# What is PenTest.WS?

**PenTest.WS** is a professional penetration testing platform designed to manage the entire assessment lifecycle. From reconnaissance to reporting, it brings all your data together in one place — eliminating spreadsheets, scattered notes, and disconnected tools.

With PenTest.WS you can:

* **Recon** – Import scan results, track hosts and services, and build situational awareness quickly.
* **Exploit** – Record commands, notes, and artifacts in real time as you test.
* **Report** – Organize findings, create reusable report content, and generate polished deliverables without copy-paste headaches.

Whether you’re a solo consultant or part of a larger team, PenTest.WS gives you the structure and flexibility to run engagements efficiently and deliver results with confidence.

{% content-ref url="/pages/SVDWnkJyTIgQj2JOEamu" %}
[Getting Started](/getting-started/dashboard)
{% endcontent-ref %}

{% content-ref url="/pages/y5otZC6UwryMEwvTtem7" %}
[Hosts & Services](/hosts-and-services/host-page)
{% endcontent-ref %}

{% content-ref url="/pages/E4RtwlSrU2t2a0WJ8Mk9" %}
[Views & Filtering](/views-and-filtering/boards)
{% endcontent-ref %}

{% content-ref url="/pages/q57QEXlw3ZiEwhoYuGee" %}
[User Libraries](/user-libraries/shells-library)
{% endcontent-ref %}

{% content-ref url="/pages/ftEm6ATPbVqZYjhAsmKw" %}
[Built-In Tools](/built-in-tools/echo-up)
{% endcontent-ref %}

{% content-ref url="/pages/vIQI0vyY6yYx3Sk0aAbo" %}
[Search Capabilities](/search-capabilities/cve-db)
{% endcontent-ref %}

{% content-ref url="/pages/lKas7rkSwk70lQ8byqvv" %}
[Findings](/findings/engagement-findings)
{% endcontent-ref %}

{% content-ref url="/pages/GiQpN2yuQiosLCK3DbLo" %}
[Clients & Reporting](/clients-and-reporting/write-ups)
{% endcontent-ref %}

{% content-ref url="/pages/t8vnRY8c9ewatQtMiYTj" %}
[Collaboration](/collaboration/user-maintenance)
{% endcontent-ref %}

{% content-ref url="/pages/t2wBupWFZdNY9jEEYpnX" %}
[Automation & Integration](/automation-and-integration/api)
{% endcontent-ref %}

{% content-ref url="/pages/A0GuFcbS6ljbQ7NPjxC6" %}
[Authentication](/authentication/two-factor-authentication)
{% endcontent-ref %}

{% content-ref url="/pages/ym3K18yVeZiSgooRHY4t" %}
[Exporting & Importing](/exporting-and-importing/export-account-items)
{% endcontent-ref %}

{% content-ref url="/pages/JWiG4eg7HpjEqoJp0bE3" %}
[Pro Tier](/pro-tier/admin-panel)
{% endcontent-ref %}


# Tier Comparison

**View our current tier comparison at:**

{% embed url="<https://pentest.ws/pricing>" %}

<figure><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2F7UKpRtRDwSwLS9LKQFGm%2Fimage.png?alt=media&amp;token=dde35fa1-f8d5-4751-994c-e1f623cfc568" alt=""><figcaption></figcaption></figure>


# Dashboard

## Pro Tier Engagements Dashboard

**URL:** <https://pentest.ws/engagements>

<figure><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FDsETu2mKYpjQNvUe0xEA%2Fimage.png?alt=media&amp;token=2b6e51f6-9b74-4bd9-8bb6-0e60ac28c096" alt=""><figcaption></figcaption></figure>

The **Engagements Dashboard** provides a centralized view of all ongoing, planned, and completed engagements. From this screen, you can quickly see the status of each engagement, track progress, and review key metrics.

Each row in the dashboard displays:

* **Engagement** – The name of the engagement.
* **Client** – The associated client.
* **Status** – Current state (e.g., *Planned*, *In Progress*, *Client Delay*, *Cancelled*).
* **Start / End / Duration** – Engagement timeline details.
* **Time Left** – Remaining duration or indication if overdue.
* **Reviewed** – Progress bar showing the number of reviewed items.
* **Findings** – Counts of findings by severity (Critical, High, Medium, Low).
* **Owner** – The user responsible for the engagement.
* **Access** – Visibility and permissions (e.g., Public, Private, or read/full access assigned to specific users).

The dashboard gives Pro users a high-level overview of active work, making it easy to prioritize, assign resources, and monitor deadlines across multiple engagements.

### Pro Tier Team Missions - On-Premise Only

When a teammate makes an engagement **Public** or grants you **Read** or **Full** access, the engagement will appear in your dashboard. In the **Access** column, you’ll see the names of users who have been granted permissions alongside your own.

:link: [Read more about Access Control](/collaboration/access-control-list)

:link: [Read more about Shared Engagements](/collaboration/shared-engagements)

## Archived Engagements

Engagements can be archived from the Engagement's Console window. When an Engagement is archived it no longer appears in by default but can be found by selecting "Show" in the "Archived" filter.&#x20;

{% hint style="info" %}
No data is lost when archiving Engagements
{% endhint %}

## Free & Hobby Tier Mission Control Dashboard

**URL:** <https://pentest.ws/dashboard>

![Free / Hobby Tier Dashboard](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2F6FzeoCmsvWxNN2RnxBoo%2Fimage.png?alt=media\&token=2a11c62c-69f8-4303-874f-8a903865393e)

Mission Control on Free Tier & Hobby Tier show Engagement cards with a breakdown of their Host exploitation status:

**Vacant**: a Vacant Host is a remote machine where you have not achieved Remote Code Execution

**Shelled**: when you attain a low privilege shell on a remote Host, set the Shell ![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2F324KtUunWyIGN8TBqQu2%2Fimage.png?alt=media\&token=93e02d2c-2589-44c6-8d7f-b85cb0fd37fd) flag

**Owned**: if you gain elevated privileges on a remote Host, set the Owned ![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FbVmZ25R1qeL7GzHhfgwJ%2Fimage.png?alt=media\&token=d42d13c6-b2ed-441a-b2a9-d52ee64703d9) flag

## Tier Availability

**Mission Control** dashboard is available on **Free** and **Hobby Tiers**.

**Engagements** dashboard is available on **Pro Tier**.


# Creating An Engagement

**URL:** <https://pentest.ws/e/create>

An **Engagement** is the foundation of every assessment in PenTest.WS. It acts as the container for all the work you’ll perform — including hosts, ports, findings, notes, and reporting. By creating an engagement, you establish the structure that ties every part of the testing lifecycle together.

From the Dashboard, click **Create Engagement** to begin:

![Create Engagement](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FnxFIlHhwvgdFKylQWfUa%2Fimage.png?alt=media\&token=f61d8ca2-8400-4e47-b979-89403479a895)

#### Why Start with an Engagement?

* **Organized Workflow** – Each engagement keeps your scope, assets, and findings grouped and separate from other projects.
* **Hosts and Ports** – All hosts discovered or imported during testing are tied back to an engagement. Their associated ports, services, and evidence remain organized within this container, making it easy to pivot between technical details and higher-level reporting.

#### Tips for Creating an Engagement

* Choose a **clear, descriptive name** so the engagement is easy to identify in your dashboard.
* Always **link the correct client**, as this connection is used throughout reporting and collaboration.
* Use the **summary** field to capture the objective or scope (e.g., *“External black-box assessment of public web applications”*).

Once created, you’ll be taken into the engagement workspace where you can begin adding hosts, importing scan data, and tracking findings.


# Main Window Layout

**Example URL**: <https://pentest.ws/e/{engagement.id}/console>

![Main Window Layout](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FMR3dMsMdf2sijcBjKWCt%2Fimage.png?alt=media\&token=7a228ac7-0a65-419e-8b89-b5c9b06f8f60)

## <mark style="color:red;">Top Menu</mark>

![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2F8kRjOc3kRZ6wkSjqfAVk%2Fimage.png?alt=media\&token=795b5b0e-7485-48dc-aee9-bb9e196e193a)

The Top Menu contains items associated with your account and not tied to a specific Engagement. These features, such as the [Shells Library](/user-libraries/shells-library) and [General Command Library](/user-libraries/general-command-library) will load into the Main Content Section when you are in an Engagement. This way you don't have to leave the Engagement to access your User Items.

## <mark style="color:purple;">User Menu</mark>

![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FAaTfZZzyGcm7EQIgekwG%2Fimage.png?alt=media\&token=cdfd97fc-fe6b-4dfd-91a3-9302f03aad4c)

Your Account Settings, Membership Settings and several library managers are accessible from the top right User Menu.&#x20;

## <mark style="color:green;">Sidebar</mark>

The Sidebar lays out all of the Engagement's Hosts and Services for quick navigation.

![Sidebar](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FNRTo8q0AQQKj2MgdYxrz%2Fimage.png?alt=media\&token=0a1f0330-9231-46fe-83ab-5029a425d547)

<table><thead><tr><th align="center"></th><th width="499.33333333333326"></th></tr></thead><tbody><tr><td align="center"><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2F4A5lUFXLSRkUDqFJG5ZC%2Fimage.png?alt=media&amp;token=32215d67-3fec-4ca5-a65a-edda13083fa2" alt="" data-size="line"></td><td>The name of the Engagement</td></tr><tr><td align="center"><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2F7yW78JkOca5TOZCGHc2g%2Fimage.png?alt=media&amp;token=004c45e6-b681-437c-945e-7496817325a6" alt=""></td><td>Click the Hosts header to expand or collapse the list of Hosts</td></tr><tr><td align="center"><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FOv6knDsZNdBSRkJhw9O5%2Fimage.png?alt=media&amp;token=cfb9e281-b4ca-4218-87a0-2ff80a25fd83" alt=""></td><td>Import XML</td></tr><tr><td align="center"><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FYcpCeF2W0NmIawLXT7dW%2Fimage.png?alt=media&amp;token=e335fb95-6196-4fbe-8852-c878e13469e9" alt=""></td><td>Add Hosts</td></tr><tr><td align="center"><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2F8WAliRNSuC3hc9E6GnXB%2Fimage.png?alt=media&amp;token=6e635732-260d-487f-9832-8cc7a3af3f8b" alt=""></td><td>Expand / Collapse all Hosts details</td></tr><tr><td align="center"><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FhkKPuhATl0JNr0tGHY2N%2Fimage.png?alt=media&amp;token=9d15b895-360e-46a4-ab85-8bc65068aa59" alt=""></td><td>Refresh the Sidebar's Hosts &#x26; Ports list</td></tr><tr><td align="center"><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FyDOxolvA9kYewqZudEkL%2Fimage.png?alt=media&amp;token=4e9ce91a-bfe3-4515-bd8f-05d5aff6c1fe" alt=""></td><td>Sort the Host list alphabetical / numerical</td></tr><tr><td align="center"><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FXDoLClYbw9DTsbhVgmp3%2Fimage.png?alt=media&amp;token=b825a2ac-4102-43a9-affc-a8eb5ad62223" alt=""></td><td>The Board selector</td></tr><tr><td align="center"><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FcOjYV5YoDf3paAJFZ0QS%2Fimage.png?alt=media&amp;token=5aa30754-cf56-4ccf-8d07-6a296e97b24f" alt=""></td><td>Host Type (server, workstation, router, etc.)</td></tr><tr><td align="center"><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FmrnjnHtTlDLUEf4LF50G%2Fimage.png?alt=media&amp;token=539dfb60-b775-4a4f-a25e-e1e09118e080" alt=""></td><td>Host OS Type (Windows, Linux, etc.)</td></tr><tr><td align="center"><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2F5A78hWpFohYQQxjSNzHk%2Fimage.png?alt=media&amp;token=4efaf064-dfd0-4824-aa1b-e1e7ed18d5f6" alt=""></td><td>Host Target (IP address or hostname)</td></tr><tr><td align="center"><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FAB5S1EUPft5McT5qbC9L%2Fimage.png?alt=media&amp;token=d7be40ff-635b-4556-ab6f-1fddbb1fec31" alt=""></td><td>Load this Host</td></tr><tr><td align="center"><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FvmBWkfC7cEEo1BZ5PqDs%2Fimage.png?alt=media&amp;token=434a8b64-4109-481a-ae60-1a9a4f2a83cb" alt=""></td><td>Host Flags</td></tr><tr><td align="center"><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FPAnjWChO5wky4BSe4i2h%2Fimage.png?alt=media&amp;token=5ddc5f01-ae68-4c77-95d6-452cfcdc2b81" alt=""></td><td>Host Label</td></tr><tr><td align="center"><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FYUYsjOadh6FqtHhzToWo%2Fimage.png?alt=media&amp;token=3b377f8a-4f2d-4b4e-b073-c3f9853ef99d" alt=""></td><td>Host Operating System</td></tr><tr><td align="center"><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FVBS0j0qKMKIxlUIRbWMU%2Fimage.png?alt=media&amp;token=cf17a084-bb66-4e1c-8846-20446fdc5188" alt=""></td><td>The Host's Port Table can be expanded by clicking on the Host itself. The colored dots indicate TCP/UDP port state: <br><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FVvZ3Y7jUP7Ih92qbfuAv%2Fimage.png?alt=media&amp;token=a8bce330-1e65-49e9-b49d-12b1358b0a9e" alt=""> Open <img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FOcqleizbEEa8bxRad9k9%2Fimage.png?alt=media&amp;token=ffbe3f07-e164-462d-83c2-d6897c65d535" alt=""> Filtered <img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FFWtryv97nvFK6UrSLiLf%2Fimage.png?alt=media&amp;token=7a47dd75-22ad-46af-91e5-456b5298f647" alt=""> Closed</td></tr></tbody></table>

### Sidebar Services

![Side Services](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FXsXi4ZtlU4sLnAoqD5na%2Fimage.png?alt=media\&token=b59cf81c-7557-497e-b859-dbf293e8571d)

<table><thead><tr><th width="212" align="center"></th><th width="424.33333333333326"></th></tr></thead><tbody><tr><td align="center"><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FG4RyWWZqpN6zPmvtPP45%2Fimage.png?alt=media&amp;token=7fa00b39-f9c2-4049-ab34-10ec86e68036" alt=""></td><td>Click the Services header to expand or collapse the list of Services</td></tr><tr><td align="center"><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2F6LH66inXuZUAXrJC0KIS%2Fimage.png?alt=media&amp;token=4aef77f6-d8dd-4c10-8465-dab7ebe01cb0" alt=""></td><td>Collapse all Service details</td></tr><tr><td align="center"><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2F4kSZU06RNZGRyWSRjIgu%2Fimage.png?alt=media&amp;token=5c25be50-0dd3-4aa4-9ccc-fbbd5b35739d" alt=""></td><td>Refresh the Service list</td></tr><tr><td align="center"><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FDC71LEAQ5jBDR3jJ1Bor%2Fimage.png?alt=media&amp;token=61b23fe0-9ef4-4e15-9389-89237f372b74" alt=""></td><td>The name of the Service</td></tr><tr><td align="center"><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FI1sf5nlTXAjEZ9QRVA58%2Fimage.png?alt=media&amp;token=3a3cc15b-4ecc-46d4-97cd-1e011f86eef3" alt=""></td><td>The Host Type and Operating System</td></tr><tr><td align="center"><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FOYX0e36x5oXmqPdnDRTU%2Fimage.png?alt=media&amp;token=9dbf540e-c17e-40c2-87af-8229f5114199" alt=""></td><td>Port state : Host Target : Port Number</td></tr><tr><td align="center"><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FnrS1YUAi7cMFxjb9ycv0%2Fimage.png?alt=media&amp;token=a3075d62-7a21-476b-96c1-72c157ebbe19" alt=""></td><td>Load the Host</td></tr><tr><td align="center"><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FAcHaZbzQarpJjZZ76YXV%2Fimage.png?alt=media&amp;token=2fe2e598-ba3e-479c-8508-b2420efc9a04" alt=""></td><td>Load the Port</td></tr><tr><td align="center"><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FtgHoKWCRrXQBAcys1SUw%2Fimage.png?alt=media&amp;token=b18bf3da-cc33-4aaf-83d9-6bec7d762595" alt=""></td><td>The Service Version</td></tr><tr><td align="center"><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2Fuo2cw3PSwD3B8rVOSJ2f%2Fimage.png?alt=media&amp;token=8de44f29-19ed-4f1a-b7a3-ada5b23e3779" alt=""></td><td>The Host's Label</td></tr></tbody></table>

### Sidebar Footer

<img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FtkFvaAQkUPm4CGVlaElC%2Fimage.png?alt=media&amp;token=451a4cb2-6009-4088-9880-515d5d32f9de" alt="" data-size="line"> At the bottom of the Sidebar are buttons to [Import XML](/getting-started/import-nmap-and-masscan-xml) and [Add Hosts](/getting-started/adding-hosts-manually).

