Black Hat USA: Pen testing tool that aims to ‘keep the fun in hacking’ unveiled | The Daily Swig

2022-08-13 05:44:12 By : Ms. Ashily Xiong

Russia is ‘failing’ in its mission to destabilize Ukraine’s networks

Human error bugs increasingly making a splash, study indicates

Software supply chain attacks – everything you need to know

Inaugural report outlines strengths and weaknesses exposed by momentous security flaw

Flaw that opened the door to cookie modification and data theft resolved

The latest programs for June 2022

A schedule of events in 2022 and beyond

Latest version of AttackForge ReportGen DevSecOps aid demonstrated during conference Arsenal track

A tool that aims to “keep the fun in hacking” by simplifying penetration test reports is being showcased at Black Hat USA’s Arsenal track yesterday (August 10).

AttackForge is a pen test management and collaboration platform created to facilitate security testing across large and small organizations.

As previously reported by The Daily Swig , the developers demonstrated an earlier version of the tool at Black Hat Europe 2021.

This year’s offering, ReportGen, includes new features designed to remove the “most loathed part” of pen testing, according to Stas Filshtinskiy, co-founder of the DevSecOps aid.

Read more of the latest news from Black Hat USA

“Reporting is the most loathed part of any pen test,” he told The Daily Swig . “It is highly time consuming and can take out all the fun of being a hacker.

“There are other tools available, however, most of them require complex programming or multiple tools to use – making it difficult to create templates and to maintain them.

“We created a very different approach, which makes it simple for people to get started fast with minimal learning curve; and easy to maintain templates.

“We made the tool free so security community can focus more on what matters, which is finding vulnerabilities and getting them fixed faster!”

The key highlights for the latest version include:

DON’T MISS The best Black Hat and DEF CON talks of all time

Asked why the team decided to create the tool, Filshtinskiy said that many of the best tools either cost money or have vendor lock-in to their products.

“Existing tools require significant investment to learn how to use, and have limited template libraries,” he explained.

Fil Filiposki, AttackForge co-founder, told The Daily Swig that AttackForge ReportGen is aimed at “anybody who needs to create pen test reports”.

“This can include people learning about pen testing, professional pen testers and bug bounty hunters, and security teams.

“Users don’t need to have any particular knowledge or experience to effectively use AttackForge ReportGen.”

He told The Daily Swig prior to the demonstration: “There are many other enhancements and new capabilities also included in this upgrade, and we will be showing them during our Black Hat Arsenal presentation.”

YOU MAY ALSO LIKE  Black Hat USA: Deliberately vulnerable AWS, Azure cloud infrastructure is a pen tester’s playground