Releases

2021.11.25

Finding Import

This release adds the ability to import findings and targets from files generated by over 120 different scanners and tools!

Reporter security scanners import

Read more

2021.11.02

Additions

  • Cloned findings can now be deleted in the original assessment.
  • Added a 'Severity Only' scoring system that lets you select a severity from 'Info' to 'Critical' without providing impact/likelihood or CVSS metrics.

Changes

  • 'Researcher briefing updated' notifications are now only sent if the assessment status is active or under review

Bugfixes

  • Fixed an issue where notifications about new tasks would count tasks that were already completed.
  • Fixed a bug where toast notifications without
Read more

2021.10.14

Real-Time Notifications 

This release adds real-time notifications for users. By clicking on the bell icon real-time notifications can be paused.

Reporter real-time notifications

Read more

2021.10.05

Assessment Schedule

Several new dates have been added for the assessment phases. Each phase now has a 'Research Start Date' and a 'Research Deadline', a 'Review Start Date' and a 'Review Deadline', and a 'Delivery Date'.

A schedule/agenda view has been added for assessment phases, accessible via the main menu. Each phase is separated into Research, Research Overtime, Review, and Finalization steps. The schedule can be filtered by assessment and user.

Read more

2021.09.13

Support for CWE and CAPEC Classifications

The classification of findings has been reworked. MITRE Common Weakness Enumeration (CWE), MITRE Common Attack Pattern Enumeration and Classification (CAPEC), and Bugcrowd Vulnerability Rating Taxonomy are currently supported. For MITRE based classifications, it is possible to examine the entries by using views.

Read more

2021.08.09

Activity Functionality

New Activity functionality is now available via the main menu. An overview screen shows the activity per assessment in the last seven days. Besides this, it is possible to filter and search in all logged assessment activities. The activity pages have been polished, so it is easier to keep an overview.

Read more

2021.07.23

Breaking changes

The setting 2FA_ENFORCE is renamed to MFA_ENFORCE.

Activity improvements

Elaborate activity logging is available within the assessment and under the user view.

Retest request improvements

A new assessment status "Retest requested" has been added. Creating a retest inquiry in a completed assessment now sets the status to "Retest Requested". Assessments with this status are displayed on the dashboard so a manager can easily schedule them. 

Read more

2021.06.28

Resolve findings partially

Findings with multiple targets can now be resolved for some of the targets, instead of all or none. The timeline and report will show which targets were resolved and when.

Reporter resolve finding some targets

Read more

2021.06.01

CVSS 3.1 Scoring System

The Common Vulnerability Scoring System Version 3.1 (CVSS) is now supported in addition to the OWASP Risk Rating methodology.

Reporter CVSS input

Read more