## <mark style="color:blue;">Engagement Menu</mark>

![Engagement Menu](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FbYXsPaaeYqfwPOcLB073%2Fimage.png?alt=media\&token=e138d106-bc35-4a3e-9a10-0cd6e8c54d75)

Under the Top Menu you'll find the Engagement Menu with objects related to the current Engagement. Some options in the Engagement Menu have Sub Menus, such as the Hosts tab.

* [Console](/getting-started/engagement-console)
* [Boards](/views-and-filtering/boards)
* [The Matrix](/views-and-filtering/the-matrix)
* [Host Page](/hosts-and-services/host-page)
* [Credentials](/getting-started/capturing-credentials)
* [Findings](/findings/engagement-findings)
* [Reports](/clients-and-reporting/reporting)

### Filter Indicators

![Filter Indicators](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FfNxfCxmPk8fHswwifm0E%2Fimage.png?alt=media\&token=44b4aa20-7767-45cc-a32f-81552824efe4)

When you select to select a [Board](/views-and-filtering/boards) or set filters in [The Matrix](/views-and-filtering/the-matrix), filter indicators will display in the Engagement menu.

## <mark style="color:yellow;">Object Actions</mark>

![Object Actions](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FxPHiXt37cH3W7Mx5rDez%2Fimage.png?alt=media\&token=6169b088-ab0f-4bcb-8946-20ef66ae6991)

These buttons apply to the current object loaded in the Main Content Section, including the Delete Object button.

{% hint style="warning" %}
**Warning**: be aware of what object is currently load when clicking Delete Object button. Deleting an Engagement will remove all associated Hosts, Ports, Credentials, Findings and other attached objects.
{% endhint %}

## Sub Menus

![Sub Menus](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FGBC1tDAP69JL2UzvkgCR%2Fimage.png?alt=media\&token=9b15c5f1-6f21-4e46-ac3e-4c22a5b1530b)

Some tabs in the Engagement Menu have associated Sub Menus. Here we have selected the Hosts tab which brings up the Hosts Sub Menu.


# Engagement Console

**Example URL**: <https://pentest.ws/e/{engagement.id}/console>

## Pro Tier Console

<figure><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FMfMAudNS1XtTpGwMAMX4%2Fimage.png?alt=media&amp;token=69c4ed3d-9f56-40d7-bde1-a4df0d7483cf" alt=""><figcaption></figcaption></figure>

The **Engagement Console** is the central view for managing an individual engagement. From here, you can update engagement details, track notes, and control access.

### Engagement Details

At the top of the console you can edit the core details of the engagement:

* **Engagement Name** – The display name of the engagement.
* **Client** – The client associated with the engagement.
* **Status** – Current state (e.g., In Progress, Client Delay, Planned).
* **Starts At / Ends At** – Engagement timeline dates.
* **Summary** – A short description of the engagement.

Additional controls allow you to **Print**, **Export**, or **Delete** the engagement.

### Engagement Notes

Below the summary is a rich text editor for **Engagement Notes**. These notes can capture methodologies, progress updates, or other details relevant to the engagement. Notes support rich formatting, links, and images.

### Access Control

The Access Control section defines who can see and manage the engagement.

* **Restricted / Unrestricted** – Restricted engagements are visible only to the users listed. Unrestricted engagements are visible to all users.
* **No Access** – Users with no visibility into the engagement.
* **Read Access** – Users who can view the engagement but cannot make changes.
* **Full Access** – Users with full administrative control over the engagement.

In the example shown:

* *Charlie* and *David* have **No Access**.
* *Bob* has **Read Access**.
* *Admin* has **Full Access**.

This structure makes it easy to control visibility and collaboration across your team.

## Free Tier & Hobby Tier Console

![Free Tier & Hobby Tier Console](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2Fy2qinfCVHM5huU5qFVyv%2Fimage.png?alt=media\&token=3058f554-3d96-4efb-a4b3-1b03435c28b0)

On Free & Hobby Tier the Engagement Console displays a bar graph showing the distribution of Host Type and Operating System Types.

## Tier Availability

**Console** is available on all tiers.


# Import Nmap & Masscan XML

**Example URL:** <https://pentest.ws/e/{engagement.id}/import>

Importing scan results is the fastest way to populate an engagement with real data. PenTest.WS supports XML output from both **Nmap** and **Masscan**, allowing you to bring in discovered hosts and their associated ports in bulk. Instead of manually adding systems one by one, simply drop in your scan files and let PenTest.WS build the host and port inventory for you.

![Scan & Import XML](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2F9yEdp6qbPEcFn1pHdVCK%2Fimage.png?alt=media\&token=d29a85b2-71a4-43a9-93ff-732ebd838f40)

Once you have scanned a target or network range with Nmap or Masscan, import the results in PenTest.WS by drag-and-drop or opening a file dialog.

## Multiple Files

Multiple XML files can be imported at once. These files can be a mix of Nmap and Masscan results, but must be separate files. Click the trash can icon to remove a file from your current import.

## Copy & Paste

You can also Copy & Paste a single XML file contents. This is handy for reverse shell or pivot shells where file extraction is only possible through the clipboard.

## Import Options

**Open ports only:** Only imports tcp/udp ports which are open and accessible. All *closed* or *filtered* ports will not be imported.

**Skip portless hosts:** Do not create host records that do not have any associated ports.

## Default Target

When a new host is discovered in the XML content, PenTest.WS will create a new Host record. You can choose to create Hosts with the target value of either a Hostname or an IP Address.&#x20;

## Tier Availability

**Import XML** is available on all tiers.


# Port Scan Templates

**Example URL:** <https://pentest.ws/e/{engagement.id}/import>

Port Scan Templates are available on the *Scan & Import XML* page. Scan templates work using copy-and-paste from the web application to your terminal.

1. Enter a Target IP or Hostname
2. Click on a template to copy the command to your clipboard
3. Open a bash or powershell terminal
4. Paste and execute

## Single Host Port Scans

![Single Host Port Scan Templates](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FSkr2RUot7haY8ta05L7i%2Fimage.png?alt=media\&token=c6099c04-c12b-4fcd-b378-a0b58d84f640)

Scan Templates can include variables such as %tip% to insert your Target IP / Hostname.

![Template Variables](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FSWGI8UzEldDSi0Q1pUGi%2Fimage.png?alt=media\&token=665e4a2a-98ab-4de3-b37c-a4a119d78de9)

{% hint style="info" %}
**Level Up!**

Scan a target and automatically import the results into your current Engagement using the [PenTest.WS API](/automation-and-integration/api). The *%apikey%* variable will be replaced with your API key once you have confirmed your account password.

*Do not put your API key directly into templates!*

```
nmap -sC -sV -oA tcp -vv %tip% && curl -X POST "https://pentest.ws/api/v1/e/%eid%/import/nmap" -H  "X-API-KEY: %apikey%" -F "file=@tcp.xml"
```

{% endhint %}

## Subnet Port Scans

![Subnet Port Scan Templates](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FaJtBqLlIff25rATA29IS%2Fimage.png?alt=media\&token=8ffec076-5f28-46f0-9ee6-7076a8b756b7)

Subnet Port Scans work similar to Single Host Port Scans, with the added field of a DNS Server to resolve hostnames from an IP address range. The Subnet field can be a single IP address (10.1.2.3), an IP range (10.1.2.100-140) or CIDR notation (10.1.2.0/24)

## Creating & Modifying Scan Templates

Click the *Edit Templates* button to enter *Change Mode*. Here you will be able to create new scan templates or modify existing templates.

![Modifying A Scan Template](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FroTC4b3pBjVNcLOJjuJN%2Fimage.png?alt=media\&token=0dfe57f6-e204-4a66-a4e5-646a0b379e8b)

Save your changes and click the *Use Templates* button to exit *Change Mode*.

## Tier Availability

**Port Scan Templates** are available on all tiers.


# Adding Hosts Manually

**Example URL:** <https://pentest.ws/e/{engagement.id}/host/add>

Hosts are the backbone of every engagement. In PenTest.WS, a *host* represents an IP address or hostname you are assessing, and each host becomes the anchor point for associated ports, services, and findings. Adding hosts manually gives you direct control over which assets are in scope and ensures your engagement stays tightly aligned to its objectives.

From the engagement sidebar, click **+ Hosts** at the top or bottom to open the form:

![Top of the Sidebar](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FxfusJvi6nBQJmEcnDFfz%2Fimage.png?alt=media\&token=ce3b550a-ba38-42e2-9829-7a730b0ddf6a)

![Bottom of the Sidebar](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2Fvral6o8rki0II4oFI411%2Fimage.png?alt=media\&token=cfdd99d6-8193-4faf-ab3e-655fdca9e2e4)

![Add Hosts](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FaelAvi83pWZ9JPnPu5zZ%2Fimage.png?alt=media\&token=eef788c0-d681-4bfe-be01-25ddb11ba333)

#### Adding Hosts

* Enter one or more **IP addresses, hostnames, or CIDR ranges** (one per line).
* Optionally assign a **label**, **type**, and **operating system** to help categorize assets.
* Click **Add Hosts** to save.

⚠️ Each host must be unique — you cannot add multiple host objects with the same IP or hostname. Once added, the new hosts appear in the sidebar for quick navigation.

The new Host objects will appear at the top of the Sidebar.

## Using Host Scan Templates

You can save time with **Host Scan Templates**. Templates allow you to predefine commands (e.g., Nmap ping sweeps) for enumerating live hosts. Use the `%subnet%` variable in your template to target specific ranges.

Learn more at [Port Scan Templates](/getting-started/port-scan-templates)

## Tier Availability

**Adding Hosts Manually** is available on all tiers.


# Adding Ports to Hosts

From the [Host Page](/hosts-and-services/host-page), click the *Add Ports* button in the *Ports* section.

![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FZR14WR8XXxLwdHerEXDP%2Fimage.png?alt=media\&token=124255ba-1642-437f-93d1-97d8002ecc25)

**Example URL:** <https://pentest.ws/e/{engagement.id}/host/{host.id}/port/add>

![Add Ports](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FoCsJhIQc0wPht7mi6Kgq%2Fimage.png?alt=media\&token=54256b93-7c6b-4a6b-8ff1-e8509701c229)

The *Add Ports* screen lets you quickly add ports to a Host using the following template:

`portNum[:protocol][/service]`

Separate multiple ports with a comma. Manually added ports are set to the Open port state.

## Examples

**Port Numbers:**\
`21, 25, 80, 139, 443, 445, 3389`

**Port and Service Names:**\
`80/http, 443/https`

**UDP Ports:**\
`53:udp/dns`

## Tier Availability

**Adding Ports** is available on all tiers.


# Capturing Credentials

## Engagement Credentials Tab

<figure><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2F5Cii1OGVyfBIU91VNpoz%2Fimage.png?alt=media&amp;token=bf4b2201-0a7c-4ab5-97ce-92fcd8cda48a" alt=""><figcaption></figcaption></figure>

The **Credentials** screen is used to manage usernames, passwords, and hashes discovered during an engagement. This central repository makes it easier to track, reuse, and report credentials across different hosts and services.

### Features

At the top of the screen you can:

* **Add Creds** – Manually add new credentials.
* **Import Creds** – Bulk import credentials from supported formats.
* **Export Creds** – Export the current list for offline use or reporting.
* **Clear Filters** – Reset any applied filters in the table.

A search bar is also available to quickly locate specific credentials.

### Credential Fields

Each row in the table represents a credential record with the following fields:

* **Host** – The system where the credential was identified.
* **Service** – The protocol or service (e.g., SMB, RDP, SSH).
* **Domain** – The associated domain or workgroup.
* **Username** – The account name.
* **Password** – The cleartext password, if known.
* **Hash** – A stored password hash, if captured.
* **Notes** – Any additional context (e.g., “Domain Admin”).

In the example shown:

* Host: `1.2.3.4`
* Service: `smb`
* Domain: `acme.local`
* Username: `administrator`
* Password: `password123`
* Hash: `218297e636...`
* Notes: `Domain Admin`

This structured view allows you to keep track of credentials across an engagement and ensure they are available for reuse during testing or reporting.

## Adding Credentials Manually

From the *Credentials* *Tab* or [Host Page](/hosts-and-services/host-page), click the *Add Creds* button in the *Credentials* section:

![Host Page - Credentials Section](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FjP8bdzSW1v36990kA3JI%2Fimage.png?alt=media\&token=b3be9abd-8faf-4035-adee-e332c3c9d20e)

<figure><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FxE0jljX8ZxUulk5pZTPp%2Fimage.png?alt=media&amp;token=d0e1f49e-02c4-43d7-bc8a-aa4a708c2c90" alt=""><figcaption></figcaption></figure>

All fields are optional. Set the Host field to a specific host, for example web logins are typically tied to a web server. You can also attach credentials to the Engagement for domain wide credentials such as Active Directory NTLM hashes.

## Importing Credentials

From the *Credentials* *Tab* or [Host Page](/hosts-and-services/host-page), click the *Import Creds* button in the *Credentials* section.

![Import Creds](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FsRx1OiIDlyFOxUSidiQs%2Fimage.png?alt=media\&token=68cd3e25-38fc-4c90-8915-912948e2ea4f)

Import credentials by loading a file or copy & paste. The formats supported are:

* passwd
* .shadow
* username : password
* username : hash
* username : hash : hashtype

## Exporting Credentials

![Export Creds](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FhmLCIDFdSZfj9ol8y6oI%2Fimage.png?alt=media\&token=28d5cc42-3e9b-4478-b66c-b40a8016e14f)

The *Export Creds* screen provides an listing of captured credentials in various formats. These are meant to be copy & pasted into a file for use by hashcat, crackMapExec, or other tools.

## Tier Availability

**Credentials** are available on all tiers.


# Host Page

**Example URL:** <https://pentest.ws/e/{engagement.id}/host/{host.id}>

<figure><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FmrL6u2zAtmpC9jfrvYzo%2Fimage.png?alt=media&amp;token=05186cc4-8579-4c62-8416-177e00f874a6" alt=""><figcaption></figcaption></figure>

## Host Details

**Host** **Type**: Categorize the Host as a server, workstation,  router, or several other options

**OS Type**: Linux, Windows, Apple, Android

**Target**: Host IP address or fully qualified domain name

**Hostnames**: Additional hostnames, space separated. These hostnames appear on the Port page for use in Service Command Library templates.

**Label**: User defined label

**OS**: Operating system version, captured from Nmap XML or user defined.

**Flags**: Flagged, reviewed, interested, not interested, out-of-scope, shell, owned, color

## Note Pages

![Note Pages](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2Fk5Rk1FOTUEVgtpdPuNha%2Fimage.png?alt=media\&token=131547ec-a41f-4b8f-97a7-2607ef8d36c6)

A rich text editor for taking notes about the current Host. It supports copy-and-paste images from the clipboard for capturing screenshots.

