Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
OWASP PTK 9.6.0 - A Reporting and Correlation
2 points by DenisPodgurskii 37 days ago | hide | past | favorite
This version is all about turning scan output into something you can actually share, triage, and act on.

’ .. • PDF and Markdown export • Two report presets: Executive and Technical • Summary section (high-level overview + key totals) • Severity filters to triage findings faster • Confidence scoring + correlated findings across DAST / IAST / SAST / SCA to surface higher-signal issues

’ • Safe-by-default redaction in exports (tokens, Authorization headers, cookies, storage values) • Cleaner evidence: truncation + consistent formatting (monospace blocks where it helps) • Executive reports now group/deduplicate noisy repeats (especially SCA/SAST-style output) to stay concise and decision-focused

Executive reports are now genuinely shareable: prioritised risks + correlated findings, with sensitive data removed by default. Technical reports go deeper (per-engine detail + evidence) while still staying safe-by-default.

If you’re using PTK for real-world testing, this release should make reporting and handoff to dev/AppSec teams much smoother.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: