Pentera

PlexTrac supports importing JSON files from Pentera, but only JSON files exported specifically for PlexTrac will be accepted. Pentera is an automated security validation platform designed to identify and remediate security vulnerabilities continuously.

Exporting Pentera Findings

Findings of any Pentera task can be exported to a JSON-compatible format to be imported into PlexTrac.

Step 1: Click Testing History from the left menu.

Step 2: Select a test from the list to open.

Choose a test that has finished and is no longer in progress.

Step 3: Click the Export icon.

Step 4: From the modal under "Export to other tools," click PlexTrac.

The test findings are downloaded in a JSON format compatible with PlexTrac.

Each export file from Pentera contains the following:

  • The list of assets tested by Pentera within the scope of the particular test.

  • The list of vulnerabilities discovered during the test and the assets affected by each vulnerability. Discovery time is included in the dataset.

  • The list of Pentera achievements during the test and the assets affected by each achievement. Discovery time is included in the dataset. In Pentera, an achievement is Pentera’s ethical exploitation of a vulnerability or exposure intended to demonstrate its exploitability.

Mappings

Pentera identifies two main types of findings:

  • Achievement: In the context of Pentera, a positive outcome that demonstrates ethical exploitation of a vulnerability or exposure. This means that Pentera has successfully taken advantage of vulnerability or security exposure in a controlled and ethical manner. The purpose of achieving such exploits is to showcase the exploitability of a security issue without causing harm or damage to the system. Achievements illustrate the potential impact of a vulnerability when exploited by malicious actors.

  • Vulnerability: In the context of Pentera, a vulnerability finding represents a specific security issue or weakness that has been identified during the testing or scanning process. These findings are typically undesirable because they indicate a potential risk to the system's security.

Only JSON files exported from Pentera specifically for PlexTrac are accepted.

Mappings to Pentera Achievements

Mappings to Pentera Vulnerabilities

Finding Severity Mappings

Pentera uses a numerical range of 1 to 10 to capture a finding severity, while PlexTrac uses five qualitative values: Informational, Low, Medium, High, and Critical.

Last updated

© 2024 PlexTrac, Inc. All rights reserved.