{% hint style="info" %}
**Level Up!**&#x20;

Stay organized by attaching tool output directly to a Host. Create a new Note Page for each command output, such the results dirbusting a web folder or logging a nikto scan.&#x20;
{% endhint %}

{% hint style="warning" %}
**Note Pages** are available in **Hobby Tier** & **Pro Tier**
{% endhint %}

### Note Pages History

The content of your Note Pages is automatically stored. You can view previous versions of individual notes by clicking the History button. History data is removed after six (6) months.

## Ports Section

The Ports Section of the Host Page shows a summary of known ports associated with the current Host. This list is built by importing XML files or adding ports manually. &#x20;

## Credentials Section

The Credentials Section lists all credentials captured for the current Host.&#x20;

{% hint style="info" %}
Toggle the password visibility by clicking the eye icon in the table header.
{% endhint %}

## Attachments Section

Attachments are automatically created when you import an XML file. The attachment on the Host Page represents information associated with the current Host only.&#x20;

## Tier Availability

**Host Page** is available on all tiers.


# Port Page

**Example URL:** <https://pentest.ws/e/{engagement.id}/host/{host.id}/port/{port.id}>

![Port Page](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FQ1QG07VliHga1Nv8zTS4%2Fimage.png?alt=media\&token=cb362038-9e0f-4165-9836-376d082422ce)

## Port Details

**Target**: Displays the Target value of the Host

**State**: A colored dot representing the port's state: Open, Closed, Filtered, Unfiltered

**Port**: The TCP/UDP port number

**Shortcuts**: Various quick links

**Service**: The identified service running on the TCP/UDP port, typically captured from Nmap

**Protocol**: TCP or UDP

**Version**: Version of the service, typically captured by Nmap's "-sV" option

**Status**: User defined status of the port, such as Vulnerable, Reviewed, Need Credentials, etc.

{% hint style="info" %}
**Level Up!**

Click the Pencil icon next to the Status field to edit your Status options.
{% endhint %}

## Port Note Pages

***Note Pages** are available on **Hobby Tier** and **Pro Tier***

A rich text editor for taking notes about the current Port. It supports copy-and-paste images from the clipboard for capturing screenshots.

{% hint style="info" %}
**Level Up!**&#x20;

Stay organized by attaching tool output directly to a Port. Create a new Note Page for each command output, such the results dirbusting a web folder or logging a nikto scan.&#x20;
{% endhint %}

## Checklist

***Checklists** are available on **Hobby Tier** and **Pro Tier***

Keep track of todo items when testing a Port, for example "don't forget to check robots.txt". This list is populated by your [Default Service Checklist](/hosts-and-services/default-service-checklist) when a Port is added to a Host. PenTest.WS will look for a matching service name (http, smb, ftp, etc) and import the checklist items automatically.

## Service Commands

***Service Commands** are available on **Hobby Tier** and **Pro Tier***

Based on the service name of the current Port, the Service Commands provides a quick and easy way to run your enumeration and attack commands. Click the clipboard icon to copy the command to your clipboard and paste the command into your terminal.&#x20;

Use your [Service Command Library](/hosts-and-services/service-command-library) to create your service command templates. Be sure to include variables such as $ip and $port to target the current Host:Port.

## Global Service Notes

GSN is a place to store information about a particular service (http, smb, ftp, etc). These notes are global and not attached to a single Engagement, Host or Port. Next time you encounter the same service, you will see your Global Service Notes for that specific service.

## Credentials Section

The Credentials Section lists all credentials captured for the current service under the current Host. If you add a credential for the HTTP service to the host, you will see that credential on all HTTP ports for that host.&#x20;

{% hint style="info" %}
Toggle the password visibility by clicking the eye icon in the table header.
{% endhint %}

## Attachments Section

Attachments are automatically created when you import an XML file. The attachment on the Port Page represents information associated with the current Port only.

## Tier Availability

**Port Page** is available on all tiers.


# Global Service Notes

**Example URL:** <https://pentest.ws/e/{engagement.id}/host/{host.id}/port/{port.id}>

The Global Service Notes are available on the [Port Page](/hosts-and-services/port-page).

![Global Service Notes - Port Page](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FOEhKgbGrBCBB87LKZzz1%2Fimage.png?alt=media\&token=9f4da6c2-8fe7-4c9e-9454-4e0935df6727)

GSN is a place to store information about a particular service (http, smb, ftp, etc). These notes are global and not attached to a single Engagement, Host or Port. Next time you encounter the same service, you will see your Global Service Notes for that specific service.

## Global Service Notes Manager

**URL:** <https://pentest.ws/gsn>

![Global Service Notes Manager](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2F34PIDqhQTzvrTAqUP0Cj%2Fimage.png?alt=media\&token=d9130374-cad2-4adb-8762-4ee9cc26cf07)

The GSN Manager is your central repository for all Global Service Notes. Typically GSNs are created using the Port Page when you encounter a service such as HTTP or SMB. However, here you can manually add a service and attach your notes.

## Tier Availability

**Global Service Notes** is available on all tiers.


# Service Command Library

The Service Command Library (SCL) contains command templates associated with a specific service such as HTTP, SMB, FTP, etc. When a service with a matching SCL entry is added to a Host, the Service Commands list is populated on the [Port Page](/hosts-and-services/port-page).

## Service Commands - Port Page

**Example URL:** <https://pentest.ws/e/{engagement.in}/host/{host.id}/port/{port.id}>

![Service Commands on the Port Page](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2Fz0QxFcWGYMtNPXpNTjdO%2Fimage.png?alt=media\&token=d358776c-18ed-47c5-a3e6-3d59ec7a061d)

The Service Commands listed on the Port Page display the command name, command content, and any attached notes.

### Copy & Paste Functionality

SCL works by copy-and-pasting a command from SCL to your terminal. By using variables such as $ip and $port in your templates, the commands are customized for the current Host and Port.&#x20;

{% hint style="info" %}
**Expert Example:**

Run a dirsearch directory brute force attack against the current service ($service), host (ip) and port ($port) and output the results to a timestamped port specific file.

```
/opt/dirsearch/dirsearch.py -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -t 50 -e '',html,php,txt -f --plain-text-report=log.$port.dirsearch.$(date +%s) -u $service://$ip:$port
```

{% endhint %}

To add, edit and delete command templates from you SCL, click the SCL Manager in the upper right corner of the Service Commands section on the Port Page, or use the Service Command Library link from your User Menu.

### Target & Additional Hostnames

On the [Host Page](/hosts-and-services/host-page), you can add additional hostnames associated with the current target. For example, if you have specified an IP address as your main target for the current host, add:

`target.local www.target.local app.target.local`

to the hostnames field. These additional hostnames will be available to your Service Commands. Simply use the drop down list at the top of the Service Commands section to attack the host using different hostname values.

## Service Command Library Manager

**URL:** <https://pentest.ws/scl>

![Service Command Library Manager](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FuMA3PqxrpUav9HoLKy27%2Fimage.png?alt=media\&token=8360a860-77db-4db2-a857-27e07ee45c85)

The Service Command Library Manager contains your repository of service command templates. Add, edit and delete command templates for existing service names, or add a new service name to pre-populate your list.

### Add / Edit Service Command Templates

Click an existing command template to bring up the Edit Service Command screen or click the Add Command button to create new service command templates.

![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FzRLNNO6gXl2YV1meowCw%2Fimage.png?alt=media\&token=59095c73-f69b-4f19-b18b-a7163b9dec7e)

**Service(s):** enter the corresponding service name such as HTTP, SMB, FTP, etc. This is used to match your service when adding ports to your Host.

{% hint style="info" %}
**Level Up! - Service Aliases**

Attach service command templates to multiple service names by using aliases. The Service(s) field can be a single service name, or a comma separated list of service names. If your command applies to more than one service, such as both HTTP and HTTPS, enter a value of "http, https".&#x20;

Aliases are indicated in the service list with indented bullets.&#x20;

:exclamation: Be sure to use the $service variable to attack the appropriate service.
{% endhint %}

**Name:** give you service command template a descriptive name to identify the command in your Service Commands list on the Port Page.

**Command:** create a command template using variables such as $ip and $port. Use the available buttons to insert variables at your cursor's current location.

**Notes:** these notes appear in the Service Commands list right below the mutated command

### Merge Services

Select a service and click the ![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FoJeytbKC4cHsY6Hm9x7i%2Fimage.png?alt=media\&token=1b776e1e-4a64-4cb5-9086-bdb565f8a745) icon in the top right. You will be prompted to select a second service to merge the command templates with.

![Merge Services](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2Fo7gwntTol1fSdmeG0NFU%2Fimage.png?alt=media\&token=4f632ae7-ed29-4cdf-8afd-4b231adc53c3)

The result is a single Service Command Library entry with an alias of the second service containing both the original command templates and the templates of the second service.

### Print All

Use the Print All button in the top right to generate an HTML report listing all of your services and associated service command templates. This is a great way to backup your command templates or share your list with fellow hackers.

### Delete Service vs Delete Service Command

Be aware there are two different delete buttons in the Service Command Library Manager, the **Delete Service** button and the **Delete Service Command** button.

When viewing the list of command templates for a service, the trash can icon in the service header is the Delete Service button: ![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FEJYPCM3s63OY9Qidacle%2Fimage.png?alt=media\&token=4d765aa0-3de7-4f10-8525-abeb309d705e). This will remove the current service from you SCL and delete all attached command templates.

![Delete Service](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FrkluEDERGSE2I0y1wNxm%2Fimage.png?alt=media\&token=710b3499-9d40-4df5-afdd-2364afc3f1a1)

When viewing an individual command, the Delete button will remove the current command template only: ![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2F4AxjLMMdOzZ5dY6WRSWA%2Fimage.png?alt=media\&token=a4c02c55-507f-4925-9b25-16f8232ca633)

![Delete Service Command Template](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FPcuvp7Y0oqKjmuwBA6Uv%2Fimage.png?alt=media\&token=4ef77c52-9c9c-48d4-b69b-4cc95fa0c342)

## Tier Availability

**Service Command Library** is available on **Hobby Tier** and **Pro Tier**, and limited to two (2) command templates per service on **Free Tier**.


# Default Service Checklist

**URL:**  <https://pentest.ws/dsc>

The **Default Service Checklist (DSC)** acts as a todo list for your services. Found on the [Port Page](/hosts-and-services/port-page), the service checklist contains a list of things to check or actions to take when a new service is discovered running on a target.

![Service Checklist on Port Page](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FNGTtCTKu2FD1H24BAVbu%2Fimage.png?alt=media\&token=597d009c-aa0e-4f80-bfe7-e6931e1fef6a)

As you work your way through enumerating and testing each service, mark items in your checklist complete by ticking the box next to each item. You can add checklist items on-the-fly or remove items from your checklist if needed. Adding, editing and deleting items from your checklist on the Port Page does not affect your Default Service Checklist.

Items can be reordered by dragging the ![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FDWoo4Zkhx57Uq7IeN318%2Fimage.png?alt=media\&token=1c9934ea-3f81-449f-ba8c-00ca8c17a585) icon up and down. Click the ![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FD0knc2MnRNHscJZCANdR%2Fimage.png?alt=media\&token=6862707b-1b91-4c13-85ff-b33dbebac656) icon to remove a checklist item.

To reload the Default Service Checklist for the current servce, click the ![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FfZK4rwodNTNXrLuCY7JW%2Fimage.png?alt=media\&token=ce549b59-7717-437d-b2df-0b7a57fe1127) icon in the Add Item line.&#x20;

To save the current checklist as the Default Service Checklist for the current service, click the ![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2F6uXBfUtrZQ8srTpSINbZ%2Fimage.png?alt=media\&token=c51b24dc-0a0b-4748-be75-2116107bc181) icon in the Add Item line. This will replace any exist DSC for this service.

## Default Service Checklist Manager

![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2F3VFZYlWUBphNjRS7MSbJ%2Fimage.png?alt=media\&token=70adf69a-34bb-407c-8af6-d378af2117c4)

The DSC Manager allows you to add, edit and delete items from a service's default checklist. You can also manually add services to the DSC using the "Add Service" button in the lower left.

Items can be reordered by dragging the ![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FDWoo4Zkhx57Uq7IeN318%2Fimage.png?alt=media\&token=1c9934ea-3f81-449f-ba8c-00ca8c17a585) icon up and down. Click the ![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FD0knc2MnRNHscJZCANdR%2Fimage.png?alt=media\&token=6862707b-1b91-4c13-85ff-b33dbebac656) icon to remove a checklist item. Click the ![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FDmsS2tQhyEGMoVxjDMBt%2Fimage.png?alt=media\&token=1f41a936-fd5e-441c-9dbf-d5dafb6558c0) icon to delete the current service and its Default Service Checklist.

## Tier Availability

**Default Service Checklist** is available on **Hobby Tier** and **Pro Tier**.


# Scratchpad Editor

**Example URL:** <https://pentest.ws/e/{engagement.id}/host/{host.id}/scratchpad>

Scratchpad is a per Host repository of your notes, programming code, scripts, documentation, or any other rich text you want to associate with a Host.

![Scratchpad Editor](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FqbYLXJUaEZRNgTK6S86L%2Fimage.png?alt=media\&token=81cc7284-ba2e-4ebb-b4a4-4897dd88d019)

* Code editing with syntax highlighting for over 150 programming languages.
* Hierarchical file structure with drag-and-drop.
* Download files through the browser or using wget/curl/downloadstring.
* Instantly switch between code & rich text editing.
* Import CherryTree XML files!

## Toolbar Buttons

### Tree Toolbar

![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2Fcg1bH2rCxuMz1LWJHi41%2Fimage.png?alt=media\&token=78c19616-2070-46f5-a5e7-313c45ca9cb9) Create a new sibling of the current document

![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FCHheYvm1RCk5rFvJCIQR%2Fimage.png?alt=media\&token=67b87bb2-1ef0-43ff-84cc-e48355503617) Create a child of the current document

![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FNX24DUyF4uvG7DYaFs6D%2Fimage.png?alt=media\&token=b211aa69-8612-4053-a32e-7533f698fcfc) Create a duplicate of the current document

![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FQBphVEkHflgg4I3YQjVP%2Fimage.png?alt=media\&token=ad9471d1-5a9a-41cd-af1a-cbc75a692343) Expand the document tree

![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FwZj4SpoNluMjpRVHziGL%2Fimage.png?alt=media\&token=f2202e2b-6608-4b52-9b73-bd66ebb9570f) Collapse the document tree

![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2F6vBuPyFZq4LvtNXCWDY7%2Fimage.png?alt=media\&token=ceb8deeb-eabd-4aba-a42e-095fd0c6f3ea) Import documents from either raw text / code, or CherryTree XML files

![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2Fjl6sZv9dGNDIircG0W4h%2Fimage.png?alt=media\&token=5809dc3d-4b5a-4cb9-bb34-343d69b1674d) Rebuild the tree from the document list. You will lose the hierarchy structure of the tree and all documents will be on the root node. This option is only needed when the document tree gets corrupted.

### Document Toolbar

![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FE4QxUk1bJfHB9TaWmw3C%2Fimage.png?alt=media\&token=35c42c91-fa18-46e9-9a9a-2556fe89d158) Select from the Code Editor or the Rich Text Editor. The contents of your document will be automatically converted between the two.

![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FqQzYKqW2FLVYpSm0UsGi%2Fimage.png?alt=media\&token=be9fe30f-29aa-4f6c-92b8-a58b82c59172) In Code mode, the language selector gives you syntax highlighting for over 150 different programming languages.

![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FY9d9haOJpXSt9gFg0ety%2Fimage.png?alt=media\&token=ffc93217-3051-4382-ae6c-67f2d621ca44) Download the content of the current document.

