GRC SaaS platform -- 2
Budget: €1,500 – €3,000 EUR
Create is a pentest lifecycle management platform that uses a combination of data, talent and technology to provide customers with specialized pentesting as-a-service and as an on-premise platform. Customers can initiate assessments, track and eventually remediate vulnerabilities at a centralized location while leveraging a global talent pool of proven pentesters.
Platform will be build following a modular approach (GRC module, Pentest Lifecycle Management Module, Report generation module, LMS, etc.)
Software Requirement
a) The platform should be built as a simple and robust architecture, and should be easy enough to add further sub-platforms in the future
b) Platform should be built on Linux based OS/Containers
c) Wherever possible, open-source technology should be used
d) Platform should have ability to be deployed in different software defined segregation per customer
e) MVC based modular architecture (ASP.NET / Java)
Sample tools/platforms for vulnerability management
1. https://github.com/pwndoc/pwndoc
2. https://github.com/infobyte/faraday
3. URL: https://demo-e.eramba.org/dashboard
a. Username: admin
b. Password: alphanumeric1
4. https://plextrac.com/platform/reports/
5. https://github.com/KvasirSecurity/Kvasir/wiki (https://ptestmethod.readthedocs.io/en/latest/LFF-IPS-P5-Reporting.html)
6. https://www.simplerisk.com/download
Platform will be build following a modular approach (GRC module, Pentest Lifecycle Management Module, Report generation module, LMS, etc.)
Software Requirement
a) The platform should be built as a simple and robust architecture, and should be easy enough to add further sub-platforms in the future
b) Platform should be built on Linux based OS/Containers
c) Wherever possible, open-source technology should be used
d) Platform should have ability to be deployed in different software defined segregation per customer
e) MVC based modular architecture (ASP.NET / Java)
Sample tools/platforms for vulnerability management
1. https://github.com/pwndoc/pwndoc
2. https://github.com/infobyte/faraday
3. URL: https://demo-e.eramba.org/dashboard
a. Username: admin
b. Password: alphanumeric1
4. https://plextrac.com/platform/reports/
5. https://github.com/KvasirSecurity/Kvasir/wiki (https://ptestmethod.readthedocs.io/en/latest/LFF-IPS-P5-Reporting.html)
6. https://www.simplerisk.com/download