Comments (4)
We're tracking this and will see what we can implement 😄
from ghostwriter.
@BrunoTeixeira1996 @chrismaddalena
I believe what Bruno is asking is what we do at my work. I wrote a custom web page that allows me to filter report findings based on tester, date, keywords (e.g. JWT, XML, GraphQL, etc...), and then click the finding title to go to the report.
You'll probably have to re-adjust our code as we use the affected entities field as the finding evidence field to write up all our finding details and we use some other fields as shown in the screenshot to categorize findings into buckets (e.g. Authentication, Encryption, etc...).
https://github.com/StratumSecurity/Ghostwriter/blob/5219255bd7397440b16ff3c0435a5dedc271e6a2/config/urls.py - has the entry for the URL mapping: report/findings/
https://github.com/StratumSecurity/Ghostwriter/blob/5219255bd7397440b16ff3c0435a5dedc271e6a2/ghostwriter/stratum/filters.py - code to handle different types of filtering
https://github.com/StratumSecurity/Ghostwriter/blob/5219255bd7397440b16ff3c0435a5dedc271e6a2/ghostwriter/stratum/templates/report_findings_list.html - webpage HTML code
https://github.com/StratumSecurity/Ghostwriter/blob/5219255bd7397440b16ff3c0435a5dedc271e6a2/ghostwriter/stratum/urls.py - URL mapping
https://github.com/StratumSecurity/Ghostwriter/blob/5219255bd7397440b16ff3c0435a5dedc271e6a2/ghostwriter/stratum/views.py - API code for the page
https://github.com/StratumSecurity/Ghostwriter/blob/5219255bd7397440b16ff3c0435a5dedc271e6a2/ghostwriter/templates/base_generic.html - has the Search Report Findings menu item entry there
from ghostwriter.
@ArgentEnergy that is exactly what I was looking for however I can't use your fork at work but I think this would be a realy cool feature.
I was thinking on doing something similar just by using a cli something like a grep but I had to have admin rigths for that
from ghostwriter.
This issue has been labeled as stale
because it has been open for 30 days with no activity.
from ghostwriter.
Related Issues (20)
- Format Evidence Files HOT 2
- 'NoneType' error for Fetching NameCheap Domains HOT 2
- Failed new installation HOT 2
- Add Description to Extra Fields HOT 7
- Keep Findings as Default Tab for Report HOT 2
- Namecheap Update Does Not Fail on IP Whitelisting Error HOT 2
- 2FA Does not seem to work HOT 2
- Failed to RE-install the GhostWriter on Ubuntu HOT 1
- EVIDENCE PICTURES ATTACHED NOT SHOWING UP IN THE REPORT
- Jira Api Support HOT 2
- List Machine Status in Cloud Review Notifications HOT 2
- (Feature Request) Collaboration Features (comments on findings; tracked changes) HOT 8
- Severity levels not defined amongst variables for export HOT 2
- Issue with v4.1 and extra fields HOT 4
- Oplog start_time and end_time format missing timezone offset. HOT 1
- Report template types are broken HOT 5
- Generate DOCX report broken for existing findings with empty affected entities HOT 4
- Finding with SSTI payload in replication steps (as inline code), prevents report generation HOT 2
- No route found... Username incudes `-` HOT 1
- Cross-references broken when ref includes special characters (e.g., hyphens or underscores) HOT 6
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from ghostwriter.