![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FuUwMgM78vYCvaATvdyTM%2Fimage.png?alt=media\&token=bb7d1dfc-5206-4160-a7c0-a030be8ca6c7) See the [Public Download](#public-download-scratchpad-items) section below

![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FD8zJFLCSsx3MyfnLHeEh%2Fimage.png?alt=media\&token=5ca03842-3013-4b9e-a35a-1cce8f2d13a3) Send To shortcuts to copy the current document to your clipboard. You can also send the document over to the [CyberChef](/built-in-tools/cyberchef) or [Echo Up](/built-in-tools/echo-up) tools.

## Document Tree

Scratchpad's document tree is a hierarchical file structure that supports drag-and-drop to reorder documents. You can also drag documents onto other documents to create child documents.

Double click a document in the Document Tree to rename the document.&#x20;

## Public Download Scratchpad Items

![Public Download](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FblDVx33B46qyNUr2rjm1%2Fimage.png?alt=media\&token=5cf02ff0-1465-40ee-a61e-be556877fb62)

Scratchpad documents can be downloaded using wget, curl, powershell or other HTTP request by clicking the ![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FAcFF18wLvsSRnscvIGtv%2Fimage.png?alt=media\&token=e0bf8366-ae19-433e-be05-29fd1824314d) button in the toolbar to make the document publicly available for 60 seconds.

The popup screen will give you a number of download commands and a timer indicating the number of seconds remaining before the document automatically returns to private state. At any time you can remove public access by clicking the ![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2F5p6AKOtniaMOeVnZTOAA%2Fimage.png?alt=media\&token=031a9d9f-e9c0-41f7-9cb6-6a5a834a474a) button.

When a document is public, no authentication is required to access the contents. The document is accessed by referencing the cryptographically secure random alphanumeric string. Anyone with this token can access the content while the document is public.

## Tier Availability

**Scratchpad** is available on **Hobby Tier** and **Pro Tier**, and limited to two (2) scratchpad documents per Host on **Free Tier**.&#x20;

The **Public Download** feature is not available on **Free Tier**.


# People Hacking

**Example URL:** <https://pentest.ws/e/{engagement.id}/people>

<figure><img src="https://pentestws.wordpress.com/wp-content/uploads/2025/05/image.png?w=1024" alt=""><figcaption><p><em>The individuals shown in this screenshot are entirely fictitious and generated for demonstration purposes only.</em></p></figcaption></figure>

The **People** page in PenTest.WS is your command center for tracking human targets during a red team engagement. Whether you're importing contacts for phishing, logging vishing attempts, or just enriching targets with metadata, this feature makes it easy to organize, search, and act on human intelligence.

## Overview

People are treated as first-class objects in PenTest.WS, just like hosts and services. Each person can include:

* Full name, job title, company, and location
* Tags for filtering (e.g. `finance`, `europe`)
* Multiple email addresses, phone numbers, and social links
* Freeform notes
* Linked events (calls, texts, phishing, etc.)
* Custom extra fields from import or manual entry

This makes it easy to build out real-world social engineering scenarios and tie them directly into findings or timelines.

## Importing People

To populate the People page, you can upload a file in one of the following formats:

* `.csv`
* `.json`
* `.xlsx` (Excel)

Only `first name` and `last name` are required. All other fields are optional but will be mapped where possible:

| Field Type     | Supports Multiple | Notes                                     |
| -------------- | ----------------- | ----------------------------------------- |
| `title`        | No                | Job title                                 |
| `company`      | No                | Company name                              |
| `location`     | No                | City or region                            |
| `tags`         | ✅ Yes             | Comma- or array-delimited                 |
| `emails`       | ✅ Yes             | Multiple email addresses supported        |
| `phones`       | ✅ Yes             | Supports various phone formats            |
| `links`        | ✅ Yes             | Social or profile URLs                    |
| *other fields* | ✅ Yes (dynamic)   | Stored under “Extra Fields” automatically |

> You can download a sample import file below:

{% file src="/files/03Bu4SKEV1WpxHCkVHB3" %}
**Sample File:** contains 1,000 fully fictitious entries for testing purposes
{% endfile %}

## Adding & Editing People

<figure><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FlldAFqjQpNspVa1S3b24%2Fimage.png?alt=media&amp;token=d274f923-b9eb-46c1-bfe9-a9365e134d5e" alt=""><figcaption><p><em>Edit Person</em></p></figcaption></figure>

You can also create or update individuals manually. The **Edit Person** page allows full control over all fields, including:

* Basic identity fields
* Tags (freeform)
* Custom links, emails, and phone numbers
* Rich text notes
* Extra fields (added automatically from imports or via the UI)

***

## Searching & Filtering

The People page uses a flexible filter system. You can stack multiple tags and metadata filters like:

* `north america`
* `engineering`
* `linkedin.com`
* `+1-202`

Only people matching **all** active filters are shown, allowing for precise targeting in large datasets.

***

## Linking Events

You can link people to events like:

* Phone calls (vishing)
* SMS messages (smishing)
* Emails or phishing attempts
* Physical impersonation

Event shortcuts are available from both the **main People page** and the **Edit Person** view. All events are timestamped in **UTC** and can be locked as **Evidence** to maintain a tamper-proof audit trail.

***

## Notes & Recommendations

* There’s no hard cap on how many people can be imported, thousands of records are supported.
* Extra fields added via import or UI can be deleted or renamed at any time.

## Tier Availability

**People Hacking** is available on **Pro Tier**.


# Events Timeline

**Example URL:** <https://pentest.ws/e/{engagement.id}/events>

<figure><img src="https://pentestws.wordpress.com/wp-content/uploads/2025/05/image-3.png?w=1024" alt=""><figcaption><p><em>Events list showing both social engineering logs and technical commands. All data shown is fictitious.</em></p></figcaption></figure>

The **Events** system in PenTest.WS provides a structured, timestamped log of your operational activity, from reconnaissance and exploitation to social engineering and post-exploitation actions. Events are searchable, flexible, and evidence-ready, making them essential for timeline analysis and reporting.

## Overview

Each event in PenTest.WS includes:

* **Timestamp** (UTC)
* **Title** or summary (e.g., `Phish: Email to Jane Doe`)
* **Command** (for technical actions like `smbclient`, `nmap`, etc.)
* **Person** or **host** references
* **Details** – one or more rich-text summary blocks
* **Meta Data** – freeform key-value pairs
* **Evidence Locking** – make entries immutable when needed

## Creating & Editing Events

<figure><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FhTyKHij8NgvQvwuzUBMG%2Fimage.png?alt=media&amp;token=ed635671-207d-4ca5-b51b-27f808a5d3b9" alt=""><figcaption><p><em>Edit Event view with capacity for multiple rich text notes and editable key-value metadata.</em></p></figcaption></figure>

You can create events manually or let the platform do it for you:

* **Manual Entry**: Click **Add Event** and fill in the form fields.
* **Auto-Generated Events**: When you click **Copy Command** in Hosts or Services, a corresponding event is created automatically.
* **People Events**: On the People page, you can quickly log a phishing, vishing, or smishing attempt using shortcut buttons.

***

## Evidence Locking

When an event is finalized and used as part of a finding or timeline, you can **mark it as Evidence** by clicking the lock icon.

* Evidence entries become **read-only and undeletable**
* Ensures data integrity for reporting, audits, or peer review
* Timestamp and author information is preserved

***

## Filtering & Sorting

The Events view allows filtering by:

* **Keyword** in title or summary
* **Time (Newest/Oldest)**
* **Type** (e.g. Command, Vishing, Phishing, etc.)

You can also export your timeline for additional processing or inclusion in external reports.

***

## Notes & Best Practices

* All timestamps are recorded in **UTC** to support correlation with other log sources
* Use consistent tags and metadata to streamline search and export
* Link people and hosts to ensure full traceability from action → target → impact
* Lock Evidence only after review - it cannot be edited or removed afterward

***

## Tier Availability

**Events Timeline** is available on **Pro Tier**.


# Boards

**Example URL:** <https://pentest.ws/e/{engagement.id}/boards>

Boards give you a flexible, drag-and-drop way to organize hosts within an engagement. Each board is user-defined and can contain any number of hosts, allowing you to visually track progress, group targets, or segment environments.

![Boards Demo](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FDa5ENuA7OyZLJtodZehW%2Fptws-boards-1.gif?alt=media\&token=a3ff1330-45b9-48db-b7c1-5b2f79772a71)

#### How Boards Work

* Create as many boards as you need within an engagement.
* Add hosts to boards using the sidebar or drag-and-drop.
* Move hosts between boards to reflect status or workflow.

#### Organizing Strategies

You can define boards to match the way you work. Common approaches include:

* **Status** – In Progress, Vulnerable, Cleared
* **Environment** – External, Internal, WiFi, Cloud
* **Domains** – AD: US, Europe, Asia
* **Phases** – Group 1, Group 2, Group 3

#### Advanced Uses

* **Board Filters** – Narrow your view to a single board for focus.
* **Team Collaboration (Pro Tier)** – In shared engagements, assign hosts by board to different testers.
* **Creative Workflows** – Use boards for labs (e.g., HackTheBox), with categories like *Active Testing*, *Pwned*, *Archived*.

#### Key Benefits

* Visual, intuitive host management
* Fully customizable for any workflow
* Scales from personal use to collaborative engagements

## Board Sub Menu

Access the Board Sub Menu by clicking the ![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FTK2NPzg8lOoo4wkWoojX%2Fimage.png?alt=media\&token=44b124e7-9bef-4da9-8449-8e8c931124f2) icon in the Board header. You can also use this icon to reorder the Boards using drag-and-drop.

![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FQXB3hFTrJrHMYDvMJLD6%2Fimage.png?alt=media\&token=fa494c3c-9c59-4786-979b-fbca7e398caf) Sort the Board's Hosts by ascending target values

![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FtNiQB48l4WKpawOT22cL%2Fimage.png?alt=media\&token=8d6bb40c-10c9-4944-9c48-b5f073f3212e) Sort the Board's Hosts by descending target values

![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FBYAdkwpvqRHyGM1ZziqE%2Fimage.png?alt=media\&token=c7e9fa1f-a297-476d-af08-957568ce16ef) Move all Hosts in this Board to another Board

![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FQ1GDKmH48GYufqHgUiEw%2Fimage.png?alt=media\&token=f7d21824-ef0f-4538-9432-ab064425c615) Equally distribute all Hosts in this Board to the other Boards

![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FLCll76xqQJVIvCvNVfiv%2Fimage.png?alt=media\&token=6b5bb8ca-b51b-46fa-a360-c4f0ac2b5953) Delete the current Board and move all Hosts to the Unassigned bucket

## Tier Availability

**Boards** are available on all tiers.


# The Matrix

**Example URL:** <https://pentest.ws/e/{engagement.id}/matrix>

The **Matrix** provides a high-level, interactive view of your entire engagement — showing every host and port in one place. It’s designed to help you spot patterns, identify targets, and quickly pivot into deeper testing.

![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FJPoJ5nrZ6xHJsQHKv6x4%2Fimage.png?alt=media\&token=877cbf0b-67ad-4052-8189-56df8296a51a)

#### Key Features

* **Complete Engagement View** – See all hosts and ports at a glance.
* **Flexible Filtering** – Narrow results by operating system, host type, host flags (including color flags), or port number/state/status.
* **Board Integration** – Filters and organization work seamlessly with your existing Boards.

#### How It Works

* Use filters at the top of the Matrix to refine your view.
* The sidebar automatically syncs with your selection, letting you jump into any host instantly.
* Port states and host attributes update dynamically, helping you track progress in real time.

#### Collaboration in Pro Tier

In shared engagements, the Matrix becomes a **personalized view** for each teammate. Every tester can apply their own filters and focus on their own objectives without disrupting the workflow of others.

#### Why Use the Matrix?

* Spot live services across dozens of hosts in seconds
* Prioritize targets for deeper testing
* Maintain situational awareness across large environments

## Tier Availability

**The Matrix** is available on all tiers.


# Subnetting

**Example URL:** <http://localhost:7897/e/{engagement.id}/subnets>

Pro Tier’s subnetting system allows the penetration tester or team to breakdown a large engagement, maintain scope, and focus on individual segments of a target network.

![Pro Tier's Subnetting System](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FZahz4GoKST8ARMRSgCpc%2Fimage.png?alt=media\&token=305eca56-6c3e-42f8-bccd-884e4cbb84ce)

## Subnet Filtering

Use the Filter column ![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FrL1PUJBjh9EjccvGgW9U%2Fimage.png?alt=media\&token=1959c098-1c34-4f99-9115-fe9ecaef2991)of the Subnets table to show or hide various subnets you have created. The application's [Sidebar](/getting-started/main-window-layout#sidebar), [Boards](/views-and-filtering/boards), and [Matrix](/views-and-filtering/the-matrix) views will reflect the IP subnets you selected. Use the ![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FjU7o5YehWnSbqHHGffFz%2Fimage.png?alt=media\&token=885317d6-8da9-4f98-b054-a61139c00a71) links at the bottom of the table to enable or disable all subnets.

## IP List Shortcuts

![IP Shortcuts](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2F4CTVkIth22iQcJPiLYzZ%2Fimage.png?alt=media\&token=ae22ade6-1954-4354-ae75-031fd4c583c6)

The Subnets screen provides a convenient list of filtered IP addresses to run additional tools against a subnet, such as nmap or EyeWitness to quickly scan large blocks of IP addresses.

## Subnet Scans

These subnets can be used in scan templates.

![Using Subnets in Scan Templates](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2Fb835OtLrI1rpDAmN6tfu%2Fimage.png?alt=media\&token=dc27922a-4d53-4e38-b308-a024e2c9f88e)

## Tier Availability

**Subnets** are available on **Pro Tier**.


# Shells Library

**URL:** <https://pentest.ws/tools/shells>

The Shells Library is a user defined list of commands to execute, receive and maintain reverse shells. New accounts receive a default list of commands which can be expanded upon as needed.

Click the *Edit Templates* button to enter *Change Mode*. Here you will be able to create new scan templates or modify existing templates.

## Reverse Shells

Reverse Shells is a user defined library of reverse shell commands meant to be executed through remote code execution vulnerabilities. Be sure to include your Host IP (%hip%) and Host Port (%hport%) variables in your command templates.

![Shells Library](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2F88WJ34whA7cTfZdFOc9M%2Fimage.png?alt=media\&token=a8d5e19b-4f40-4eef-8c4d-cc3d461eff4d)

## Shell Upgrades

This section of commands are used when a low quality shell is received from exploits such as remove code execution.

![Shell Upgrades](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FFtvCfOA2CP5G63ykQFhV%2Fimage.png?alt=media\&token=ade3822f-ee5b-4a05-b687-2017b0fd7155)

## Shell Fixes

When receiving a reverse shell, its often needed to configure your terminal session so the columns, rows, clear screen and autocomplete work correctly. Shell Fixes is your command list to solve these problems.

![Shell Fixes](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FMx4rPFR9aVPDtnyL4lzd%2Fimage.png?alt=media\&token=65db696d-0006-4272-9f58-263cc34d230a)

## Tier Availability

**Shells Library** is available on all tiers.


# General Command Library

**URL:** <https://pentest.ws/tools/commands>

The General Command Library (GCL) is a place to store all your frequently used, and not so frequently used, general system commands.

![General Command Library](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2F6eh5MWboZyKHzll9CGx1%2Fimage.png?alt=media\&token=a9d4d5db-3b8b-46b2-9050-850055f51cc6)

Much like how the [Service Command Library](/hosts-and-services/service-command-library) works for services, the GCL works for:

* System enumeration
* Privilege escalation
* Shell escapes
* File transfer shortcuts
* Powershell download cradles
* Pivot tunnels
* … and anything else!!

Each command can be organized by Operating System, Category, and Sub-Category values. These filters are user-created and self-populated as more and more commands are entered into your GCL system. Additionally, you can quickly search for keywords such as "wmic" or "iex" if you’re looking for a specific functionality.

