps wp
penetration testing
Penetration Testing; A customers perspective
COVID-19 free penetration tests by Pentest-Tools.com
Keeping the wolf from 1000 doors.
Vulnerability assessment and penetration testing
Ad

More from DefCamp (20)

PDF
Remote Yacht Hacking
PDF
Mobile, IoT, Clouds… It’s time to hire your own risk manager!
PPTX
The Charter of Trust
PPTX
Internet Balkanization: Why Are We Raising Borders Online?
PPTX
Bridging the gap between CyberSecurity R&D and UX
PPTX
Secure and privacy-preserving data transmission and processing using homomorp...
PPTX
Drupalgeddon 2 – Yet Another Weapon for the Attacker
PPTX
Economical Denial of Sustainability in the Cloud (EDOS)
PPTX
Trust, but verify – Bypassing MFA
PPTX
Threat Hunting: From Platitudes to Practical Application
PPTX
Building application security with 0 money down
PPTX
Implementation of information security techniques on modern android based Kio...
PPTX
Lattice based Merkle for post-quantum epoch
PPTX
The challenge of building a secure and safe digital environment in healthcare
PPTX
Timing attacks against web applications: Are they still practical?
PPTX
Tor .onions: The Good, The Rotten and The Misconfigured
PPTX
Needles, Haystacks and Algorithms: Using Machine Learning to detect complex t...
PPTX
We will charge you. How to [b]reach vendor’s network using EV charging station.
PPTX
Connect & Inspire Cyber Security
PPTX
The lions and the watering hole
Remote Yacht Hacking
Mobile, IoT, Clouds… It’s time to hire your own risk manager!
The Charter of Trust
Internet Balkanization: Why Are We Raising Borders Online?
Bridging the gap between CyberSecurity R&D and UX
Secure and privacy-preserving data transmission and processing using homomorp...
Drupalgeddon 2 – Yet Another Weapon for the Attacker
Economical Denial of Sustainability in the Cloud (EDOS)
Trust, but verify – Bypassing MFA
Threat Hunting: From Platitudes to Practical Application
Building application security with 0 money down
Implementation of information security techniques on modern android based Kio...
Lattice based Merkle for post-quantum epoch
The challenge of building a secure and safe digital environment in healthcare
Timing attacks against web applications: Are they still practical?
Tor .onions: The Good, The Rotten and The Misconfigured
Needles, Haystacks and Algorithms: Using Machine Learning to detect complex t...
We will charge you. How to [b]reach vendor’s network using EV charging station.
Connect & Inspire Cyber Security
The lions and the watering hole
Ad

Recently uploaded (20)

PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PPTX
1. Introduction to Computer Programming.pptx
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
Assigned Numbers - 2025 - Bluetooth® Document
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PPTX
A Presentation on Artificial Intelligence
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PPTX
Programs and apps: productivity, graphics, security and other tools
PDF
Mushroom cultivation and it's methods.pdf
PPTX
OMC Textile Division Presentation 2021.pptx
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PDF
Empathic Computing: Creating Shared Understanding
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
Machine learning based COVID-19 study performance prediction
PPTX
SOPHOS-XG Firewall Administrator PPT.pptx
PDF
A comparative study of natural language inference in Swahili using monolingua...
PDF
August Patch Tuesday
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Per capita expenditure prediction using model stacking based on satellite ima...
1. Introduction to Computer Programming.pptx
Network Security Unit 5.pdf for BCA BBA.
Spectral efficient network and resource selection model in 5G networks
Assigned Numbers - 2025 - Bluetooth® Document
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
A Presentation on Artificial Intelligence
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Programs and apps: productivity, graphics, security and other tools
Mushroom cultivation and it's methods.pdf
OMC Textile Division Presentation 2021.pptx
Advanced methodologies resolving dimensionality complications for autism neur...
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
Empathic Computing: Creating Shared Understanding
Diabetes mellitus diagnosis method based random forest with bat algorithm
Machine learning based COVID-19 study performance prediction
SOPHOS-XG Firewall Administrator PPT.pptx
A comparative study of natural language inference in Swahili using monolingua...
August Patch Tuesday
Agricultural_Statistics_at_a_Glance_2022_0.pdf

Let's Make Pentesting Fun Again! Report writing in 5 minutes.