Filters are sticky, so you can navigate away from the GCL screen and when you return later, you’re dropped right back into the list of commands you were previously viewing.

## Tier Availability

**General Command Library** is available on **Hobby Tier** and **Pro Tier**, and limits to five (5) commands on **Free Tier**.


# General Notes Library

**URL:** <https://pentest.ws/tools/notes>

All the functionality of [Scratchpad](/hosts-and-services/scratchpad-editor), but for general notes not associated with a specific Host:

* Code editing with syntax highlighting for over 150 programming languages.
* Hierarchical file structure with drag-and-drop.
* Download files through the browser or using wget/curl/downloadstring.
* Instantly switch between code & rich text editing.
* Import CherryTree XML files!

Your new General Notes Library is a great place to store your favorite pieces of C# code, common or rarely used procedural steps, or your exciting new research ideas and references. General Notes are linked to your account and not associated with an Engagement.

## Rich Text Editor

![Scratchpad Rich Text Editor](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2F6EbqZ4GELLfBtPeKcsZo%2Fimage.png?alt=media\&token=6bcd9ad1-6f8c-48d0-850c-2cbdaa9af89c)

## Code Editor

![Scratchpad Code Editor](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FPMXJx4SXcNYAR4W03OvQ%2Fimage.png?alt=media\&token=4327af11-91f4-4362-b0fa-77097182bec0)

## Tier Availability

**General Notes** **Library** is available on **Hobby Tier** and **Pro Tier**, and limits to five (5) documents on **Free Tier**.


# Bookmark Library

**URL:** <https://pentest.ws/tools/bookmarks>

![Bookmark Library](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2F79xjJzPmSmAIoCRQ2wFW%2Fimage.png?alt=media\&token=0d0414f7-2160-46ec-adda-cae47aac8a4e)

Store your security related bookmarks all in one place with the Bookmark Library. Add notes and assign keywords for easy retrieval later using filters, sort and search. You can also store local PenTest.WS links. Bookmark where you left an engagement Friday night and easily pick back up Monday morning.

## Tier Availability

**Bookmark Library** is available on all tiers.


# Echo Up

**URL:** <https://pentest.ws/tools/echo-up>

The Echo Up tool is useful for creating files on remote servers when you only have access to a terminal interface, either through a bash reverse shell or powershell remoting.

![Echo Up](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FQHvn9xc2ASmOe7HouE3d%2Fimage.png?alt=media\&token=899dcdfa-20c3-4785-80b1-aa351eb5c252)

On the left side of the screen you can manually enter file contents or use the Load File button to read in a local file. As you type, the right side of the screen will create a list of shell commands to build the file on the remote server by using a number of techniques.

## Base 64 Techniques

{% hint style="info" %}
The following examples will encode "Hello World" and generate a "helloWorld.txt" file.
{% endhint %}

### B64 bash

Linux - echos the payload to base64 and uses bash output redirection

```bash
echo -n 'SGVsbG8gV29ybGQ=' | base64 -d > helloWorld.txt
```

### B64 cmd

Windows - uses certutil and cmd variables to generate a file

```bash
del /Q helloWorld.txt
del /Q froqwcxj
echo|set /p="SGVsbG8gV29ybGQ=" >> froqwcxj
certutil -decode froqwcxj helloWorld.txt
del /Q froqwcxj
```

### B64 Powershell

Windows - powershell script using local variables and System.Convert

```powershell
del helloWorld.txt
$boizakxl = @()
$boizakxl += [System.Convert]::FromBase64String("SGVsbG8gV29ybGQ=")
[Environment]::CurrentDirectory = (Get-Location -PSProvider FileSystem).ProviderPath
[System.IO.File]::WriteAllBytes("helloWorld.txt", $boizakxl)
Remove-Variable boizakxl
```

## Quote Conversion Techniques

These examples parse the file contents converting single quotes to double quotes where needed. The file contents of the following examples is:

> This is a "test" of the application's Echo Up feature.

### Single Quoted

Wrap the file contents in single quotes and convert inner single quotes to a series of single quote, double quote, single quote, double quote, single quote.

```
echo 'This is a "test" of the application'"'"'s Echo Up feature.' > helloWorld.txt
```

### Double Quoted

Wrap the file contents in double quotes and convert inner double quotes&#x20;

```
echo "This is a "'"'"test"'"'" of the application's Echo Up feature." > helloWorld.txt
```

### No Quotes

Do not convert the file contents.

```
echo This is a "test" of the application's Echo Up feature. > helloWorld.txt
```

## Tier Availability

**Echo Up** is available on all tiers.


# CyberChef

**URL:** <https://pentest.ws/tools/cyberchef>

**Git Repo:** <https://github.com/gchq/CyberChef>

CyberChef, "The Cyber Swiss Army Knife," was created by [GCHQ](https://github.com/gchq) and is not maintained by PenTest.WS. It is included here for your convenience.

![CyberChef](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2Fr3h2raUq7rKnag7yz2OT%2Fimage.png?alt=media\&token=263da46f-02b7-4bc6-a1a1-6e20e98919d8)

## Tier Availability

**CyberChef** is available on all tiers.


# Venom Builder

**URL:** <https://pentest.ws/tools/venom-builder>

Venom Builder is a graphical user interface for building MSFVenom commands. The minimal steps required to use this tool are:

1. Select your Payload&#x20;
2. Enter your LHOST and LPORT values
3. Click the clipboard icon in the "MSF Venom Command" section
4. Switch to a terminal
5. Paste and execute the generated command
6. Launch the MSF console and load the matching payload handler
7. Deploy and execute the payload to your target

![Venom Builder](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FgO1Bop9AZlKIZtteognX%2Fimage.png?alt=media\&token=0a765770-b5ed-4f9e-8277-fdaf990d63bb)

{% hint style="info" %}
**Level Up!**

In the Payload search field, search for word fragments in any order to narrow down the list of payloads that match your environment and target.

**Example:** "win met rev tcp 64"
{% endhint %}

### MSF Venom Command Section

This is the dynamically generated MSFVenom command to build your reverse shell payload. Take advantage of the various other fields in the Venom Builder interface to refine and customize your MSFVenom command.

### Launch Console & Load Handler

This section generates a command to launch the MSF console and immediately load the payload's matching handler. This command is meant to be run locally in bash.

### Load Handler Only

This section generates a series of commands to load the payload's matching handler from inside the MSF console. The MSF console must be launched separately.

## Tier Availability

**Venom Builder** is available on all tiers.


# CVE DB

**URL:** <https://pentest.ws/tools/cve>

PenTest.WS maintains a local copy of the Common Vulnerabilities and Exposures (CVE) database and is searchable from within the application.

![CVE DB Search](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FBDNUj8MAreU95iUQHhg9%2Fimage.png?alt=media\&token=aca6b2f0-d930-4fc1-8cb5-28cda2b0d871)

The search functionality will match any CVE entry containing all of the words entered into the search field. This includes the CVE's ID, description, references and other fields.

### CVE Details

Clicking on a result in the search results provides detailed information about the CVE.

![CVE Details](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FOwhyLcaMIXB1PoxIZfBJ%2Fimage.png?alt=media\&token=d5535676-2d3e-4565-8055-3b77ec070825)

## Tier Availability

**CVE DB** is available on all tiers.


# Exploit-DB

**URL:** <https://pentest.ws/tools/exploit-db>

PenTest.WS maintains a local copy of the Exploit-DB (EDB) database and is searchable from within the application.

![Exploit-DB Search](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2Fmsw3avL94oyw2cpCTusu%2Fimage.png?alt=media\&token=41beef32-ec20-4f8a-80bf-74a1805c2e30)

The search functionality will match any EDB entry containing all of the words entered into the search field. This includes the title, platform, type, id, author, code and other fields.

### Exploit Details

Clicking on a result in the search results provides detailed information about the exploit.

![Exploit Details](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2Fdu8p5HTO9c2FbDuq3jZO%2Fimage.png?alt=media\&token=10630af7-5e26-432e-a722-33ffa128bc96)

## Tier Availability

**Exploit-DB** is available on all tiers.


# Nmap Scripts

**URL:** <https://pentest.ws/tools/nmap-scripts>

PenTest.WS maintains a local copy of the Common Vulnerabilities and Exposures (CVE) database and is searchable from within the application.

![Nmap Scripts Search](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2F5OhpwtcNrVJPHLGJqTcL%2Fimage.png?alt=media\&token=044dd7f6-cd39-405f-9ef0-4a180733e281)

The search functionality will match any Nmap Script containing all of the words entered into the search field. This includes the script's name, categories, port, source code and other fields.

### Nmap Script Details

Clicking on a result in the search results provides detailed information about the script.

![Nmap Script Details](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FBU5Ip7eH3EGmmdTJfl7F%2Fimage.png?alt=media\&token=cae44dbd-2b0f-45ce-b2cd-04edb981a869)

## Tier Availability

**Nmap Scripts** are available on all tiers.


# Metasploit Modules

**URL:** <https://pentest.ws/tools/msf-modules>

PenTest.WS maintains a local copy of the Common Vulnerabilities and Exposures (CVE) database and is searchable from within the application.

![Metasploit Modules Search](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FUzK1PSuDKkMBe2TfFvDt%2Fimage.png?alt=media\&token=ae0eca8c-d9c0-4ad1-b3fc-c499399bb2e7)

The search functionality will match any Metasploit Module containing all of the words entered into the search field. This includes the module's name, type, platform, source code and other fields.

### Metasploit Module Details

Clicking on a result in the search results provides detailed information about the module.

![Metasploit Module Details](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FdJtKvbUVk95VRpR7josG%2Fimage.png?alt=media\&token=76820126-9ea2-4372-bbc5-fd8dbec59bfa)

## Tier Availability

**Metasploit Modules** is available on all tiers.


# Keyword Search

**URL:** <https://pentest.ws/search>

The Keyword Search feature attempts to locate your keywords by searching through Engagements, Hosts and Ports looking for any matching field. You can search All Engagements or limit your search to a particular Engagement, such as the Engagement you are currently working on.

![Keyword Search](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FAidhqbXHt8uKKNMSK9lc%2Fimage.png?alt=media\&token=44df4fe1-56b0-45f2-8280-7eb626bf37be)

**Path:** this is the breadcrumbs of where your keywords where found, starting with the Engagement and moving into its Hosts, Ports and even Note Pages of each object.

**Matches:** shows the field and value of where your keywords where found.

Click any of the results to jump straight to the location of your keywords.

## Tier Availability

**Keyword Search** is available on all tiers.


# Engagement Findings

During a security assessment we often discover vulnerabilities in web applications, network infrastructure, and Active Directory environments, generally called Findings. These issues need to be documented and later reported back to the client for remediation. The new Findings System in PenTest.WS aims to make this process of collection & documentation as easy as possible.

## Engagement Findings

**Example URL:** <https://pentest.ws/e/{engagement.id}/findings>

<figure><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2Fc9z0t7pucqRtZb2WN1e6%2Fimage.png?alt=media&amp;token=dc2a33e4-d335-49c2-98c1-c79d4169076d" alt=""><figcaption></figcaption></figure>

Visiting the Findings tab in an Engagement brings up the Engagement Findings screen. Here you will see all of the previously identified vulnerabilities with their various details. The colors of the Findings are defined in your [Findings Admin](/findings/findings-admin) screen.

### Auto ID

Auto ID is a time-saving feature that automatically sets the Finding's ID value based on a template you define for each Engagement. Use any format you need and include hash marks (#) where you want the system to sequentially number each finding.&#x20;

In this example we have defined "ACME.##" as the Auto ID format. The Findings System then numbers the Findings:

* ACME.01
* ACME.02
* ACME.03

The numbers are left padded with zeros based on the number of hash marks.&#x20;

{% hint style="info" %}
Auto ID values are automatically updated when you re-sort the Findings list.
{% endhint %}

### Drag-Drop Sorting

Most things in PenTest.WS can be drag-and-dropped to sort the objects, including your Findings. Drag a Finding up or down and the system will not only sort them as requested, but also re-number the Findings according to your Auto ID format.

## Using the Findings Library

**Example URL:** <https://pentest.ws/e/{engagement.id}/findings/add>

<figure><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FAOzoF6QttvcYyiYBySs5%2Fimage.png?alt=media&amp;token=5211ce45-fcb0-45ce-b4bf-7550c29c4276" alt=""><figcaption></figcaption></figure>

When you click the "Add Finding" button on the Engagement Findings screen you will be presented with the Add Finding utility. Search is available as a global search in the top right, or search specific columns using their header search fields.

If you do not have a Findings Library entry for your new Finding, click the "Add Manual Finding" button and fill out the vulnerability information.

Click an entry in the Findings list to import the Finding into your current Engagement.

### Finding Preview

Before a Finding from your Findings Library is imported into the current engagement, you are presented with a Finding Preview window.

![Finding Preview](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FHo1ppFoDW2Vkacff746r%2Fimage.png?alt=media\&token=57251e22-6531-41c7-9a9e-22127274cf55)

This allows you to review the details of the Findings Library entry and decide to Add To Engagement or not. This step is useful if you have multiple listings describing the same issue but each have slightly different information or circumstances.

## Finding Detail

**Example URL:** <https://pentest.ws/e/{engagement.id}/findings/{findings.id}>

<figure><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FF2CFYMadK9hx0tZ8FftD%2Fimage.png?alt=media&amp;token=205c7ce0-a7b3-4c95-8e6e-9d36fc6e0a38" alt=""><figcaption></figcaption></figure>

Sections of the Finding Details page can be enabled/disabled and renamed in the [Findings Admin](/findings/findings-admin) panel. Below is a brief explanation of each.

### Main Info

**Title**: the main title of the Finding, such as "SQL Injection".

**Risk Level**: rate how critical this Finding typically is. This value can be adjusted when creating an Engagement Finding if required.

**Environment**: custom or pre-defined environment where the Finding was discovered

**Category**: the category of the Finding. In a web application assessment, this might map to the OWASP Top 10.

**Status**: is this a new finding, has it been accepted, rejected, mitigated?

### CVSS

Enter details about the Finding's Common Vulnerability Scoring System (CVSS) score. More information about CVSS scoring is available here:

* <https://www.first.org/cvss/>
* <https://nvd.nist.gov/vuln-metrics/cvss>
* <https://en.wikipedia.org/wiki/Common_Vulnerability_Scoring_System>

### DREAD

Assign values for each of DREAD categories:

* Damage – how bad would an attack be?&#x20;
* Reproducibility – how easy is it to reproduce the attack?&#x20;
* Exploitability – how much work is it to launch the attack?&#x20;
* Affected users – how many people will be impacted?&#x20;
* Discoverability – how easy is it to discover the threat?

<https://en.wikipedia.org/wiki/DREAD_(risk_assessment_model)>

### Background

Provide some general background information about the vulnerability. This is not meant to include specific details about the client's environment, application, system, people, etc. Background should provide context for the client to better understand the nature of the vulnerability.

### Description

{% hint style="info" %}
**Brief Fields**

The Description, Impact and Recommendation fields have Brief variants of their values. These are meant to be short descriptive versions of the full language field. For example, "Description - Brief" summarizes the Finding's "Description" in one or two sentences. These brief fields are useful for short executive summaries where the longer version is not needed.
{% endhint %}

Describe the vulnerability in detail. Consider including the following information:

* What you saw
* Where you saw it
* When you saw it
* How you discovered it
* Variables, URLs or file paths relevant to the Finding

Another import detail to include in the Description is the authorization and/or authentication required to exploit this vulnerability as this can greatly affect the Impact and Risk Level of the vulnerability.

### Impact

The Impact of a vulnerability is a description of the harm an attacker could inflict on a client when exploiting the vulnerability. This is often related to the confidentiality, integrity and availability of the client's assets, known as the CIA Triad.

**Confidentiality** - be sure to consider the type of data exposed in a loss of confidentiality. When Personally Identifiable Information (PII) is leaked, the Impact can be greatly increased.

**Integrity** - adjust the risk to integrity in accordance with the control an attacker would gain over a client's data. Can the attacker modify existing data or inject new records such as hidden admin accounts? What about removing event logs to hide the attack's evidence?

**Availability** - during a Denial of Service (DoS) attack, data and services may be slow or unreachable, but these attacks are typically temporary. The Impact might be greater if an attacker can delete data or completely crash a service that requires human intervention to recover.

### Recommendation

Provide a list of recommended steps to remediate the vulnerability. Classic recommendations include validating user supplied data, implementing the Principle of Least Privilege and practicing Defense in Depth.

Increase the value of your recommendation by providing an effort level and time-frame the client can expect to fully patch a system or implement additional security controls.

### References

Consider adding reference URLs to support the Background, Impact and Recommendations your are providing to your client. Try to limit your reference links to primary sources of information.

### Targets

A single Finding may apply to single or multiple Targets. List the vulnerability end-points, systems or networks where your Finding applies.

### Evidence

Provide supporting evidence to your Finding. Common evidence includes screenshots and command logs. Timestamps are a great idea to help the client's investigation during a debrief.

### Validation Steps

Once the client has remediated the vulnerability outlined in your Finding, validation should be performed. It may be easiest for the original penetration tester to describe the steps needed to conduct this validation, and the Validation Steps is a convenient way to document these details at the time the Finding is discovered.&#x20;

Many times the validation can occur weeks or months after the initial report, and sometimes conducted by a different penetration test, team or the client themselves. A few quick notes on how to validate the solution can save everyone a bit of time in the future.

### Remediation Log

The Remediation Log is meant to be an internal field for keeping track of the remediation status the client has reported. This data is not necessarily meant to be shared with the client. Date and time stamps, along with the name of the person updating the log, is good information to include for long running remediation processes.

## Tier Availability

**Engagement Findings** are available on **Hobby Tier** and **Pro Tier**.


# Findings Groups

Findings Groups provide a way to organize findings within an engagement into logical categories. Instead of working from a flat list, Pro users can create groups (such as *External*, *Internal*, or *Social Engineering*) and drag findings into them. This makes it easier to manage large engagements, highlight patterns, and produce reports that clearly communicate risk in context.

### Why Use Findings Groups

* **Organize findings logically** – Group findings by environment, test type, or methodology.
* **Improve readability** – Clients can more easily understand findings when they’re presented in structured sections.
* **Flexible workflow** – Groups are optional. Engagements start with a flat list of findings, and groups can be added only if you need them.
* **Report integration** – Groups carry over into reporting, so your exported documents reflect the same structure you set in the engagement.

### Creating and Managing Groups

<figure><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2F6cKXjzuFTTHYwX0EaNSj%2Fimage.png?alt=media&amp;token=d009f51b-42e9-46f6-895d-846313e92ddb" alt=""><figcaption></figcaption></figure>

From the Findings page, click **Groups** to open the group management screen. Here you can:

* **Add Group** – Create a new group and define its Auto ID format.
* **Edit Group** – Rename the group or change its Auto ID.
* **Reorder Groups** – Drag and drop groups to change their order.
* **Delete Group** – Remove a group (findings inside will return to *Uncategorized*).

### Auto IDs

Normally, the Findings page has a single **Auto ID** format that controls numbering for all findings (e.g., `F-##`). When groups are created, Auto ID moves to the group level. Each group has its own Auto ID format, which controls how findings in that group are numbered.

Example:

* Group **External** with Auto ID `EX-##` will assign IDs like `EX-01`, `EX-02`.
* Group **Internal** with Auto ID `IN-##` will assign IDs like `IN-01`, `IN-02`.

IDs are automatically updated based on the group’s Auto ID format and the position of the finding within the group.

### Uncategorized Findings

When groups are first created, any existing findings are automatically assigned to a special group called **Uncategorized**. From here you can:

* Drag and drop findings into the appropriate group.
* Once moved, the finding will be automatically re-ID’d according to the group’s Auto ID and order.

This ensures that every finding belongs to either a specific group or *Uncategorized*.

### Drag and Drop Organization

The Findings page allows you to expand or collapse groups, then drag findings into them. Findings can be freely moved between groups. The system automatically renumbers findings to match the new group’s Auto ID scheme.

### Grouped Findings Example

<figure><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2F0ognJqkyaRQk8L2UUwDQ%2Fimage.png?alt=media&amp;token=0a31a2cc-a0f7-40ea-b848-884069387675" alt=""><figcaption></figcaption></figure>

Here you can see findings organized into three groups: *External*, *Internal*, and *Social Engineering*. Each finding has been automatically assigned an ID based on the group’s Auto ID format (e.g., `EX-01`, `IN-02`, `SE-03`). This structure makes it easy to separate findings by scope and ensures numbering remains consistent within each group.

### Reporting

Grouped findings carry over into reporting and can be displayed using the `findingsGrouped` collection in templates. See [Working with Grouped Findings](https://docs.pentest.ws/clients-and-reporting/reporting-templates-admin#working-with-grouped-findings) for template examples.

## Tier Availability <a href="#tier-availability" id="tier-availability"></a>

**Findings Groups** is available on **Pro Tier**.


# Findings Library

**URL:** <https://pentest.ws/findings-library>

During a security assessment we often discover vulnerabilities in web applications, network infrastructure, and Active Directory environments, generally called Findings. These issues need to be documented and later reported back to the client for remediation.

The Findings Library is a repository of documentation templates for vulnerabilities such as SQL Injection and add generic text for background information, descriptions, impact, recommendations, as well as a default risk level and reference links. During a live security assessment, these findings templates can quickly be added to the engagement in real-time as you discover them. Further refinements can then be captured with unique details about each specific finding.

![Findings Library List](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FN1qJOTel4U05PZPf1CVn%2Fimage.png?alt=media\&token=178dcdcc-dbb9-4b14-979d-18b2cb96866c)

To get started, click the ![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FrEDdj9wDrR8nc9KDRJva%2Fimage.png?alt=media\&token=56000be5-7708-43f7-8188-c64dfc01d9de) button to start building a Findings Template.

![Findings Library Add / Edit](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2F6CShjrTEpqmLGciDq7tD%2Fimage.png?alt=media\&token=f8b35fcc-336c-4a30-9af8-fa210ebe72f6)

## Main Info

**Title**: the main title of the Finding, such as "SQL Injection".

**Environment**: custom or pre-defined environment where the Finding was discovered

**Category**: the category of the Finding. In a web application assessment, this might map to the OWASP Top 10.

**Risk Level**: rate how critical this Finding typically is. This value can be adjusted when creating an Engagement Finding if required.

## CVSS

Enter details about the Finding's Common Vulnerability Scoring System (CVSS) score. More information about CVSS scoring is available here:

* <https://www.first.org/cvss/>
* <https://nvd.nist.gov/vuln-metrics/cvss>
* <https://en.wikipedia.org/wiki/Common_Vulnerability_Scoring_System>

## DREAD

Assign values for each of DREAD categories:

* Damage – how bad would an attack be?&#x20;
* Reproducibility – how easy is it to reproduce the attack?&#x20;
* Exploitability – how much work is it to launch the attack?&#x20;
* Affected users – how many people will be impacted?&#x20;
* Discoverability – how easy is it to discover the threat?

<https://en.wikipedia.org/wiki/DREAD_(risk_assessment_model)>

## Background

Provide some general background information about the vulnerability. This is not meant to include specific details about the client's environment, application, system, people, etc. Background should provide context for the client to better understand the nature of the vulnerability.

## Description

Findings Library entries should not contain specific details such as URLs, variables or file paths. Rather, the Description field should give the penetration tester who is reporting the vulnerability a good starting point to describe what was observed during the pentest.

## Impact

The Impact of the vulnerability can be fairly static from Engagement to Engagement, although the depth of the Impact might change. For example, a SQL Injection vulnerability would generally allow an attacker to read arbitrary data from a database. This would make a good starting point for the report.

However, in the example of a SQL Injection, the Impact would be greatly increased if protected data, such as Personally Identifiable Information (PII) was leaked as a result of the exploit. Try to build your Impact statements accordingly.

## Recommendation

As with Impact, the Recommendation for vulnerabilities is often similar when discovered. Continuing our SQL Injection example, the recommended fix might be to filter and validate all incoming user supplied data before passing to a back-end database engine.

## References

Consider adding reference URLs to support the Background, Impact and Recommendations your are providing to your client. Try to limit your reference links to primary sources of information.

## Tier Availability

**Findings Library** is available on **Hobby Tier** and **Pro Tier**.


# Findings Admin

**URL:** <https://pentest.ws/findings-admin>

The Findings Admin screen allows you to customize the fields available in the Findings Library. Don’t need to capture Validation Steps or track a Remediation Log? Simply visit the Findings Admin utility and hide these fields. Want to rename the References field to External Links? No problem. Add/Remove environments and categories. You can even change the color of your Risk Levels!

![Screenshot has been truncated for space](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FqXOfrGuNE8lnzQltj81s%2Fimage.png?alt=media\&token=9b5e73f4-ef19-4f1b-9b5c-f0ab4af32255)

## Fields

Elect to show or hide various fields such as CVSS or DREAD. If your organization doesn't use a particular field, simply remove it from your user interface.&#x20;

![Fields Section](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FKNE5rzBKdAvL0P9PsO0v%2Fimage.png?alt=media\&token=f5fa5af8-a4cc-434f-86d3-81d69dddf3f1)

{% hint style="info" %}
Hiding fields from the user interface does not remove data from the database. Any previously entered values in Engagement Findings or Findings Library entries will not be lost, only hidden.
{% endhint %}

### Brief Fields

Several fields in the Findings System have a Brief variant. These are meant to be short descriptive versions of the full language field. For example, "Description - Brief" summarizes the Finding's "Description" in one or two sentences. These brief fields are useful for short executive summaries where the longer version is not needed.

Not all organizations take advantage of these brief fields, therefor they are broken out in the Fields list and can be hidden from your Findings Systems while keeping the full language field.

### Rename Fields

Use the Rename functionality to customize the names of certain fields. Renaming a field affects your [Findings Library](/findings/findings-library) interface and all [Engagement's Findings](/findings/engagement-findings). This does not affect generated reports since those details are customizable by uploading a new [Report Template](/clients-and-reporting/reporting-templates-admin).

Renaming brief fields affects both the brief version of the field and the full language field.

## Lists

These lists are the available drop down values when creating a Finding during an Engagement.

![Lists Section](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2Fku0tQpY3QkIMMWVqfOOn%2Fimage.png?alt=media\&token=103555c7-a46a-4dd7-adbd-80e0e03e87a7)

{% hint style="info" %}
Modifying these lists does not affect previously created Engagement Findings or Findings Library entries. This only affects the list shown while creating new entries.
{% endhint %}

### Environments

Define the environments you operate in, such as Web, Internal, External, etc.

### Categories

The format for Categories is:

`Environment - Category`

Environment is optional and limits the Category to the Environment. If no Environment is specified, the Category will appear in all Environments.

### Risk Levels

The format for Risk Levels is:

`Risk Level - Color`

Color is optional and can be a named color (red, green, blue) or an RGB color code (#ff000, #00ff00, #0000ff).

## DREAD

The DREAD values are pre-populated with standard DREAD values. You can modify these lists if your organization uses a custom DREAD scoring system.

![DREAD Section](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FjcTOZ9JS6Iy79eda0EyJ%2Fimage.png?alt=media\&token=fe282957-3f58-41f5-bfa1-161266cd60e6)

## Tier Availability

**Findings Admin** is available on **Hobby Tier** and **Pro Tier**.


# Write-Ups

**Example URL:** <https://pentest.ws/e/{engagement.id}/host/{host.id}/writeup>

The Write-Up tab is meant to document a walk-through of challenge boxes such as VulnHub or HackTheBox.

![Host Write-Up](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FmfFIRdw4KZHmzd2zcgsB%2Fimage.png?alt=media\&token=560a3665-b74a-4d4f-af6a-0ca71f3c9245)

## Tier Availability

**Write-Ups** are available on all tiers.


# Clients Manager

**URL:** <https://pentest.ws/clients>

The Clients Manager works in coordination with Engagements and the Reporting Module. New Engagements can be associated with a Client or the Engagement can be assigned to a Client from the Engagement Console.

![Clients Manager - List](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FSSe4A1WZYCBSXAifvFyI%2Fimage.png?alt=media\&token=4941ef0b-f65c-4e1c-8166-a36d11f62a7a)

### Add / Edit Client

![Clients Manager - Add / Edit](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FiyhdCIOp8uD73wI2HbqW%2Fimage.png?alt=media\&token=8df16c73-6032-4da4-82f9-5d1507c3f52a)

## Tier Availability

**Clients Manager** is available on **Hobby Tier** and **Pro Tier**.


# Reporting Templates Admin

**URL:** <https://pentest.ws/reporting-admin>

Once that you have collected your set of Findings for the client, you need to build a client deliverable document with these details. The Reporting Module processes user-uploaded Word files with embedded {{tags}} to generate fully customized reporting documents with a single click.

## Report Templates Admin

<figure><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2F7iCXP0QKRVtYulR4AFM1%2Fimage.png?alt=media&amp;token=b7973abb-bc55-4a06-947f-7dcf77c585ec" alt=""><figcaption><p>Report Templates Admin</p></figcaption></figure>

{% file src="/files/xBuu4248CDvbl7vVmdfM" %}

{% file src="/files/rD7Dfce81Rp0cnM3j5X0" %}

Start by downloading a report template and begin customizing your company name, logo and other needed details.&#x20;

Upload your Report Template using the Report Templates Admin screen. From here, the template will be available for use in the Engagement's Reports tab. See [Generating Deliverable](/clients-and-reporting/reporting) for more details.

## Template Syntax

The template syntax includes For loops, If statements, and Variables and HTML content from your Findings entries including embedded images like screenshots for evidence. Using the [Client Manager](/clients-and-reporting/clients-manager) you can add tags such as `{{= client.name}}` and `{{= client.shortName}}`, its just one less thing you need to fill out in the final report. Once the Reporting Module is finished processing, your browser downloads the new DOCX file where you can further customize the report as needed.

### Fields List

For a full list of fields available in your report templates, visit:

<https://gist.github.com/PenTestWS/c5d378e789e06e81a142495ea3823a52>

### Text Variables

```
{{= engagement.name}}
```

Simple text variables are referenced using the `{{= variable}}` format. You can also insert statements such as `{{= client.city + ", " + client.state + " " + client.zip}}`

Notice that with simple text variables, the dollar sign $ is not required to reference the variable, but other syntax statements requires the dollar sign $.

### Rich Text / HTML

```
{{HTML $finding.descFull}}
```

Fields in the PenTest.WS user interface that use the rich text editor require the HTML format `{{HTML $variable}}` to reference the variable in the reporting template.

The HTML format is also capable of rending images you have inserted into the associated field.

### IF Statements

```
{{IF $finding.evidence != ""}}
    
    Evidence:
    {{HTML $finding.evidence}}
    
{{END-IF}}
```

Conditional statements are supported through the `{{IF $variable = "value"}}` syntax. To end the if statement use `{{END-IF}}`.

### FOR Loops

```
{{FOR finding IN findings}}
    Title: {{= finding.title}}
    Risk:  {{= finding.riskLevel}}
{{END-FOR finding}}
```

For loops allow you to step through arrays such as Hosts and Findings and follow the classic For Loop programming language structure `{{FOR x IN array}}` and end with the `{{END-FOR x}}` statement.

## Working with Grouped Findings

When using **Findings Groups** in engagements, your reporting templates can be updated to display findings organized by group. This allows your exported reports to mirror the same structure you set inside PenTest.WS (e.g., grouping findings into *External*, *Internal*, or *Social Engineering*).

To enable this, use the `findingsGrouped` collection in your Word template. The general structure looks like this:

```
{{FOR group IN findingsGrouped}}

{{= $group.groupName}} Detailed Findings

    {{FOR finding IN $group.findings}}

    {{= $finding.findingId}} - {{= $finding.title}}
    {{= $finding.riskLevel}}
    {{= $finding.descFull}}
    {{= $finding.impactFull}}
    {{= $finding.recoFull}}

    {{END-FOR finding}}

{{END-FOR group}}
```

#### Explanation

* **findingsGrouped** – The collection of all groups defined in the engagement.
* **$group.groupName** – The display name of the group (e.g., *External*).
* **$group.findings** – The list of findings inside that group.
* **$finding** – A single finding object, which exposes all the same fields available when working with ungrouped findings (e.g., `findingId`, `title`, `riskLevel`, `descFull`, `impactFull`, `recoFull`).

If no groups are created in the engagement, the `findingsGrouped` collection will be empty and you can continue to use the standard `findings` collection as before.

#### Example Output

```
External Detailed Findings

101 - Outdated Apache HTTP Server
102 - Weak TLS Configuration

Internal Detailed Findings

201 - Excessive SMB Share Permissions
202 - Hardcoded Credentials in Scripts
```

This structure ensures grouped findings appear neatly in your final reports, giving clients context for how issues relate to one another.

## Sample Report Template - Non-Grouped Findings

{% file src="/files/TztPyEWYxrFUenKbvJki" %}

{% embed url="<https://pentest.ws/docx/PTWS_Report_Template_2025_May.docx>" %}

## Sample Report Template - Grouped Findings

{% file src="/files/H4uX7bR8VXhC7Tk5uRgU" %}

## Tier Availability

**Reporting Templates** are available on **Hobby Tier** and **Pro Tier**.


# Reporting Briefs Admin

**URL:** <https://pentest.ws/reporting-admin>

Reporting Briefs let you build, maintain, and reuse narrative content for your reports. Instead of copy-pasting from past documents, you can create a library of briefs that are stored directly in PenTest.WS. Each brief can be customized per engagement, making reporting faster, more consistent, and more professional.

### Why Use Reporting Briefs

Reports are more than technical data — they need context and explanation. Reporting Briefs help you:

* **Save time** – Reuse standard sections across multiple reports.
* **Ensure consistency** – Keep executive summaries, scope statements, and methodologies aligned across engagements.
* **Customize per engagement** – Use default content as a starting point, then tailor it to the specific client or test.
* **Centralize reporting content** – Manage all narrative text within PenTest.WS, instead of scattered files.

Examples of common briefs include:

* *Objectives & Scope*
* *Engagement Overview*
* *Methodology*
* *Testing Limitations & Assumptions*

## The Reporting Briefs Admin Page

<figure><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FCR9huJVTOmj7PljPK2WO%2Fimage.png?alt=media&amp;token=21b82d93-2746-4c86-aa20-af27dd23b176" alt=""><figcaption></figcaption></figure>

The Reporting Briefs page lists all available brief templates.

For each template, the list shows:

* **Title** – The name of the brief (e.g., *Objectives & Scope*).
* **Key** – A short identifier used to reference the brief in reporting templates.
* **Is Default** – Indicates whether this brief is included by default in new Engagements.
* **Default Content** – The starting text for the brief, which can be edited per engagement.
* **Actions** – Options to edit or delete the brief template.

From this page you can:

* Create a new brief using the **Define New Brief Template** button.
* Edit existing briefs to update their default content.
* Delete briefs you no longer need.

## Brief Template Details

<figure><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FE9hLRgN658BVNKehjXuJ%2Fimage.png?alt=media&amp;token=ce0a84f6-b0d2-4247-9643-ebf65b146e89" alt=""><figcaption></figcaption></figure>

Each Reporting Brief template has its own details page where you can configure the title, key, and default content for the brief. This is where you define what the brief will look like when it is added into Engagements.

### Template Fields

* **Title** – The display name of the brief (e.g., *Objectives & Scope*). This is what appears in the list of available briefs when working in an Engagement.
* **Key** – A unique identifier used in reporting templates to pull in the brief’s content. For example:

```
{{HTML briefs.objectives || "*** MISSING OBJECTIVES ***"}}
```

In this example, if the brief with the key `objectives` is defined, its HTML content will be inserted into the report. If not, the placeholder text `*** MISSING OBJECTIVES ***` will be displayed.

* **Is Default** – When checked, the brief will be automatically included in all new Engagements.

### Default Content

The content editor allows you to define the reusable text that will serve as the starting point for this brief.

* Rich text formatting is supported, including headings, bold, italic, lists, links, and code blocks.
* Images and inline elements can also be embedded.
* The text here becomes the default content that appears whenever this brief is added to an Engagement.
* During an engagement, the content can be customized without affecting the saved template.

Example:

> *The objective of this engagement was to evaluate the security posture of Client’s environment by identifying vulnerabilities, misconfigurations, and other weaknesses that could be exploited by an attacker.*

### Actions

* **Save / Update** – Edits to the title, key, or default content are saved automatically to the template.
* **Delete** – Permanently remove the brief template from the system.

## Tier Availability <a href="#tier-availability" id="tier-availability"></a>

**Reporting Briefs** are available on **Pro Tier**.


# Reporting

**Example URL:** <https://pentest.ws/e/{engagement.id}/reporting>

The **Reporting** page inside an engagement is where you generate final deliverables. From here, you can assemble the content of your report, manage briefs, and export reports using your defined templates.

<figure><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FZWgEjPT8ZLjICpIIrvpP%2Fimage.png?alt=media&amp;token=97b03124-3bb6-4dcf-8031-fc9b9c274d8e" alt=""><figcaption></figcaption></figure>

### Report Templates

Clicking **Generate Report** opens a dropdown menu with a list of available report templates.

* Each template defines the structure of the exported document.
* Templates can be designed for engagements with **ungrouped findings** or with **findings groups**, since the layout requirements are different depending on how findings are organized.
* Selecting a template will generate a report that pulls in all relevant findings, briefs, and engagement data.

### Briefs

The Reporting page also displays a list of **Briefs** that have been added to the engagement.

* Briefs may be automatically included as defaults when the engagement is created.
* Additional briefs can be added using the **Add Brief** button.

When adding a brief:

* You can select from existing **Brief Templates** (e.g., *Objectives & Scope*, *Engagement Overview*).
* You can also add a **Manual Brief**, where you define the Title and Key directly.

### Handling Missing Briefs

If your report template references a brief that is not currently included in the engagement (for example, the template contains `{{HTML briefs.methodology}}` but no *Methodology* brief exists), the system will prompt you before the report is generated.

* If a matching **Brief Template** is found, the system will automatically load it.
* If no template exists, a new blank brief will be created with the correct title and key so you can fill it in before completing the report.

This ensures that every referenced brief is accounted for in the deliverable.

## Tier Availability

**Reporting** is available on **Hobby Tier** and **Pro Tier,** although some functionality is limited to Pro Tier.


# User Maintenance

**Example URL:** <http://localhost:7897/admin/users>

Pro Tier's User Maintenance is available from the Admin Panel. The number of active users is limited by your Pro Tier license. Visit the [PenTest.WS Store](https://store.pentest.ws) to purchase additional user licenses.

<figure><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FU0khaYW9jvvDOMMuzsqe%2Fimage.png?alt=media&amp;token=2bbd4726-776d-4ccc-ba15-903ac63b1bd8" alt=""><figcaption><p>User Maintenance</p></figcaption></figure>

## Creating Users

![New User](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FKouau0kQ00H7wCUVJvbB%2Fimage.png?alt=media\&token=212c3965-b152-42bc-91f5-a94e9938777d)

**Username**: must be unique in the Pro Tier installation and a minimum of three (3) characters

**Admin**: creating an Admin user allows them to access the [Admin Panel](/pro-tier/admin-panel), including User Maintenance. This does not give them access to other users' private Engagements.

**Email**: the user's email address

**Login Strategy**: select between Local or [LDAP Authentication](/authentication/ldap-authentication) login strategy

**Password / Confirm**: minimum of eight (8) characters

**Random Password**: generates a random eight (8) character temporary password. Be sure to select "Send Welcome Email: Yes - With Password". The user will be asked to change their password at first login.

**Send Welcome Email**: if you have setup [SMTP Integration](/automation-and-integration/smtp) the application can send a welcome email to new users, with or without their new password.

## Tier Availability

**User Maintenance** is available on **Pro Tier.**


# Shared Engagements

**Example URL:** <http://localhost:7897/e/{engagement.id}/console>

Pro Tier's Shared Engagements capability allows multiple users to collaborate on an Engagement with shared Hosts, Ports, Notes, Credentials, Findings, and everything else associated with an Engagement.

{% hint style="info" %}
Shared Engagements is available in Pro Tier running in [Intranet Mode](/pro-tier/on-premise) for multi-user accounts
{% endhint %}

![Left Side: user Alice – Right Side: user Bob](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2Fq9HlVxyFoFaWmmpQqHyB%2Fptws-shared-engagements.gif?alt=media\&token=d547a1b2-9d42-4786-806f-5fd39a7275dc)

All Shared Engagement details are synchronized in real-time between users. Shown in the example above, fields are temporarily locked while being edited and updated as that data is saved to the server. Pop-up notifications are displayed about important events, such as adding/delete hosts, ports, credentials or findings.

![Shared Engagement's Access Control](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FupfLK5aNkxjNyTnKJF2b%2Fimage.png?alt=media\&token=2cfc9977-329a-46e6-badb-feea2c6368a4)

## Tier Availability

**Shared Engagements** are available on **Pro Tier.**


# Access Control List

**Example URL:** <http://localhost:7897/e/{engagement.id}/console>

In a Pro Tier's Shared Engagement, the owner of an Engagement (the user who created the Engagement) can grant Read Only or Full Access to teammates on an individual basis.

![Shared Engagement's Access Control](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2F9JHlye8j7Gdywk1JdjP2%2Fimage.png?alt=media\&token=260790ec-e94c-4126-9caa-27ad22a27349)

Alternatively, you can choose to make an Engagement Public, granting full access to all teammates. Engagements default to Restricted Access with all teammates in the No Access bucket.&#x20;

An Engagement’s Access Control is available in the Console tab.

## Team Missions

Shared Engagements appear on the remote user’s [Dashboard](/getting-started/dashboard) under the Team Missions section.

![Team Missions](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2F9kXsqF3DwsUGqsXNZbGk%2Fimage.png?alt=media\&token=1013fb94-d266-45cc-a3df-0828fcf9e6c6)

* In the example above, we are logged into the "alice" account.&#x20;
* The user "demo" has given "alice" Full Access to the "Demo" engagement.
* The user "bob" has made his "ABC Widgets" engagement Public

{% hint style="info" %}
**Team Missions** only appear if you have access to another user's Shared Engagement.
{% endhint %}

## Tier Availability

**Access Control** is available on **Pro Tier.**


# File Shares

**Exclusively available on Pro Tier On-Premise**

**Example URL:** <http://localhost:7897/repo/files>

File Shares provide a secure, versioned workspace for managing files during engagements. Instead of relying on external services or ad-hoc file storage, File Shares keep everything organized directly inside PenTest.WS.

### Why Use File Shares

File Shares are designed with penetration testers in mind. They give you:

* **Secure storage** – All files are stored locally on your server, never uploaded to the cloud.
* **No AV/EDR scanning** – Files are stored exactly as you upload them, without interference.
* **Versioning** – Track changes to files over time, with the ability to replace or roll back versions.
* **Team access** – Files are automatically shared with your team inside PenTest.WS, no extra permissions or ACLs required.
* **Temporary publishing** – When you need to deliver a file to a live target during an engagement, you can generate a short-lived public link that expires automatically.

With File Shares, you can securely stage payloads, tools, scripts, or reporting artifacts, all while keeping them organized in one place.

## The File Shares Page

<figure><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FzLdaWl04qkhNCAJ37wpx%2Fimage.png?alt=media&amp;token=60165c47-7217-4699-9b3a-d596ccccd1e8" alt=""><figcaption></figcaption></figure>

The File Shares page is the starting point for managing all company-wide shares. Every share created is visible to the team, making it easy to collaborate and keep files organized in one central place.

For each File Share, the list view shows:

* **Share Name** – The name you assigned to the share.
* **Files** – A quick preview of the files included.
* **Tags** – Custom tags to help categorize and search for shares.
* **Last Modified** – The last time the share or its files were updated.
* **Created By** – The user who created the share.
* **Created** – The date the share was originally created.

From this page you can:

* Create a new File Share using the **New File Share** button.
* Search across existing shares.

## File Share Details

<figure><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FHAxslIPso61viqbUcLdb%2Fimage.png?alt=media&amp;token=6f9c65f8-e3d5-4507-a0af-b27e180d5cc6" alt=""><figcaption></figcaption></figure>

Each File Share has its own details page where you can manage the files, metadata, and publishing options for that share. This page is where you’ll spend most of your time working with File Shares.

### Share Information

At the top of the page, you’ll see the share’s metadata:

* **Share Name** – The display name of the share (editable).
* **Tags** – Custom tags to help categorize and search (editable).
* **Notes** – A rich text field for describing the purpose or usage of the share.
* **Created By** – The user who originally created the share.
* **Created** – The date the share was created.

Notes are a good place to document the intended use of the share, for example:

> *This share contains staging payloads and helper scripts for use during external engagements. Links are short-lived and intended only for deployment.*

### Files Table

The files table lists every file in the share along with important details:

* **File Name** – The name of the file.
* **Size** – File size.
* **Version** – Version number for the file. Each replacement increases the version.
* **Type** – The file’s MIME type.
* **Uploaded By** – The user who uploaded the file.
* **Uploaded** – The date the file was uploaded.
* **Actions** – Options to download, publish, rename, replace, or delete the file.

### File Actions

Each file includes the following actions:

* **Download** – Retrieve the file directly.
* **Publish** – Generate a short-lived public link for deployment during an active engagement. Links expire automatically.
* **Rename** – Change the file name displayed in the share.
* **Replace** – Upload a new version of the file while maintaining version history.
* **Delete** – Permanently remove the file from the share.

### Uploading Files

New files can be added to the share using the **Upload File** option at the bottom of the page. Uploaded files are instantly available to your team and become part of the versioned history.


# API

{% hint style="info" %}
**Swagger Documentation**

#### <https://pentest.ws/docs/api/v1/>

Please refer to the Swagger Documentation for a detailed listing of API end-points, example requests and testing platform.
{% endhint %}

The PenTest.WS API provides access to your Engagements, Hosts, Ports, Scratchpad, Note Pages, Credentials, Clients & Findings through a RESTful architecture, including GET, PUT, POST, & DELETE capabilities for each object. You can now build automation scripts and integrate external tools into your PenTest.WS environment.

## API Authorization

All PenTest.WS API calls require authorization.

You can find your API-Key under **Account Settings -> API-Key**:

<https://pentest.ws/settings/api-key>

{% hint style="warning" %}
**Security Info:**

This API Key grants direct access to objects in your PenTest.WS account. This includes Engagements, Hosts, Ports, Notes, Findings and others.&#x20;

**Do not share your API key!**
{% endhint %}

### Curl Example

Get the API end-point `/api/v1/e` with the HTTP Header value `X-API-KEY`

```
curl -X GET "https://pentest.ws/api/v1/e" -H "X-API-KEY: {api-key}"
```

## Nmap Scan Automation

Consider the following Nmap Scan Template:

> `nmap -sC -sV -oA tcp -vv %tip% && curl -X POST "https://pentest.ws/api/v1/e/%eid%/import/nmap" -H "X-API-KEY: %apikey%" -F "file=@tcp.xml"`

The first half of this command runs a typical nmap scan on a target IP address, IP range or CIDR block, then outputs the results to a file called “tcp.xml”. The second half of this command uses curl to immediately post these results to your engagement in PenTest.WS.

Embedded in this command are several interesting variables:

<table><thead><tr><th width="150"></th><th width="534"></th></tr></thead><tbody><tr><td>%tip%</td><td>Target IP Address, Range or CIDR Block</td></tr><tr><td>%eid%</td><td>Current Engagement ID</td></tr><tr><td>%apikey%</td><td>Your API Key – when you click on a command with this variable, the application will prompt for your password before swapping the variable for your API Key. You can view your API key at <a href="https://pentest.ws/settings/api-key">https://pentest.ws/settings/api-key</a></td></tr></tbody></table>

The full list of template variables are available in the [template](/getting-started/port-scan-templates) screens:

![Template Variables](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2F2GxZtALIhJ5n0pmP60Z9%2Fimage.png?alt=media\&token=873d28d3-8b79-4422-b9e4-f3ac4616ef52)

## Security Best Practices

* **Do not embed API keys directly in code:** API keys that are embedded in code can be accidentally exposed to the public, for example, if you forget to remove the keys from code that you share. Instead of embedding your API keys in your applications, store them in environment variables or in files outside of your application's source tree.
* **Delete unneeded API keys:** To minimize your exposure to attack, delete any API keys that you no longer need.
* **Regenerate your API keys periodically:** You can regenerate your PTWS API key by clicking the Generate New API Key button above. Then, update your applications to use the newly-generated key.
* **Do not store API keys in files inside your application's source tree:** If you store API keys in files, keep the files outside your application's source tree to help ensure your keys do not end up in your source code control system. This is particularly important if you use a public source code management system such as GitHub.

## Tier Availability

**API** is available on all tiers.


# SMTP

**Example URL:** <http://localhost:7897/admin>

SMTP integration allows PenTest.WS Pro Tier to send email notifications such as the Welcome Email when a new user is created ([User Maintenance](/collaboration/user-maintenance)).

![SMTP Integration](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FM9HEdCDniyQcc7rnB3vA%2Fimage.png?alt=media\&token=a28944b3-c222-486c-8fba-2cc21de4bc8f)

### Enable SMTP

1. Enter the SMTP information for you local or remote SMTP server
2. Click the ![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FSBmO1zYXiz47K8dETQir%2Fimage.png?alt=media\&token=35a0df61-c165-4e8a-b855-cd3b08f58410) button to save you settings.&#x20;
3. Click the ![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FuSW4KSvYhxxoKLxyb3Bp%2Fimage.png?alt=media\&token=c0efd505-dd6b-407a-b97d-053d1cbc573e) to verify your settings
4. Send a test email with ![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FaMQ1I0sQ2DPpQirWbVBp%2Fimage.png?alt=media\&token=7bdcd7f7-df8e-4dad-aef4-a75e8c42a0a7)

![Send Test Email](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2Fvw5E4NEBhDSSf5JZUdh5%2Fimage.png?alt=media\&token=f0d924b2-4c06-43eb-8ee6-d998fb3f36c7)

## Tier Availability

**SMTP Integration** is available on **Pro Tier**.


# Two-Factor Authentication

PenTest.WS supports Two-Factor Authentication and can to be enabled per-account. You'll need a third-party authenticator app such as Google Authenticator:

**Android**: <https://play.google.com/store/apps/details?id=com.google.android.apps.authenticator2>

**iOS**: <https://apps.apple.com/us/app/google-authenticator/id388497605>

## Enable Two-Factor Authentication

**URL:** <https://pentest.ws/settings>

Visit your Account Settings page to get started:

![Account Settings - 2FA](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2F4JW54aNSBVB4kfmF7TjV%2Fimage.png?alt=media\&token=4af7ab8c-f266-406e-b434-f302c895f1e9)

1. Click ![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2Fn3kPmzW3J613PDGCu7yd%2Fimage.png?alt=media\&token=c0823461-f3cb-4724-ae93-9e1a01d362aa) in the Two-Factor Authentication section
2. Open your authenticator app
3. Scan the provided QR Code
4. Enter the One-Time Password to confirm everything is setup correctly
5. Click ![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FrQEfnm0kAp6ve7qkml3U%2Fimage.png?alt=media\&token=1c8dcafe-64d6-476b-8e2b-a7d4e19ab23b)

## 2FA Backup Codes

Once you have enabled Two-Factor Authentication for you account you'll be provided 2FA Backup Codes. Be sure to write these down, download them or print them out, and don't lose them. They are required if you lose control of your authenticator app.

![Settings - 2FA - Codes Show](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2Fd53gQsImEVJSgIoFdjM2%2Fimage.png?alt=media\&token=255bbeb4-93e3-4ca1-8268-442ca7d06fd6)

## 2FA Login

When logging into an account with 2FA enabled, you'll be presented with a Two-Factor Authentication prompt. Open your authenticator app and enter the one-time password.

![2FA Login](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FbSQccAuf7rgZ7H04dZ1W%2Fimage.png?alt=media\&token=8774fe68-7c3e-4068-8670-4c7d7b8ecd34)

## 2FA Backup Code Login

If you need to use a backup code to login, click the "Use A Backup Code" link and enter one of your ten backup codes. Once you have used a code and logged in, it will no longer be available to use again.

![Login with Backup Code](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FdDWael8B0TQjUK88AgDl%2Fimage.png?alt=media\&token=3e120b1a-8db3-49fa-b4e4-47716edfb15b)

## Tier Availability

**Two-Factor Authentication** is available on all tiers.


# LDAP Authentication

Authentication in Pro Tier can use the Local Strategy where username and passwords are stored in the PenTest.WS database, or authentication can check an LDAP server for password authentication.

Users who are authenticating against LDAP need to have an entry in both the PenTest.WS Pro Tier server's [User Maintenance](/collaboration/user-maintenance) system and the LDAP server. You'll also need to add the user's LDAP distinguished name (DN) to their user profile.

## Admin Panel LDAP URL

**Example URL:** <http://localhost:7897/admin>

![LDAP URL](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2F3c1cIL58ZCks0bqoxckk%2Fimage.png?alt=media\&token=8763e59b-28a8-4553-aef0-78f9094b3537)

The first step to setup LDAP integration is to enter the LDAP URL in the **Intranet Mode Config** section of the **Admin Panel.**

## LDAP User Setup

**Example URL**: <http://localhost:7897/admin/user/{user.id}/edit>

![User LDAP Setup](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2F79uBNPBdbvRSnah2powo%2Fimage.png?alt=media\&token=1c8f155e-1cc9-44b2-9ea7-2e0c8aa714a7)

1. Edit the user profile of the user you want to enable LDAP authentication
2. Change the **Login Strategy** to **LDAP**
3. Enter the user's distinguished name (DN)
4. Click ![](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FECrU90cP8gTDbSHW3MKi%2Fimage.png?alt=media\&token=4eae5cff-921d-4f42-9491-5c5d62d64464)

When the user attempts to login the Pro Tier server application will check their username in the local database to lookup their LDAP DN and then check the password against the LDAP server.

If the user has Two-Factor Authentication enabled they will then be prompted for their one-time password as well.&#x20;

{% hint style="info" %}
2FA is always handled locally through PenTest.WS
{% endhint %}

## Tier Availability

**LDAP Authentication** is available on Pro Tier.


# Export Account Items

**URL:** <https://pentest.ws/export>

The Export Account Items function will generate a JSON file containing the selected items from your account. This file can be used with the Import Account Items feature.

![Export Account Items](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FLcXqkErCHucnUUMjENFf%2Fimage.png?alt=media\&token=e71157a4-1ad8-4088-88f5-ae1d53add108)

## Tier Availability

**Export Account Items** is available on all tiers.


# Import Account Items

**URL:** <https://pentest.ws/import>

Import Account Items reads a JSON file and will merge your existing account items with the items found in the JSON file.

![Import Account Items](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FeiFIBppREEwHarcHFa4p%2Fimage.png?alt=media\&token=ca6348e7-27a9-41a5-8731-411011e956aa)

Once you have loaded your JSON file you will be given the chance to review the pending import.

### Confirm Import

![Confirm Account Items Import](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2F17jUi3MM59IND268Avx4%2Fimage.png?alt=media\&token=2d66a1f0-907e-4dae-a1ed-9e08dcaab3db)

The confirm screen lists the items from your JSON file and attempts to find matching records in your current Account Items. Each record will have one or more of the following options depending on the matches found:

* **Replace**: replace the existing Account Item with the import value from the JSON file
* **Skip**: do not change the existing Account Item
* **Append**: concatenate the Import Value to the Current Value. This option typically requires manually fixing the Account Item's value after the import.&#x20;

## Tier Availability

**Import Account Items** is available on all tiers.


# Export to CSV / JSON

**Example URL**: <https://pentest.ws/e/{engagement.id}/console>

Exporting objects in PenTest.WS is available from the Object Menu in the upper right corner of the content panel on their respective pages.

![Export CS / JSON](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FPaT43Zx45JTHsZ5c6qAZ%2Fimage.png?alt=media\&token=341b1767-ac66-4fd2-b75a-f12de5228e5a)

The following objects can be exported to CSV or JSON format:

<table><thead><tr><th width="179.33333333333331"></th><th width="400.18815855494233"></th><th data-hidden></th></tr></thead><tbody><tr><td>Engagement</td><td>/e/{engagement.id}/console</td><td></td></tr><tr><td>Host</td><td>/e/{engagement.id}/host/{host.id}</td><td></td></tr><tr><td>Port</td><td>/e/{engagement.id}/host/{host.id}/port/{port.id}</td><td></td></tr></tbody></table>

## Tier Availability

**Export To CSV / JSON** is available on all tiers.


# Admin Panel

**Example URL:** <http://localhost:7897/admin>

Pro Tier's Admin Panel provides maintenance functionality such as checking for software updates, renewing your license, refreshing local repository caches, and intranet configuration.

<figure><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FjoS33QikYVPjTADvs4hf%2Fimage.png?alt=media&amp;token=f6d5549b-8ca3-45ce-ab00-4aa5ae33fd89" alt="Pro Tier&#x27;s Admin Panel"><figcaption><p>Pro Tier's Admin Panel</p></figcaption></figure>

## License Information

**Version**: the current version of your Pro Tier installation

**Serial Number**: generated at time of purchase, this serial number may be requested by support during a support ticket request

**Registered** To: the username, contact name and company name of the license holder

**Issued**: date the current license was issued

**Expires**: date the current license expires

**User Licenses**: number of users the license is valid for

**Platform**: which operating system and hardware is the system running on

## Software Updates

Pro Tier does not automatically check for software updates. Additionally, Pro Tier does not contact the internet unless a user initiates a procedure that requires it, such as checking for software updates. When this happens the initiating user is prompted to confirm the action.

If a new version is available the software will confirm the upgrade and proceed to download and install the latest version. Database migrations take place when the application reboots.

## Local Repo Caches

PenTest.WS maintains several local caches of repositories such as CSV DB, Exploit-DB, Nmap Scripts and Metasploit Modules. The Admin Panel offers buttons to update each of these local caches.

## Intranet Mode Configuration

The [Intranet Mode](/pro-tier/on-premise) Config section is where you setup [LDAP](/authentication/ldap-authentication) and [SMTP](/automation-and-integration/smtp) integration.

## Tier Availability

**Admin Panel** is available on **Pro Tier**.


# On-Premise

PenTest.WS Pro can be installed **On-Premise**, giving your organization full control over the platform inside your own environment. On-Premise deployments are ideal for teams who need to keep data entirely within their own infrastructure for compliance, security, or operational reasons.

With On-Premise, your penetration testing team can:

* Track hosts, services, findings, and notes across engagements.
* Share data in real-time without relying on cloud services.
* Securely collaborate through your internal network or VPN tunnels.
* Meet strict data residency and regulatory requirements.

### Benefits of On-Premise

* **Data Control** – All engagement data stays inside your infrastructure.
* **Security** – No external dependencies or third-party storage.
* **Compliance** – Meets organizational or regulatory requirements that prohibit cloud storage.
* **Team Collaboration** – Multiple testers can connect to the same on-premise server, working together on shared engagements.

<figure><img src="https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FivFY9Ml2l8hqDS8OSFbg%2Fptws-on-premise.png?alt=media&amp;token=a3499d98-93a0-4ca9-8c22-7827ff318610" alt=""><figcaption></figcaption></figure>

## System Requirements

* Linux or macOS
* Intel, AMD, or Apple Silicon
* PostgreSQL Installed
* Minimum 2gb of memory
* Installation requires \~470mb minimum disk space, not including database usage

## Tier Availability

**On-Premise** is available on **Pro Tier**.


# Offline Mode

For individual penetration testers or field operators, PenTest.WS Pro can run entirely in **Offline Mode**. This mode is designed for situations where an internet connection is unavailable or prohibited, such as air-gapped labs, secure environments, or field work.

Once installed, Offline Mode operates as a completely stand-alone application. No server is required, and all data is stored locally on your system.

![Solo Mode](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FuJtDKIJfjHulJolo9AyW%2Fimage.png?alt=media\&token=a05266e4-3351-4125-934e-b50485c44c16)

### Key Features

* **100% Stand-Alone** – Runs directly on your workstation.
* **No Server Required** – All functionality is self-contained.
* **No Internet Needed** – Continue working in disconnected or high-security environments.
* **Secure by Design** – Data stays on your device, never leaving your environment.

### System Requirements

* Linux or macOS
* Intel, AMD, or Apple Silicon
* PostgreSQL installed
* Minimum 2 GB of memory
* \~470 MB disk space for installation (not including database usage)

Offline Mode is designed for consultants, red teamers, and field testers who need the full functionality of PenTest.WS Pro without relying on external connectivity.

## Tier Availability

**Offline Mode** is available on **Pro Tier**.


# Large Engagement Support

With Pro Tier’s Large Engagement support, a single Engagement can handle thousands, or tens of thousands of Hosts. Need to import an Nmap scan of a /20 network? An entire Class B network? No problem.

![Large Engagements Demo](https://1013683115-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHecEAvxd6Z8cSug6DhWr%2Fuploads%2FWmcn0kcOTP691y4QBtCl%2FLargeEngagements.gif?alt=media\&token=57dbe9c1-3259-4353-8188-7a4e9f410ca6)

Several systems in Pro Tier have been upgraded to work with large network ranges:

* **Import XML** – the import routine shows it’s progress log in real time, giving you live feedback of the Hosts & Ports the system is either creating or updating as it works its way through your XML file.
* **Infinite Scrolling** – the application implements infinite scrolling, only loading enough Hosts to fill the page. As you scroll through various lists, more Hosts are loaded in the background until all Hosts are displayed. The affected systems are:
  * Application’s Main Sidebar
  * Boards
  * Matrix
  * Subnets
* **Updated Matrix** – filtering by operating system, flags, ports or keywords effects all Host list queries for a faster and more intuitive user experience. Looking for systems with port 80 or 443 running Linux? Set your Matrix and the Sidebar, Boards & Subnets screens will also be filtered.
* **Boards** – combined with the Matrix, you can create boards such as “Web Servers” and easily move all of your port 80/443 Hosts. Want to break up 4,094 Hosts into ten Boards? Use the “Auto Distribute” feature, now compatible with Infinite Scrolling.
* **Subnets** – using the web servers example we’ve been discussing, jump over to the Subnets screen and copy the “IPs – One Per Line” field into a file for EyeWitness and speed up your recon.

## Tier Availability

The **Large Engagements** capability is available on **Pro Tier**.


# Accessibility Conformance

To make it easier for companies, educational institutions, and government agencies to be compliant with accessibility standards, PenTest.WS provides transparent reports about how our products currently work for people with disabilities. We publish Accessibility Conformance Reports (ACR), based on the ITI Voluntary Product Accessibility Template (VPAT®), to document conformance with WCAG 2.x and Section 508 requirements.

The following reports are available:

{% file src="/files/1OfsRDBpoltoOrdpuoUI" %}
Last Updated: September 2025
{% endfile %}


