Notify everyone who should be aware of the pentest. Ensure that the pentest doesn’t disrupt anyone’s workflows.
Prepare credentials and account details for pentesters.
Be responsive to pentest results.
Pentesters will share vulnerabilities (findings) that they discover in real time. Start remediating them. Collaborate on the pentest and ask questions if you need help.
Be available to help find solutions to problems.
Most of the time pentesters are cautious and don’t perform any actions that have detrimental effects on your software. However, as a precautionary measure, you should prepare for the worst. Prepare a backup copy of your software (especially when testing a production environment), and have a team ready to respond to any unexpected events.
Establish communication with pentesters in Slack, and let them know you are there—available and responsive.
Communicate significant changes to your environment made during a test to pentesters.
If you make significant changes to your environment during a test (including remediating vulnerabilities), make sure to communicate this to our pentesters. Any major updates to your asset that you make when the pentest is Live may impact pentesters’ workflows and the testing process.
To help our penetration testers, include more information about your asset,
such as architecture and coding language. You’ll see more details about
what to include when you define your assets.
Define details of your environment.
Is your asset in production or in development? Is part of your system
on a Cloud platform?
Plan and scope the test. Define your desired pentest start
date, and specify the pentest scope. We need time to find the best available pentesters for your assets.
Once you’ve set up a pentest, we start analyzing your asset. When
possible, we share results even before we create your report. Here’s what
you can expect.
Frequently Asked Questions
Click to view answers.
What is an organization?
When you receive an email invitation from Cobalt, you join a specific organization with a role assigned to you. Within an organization, you and your team get access to the Cobalt platform and the pentest experience. Learn more about organizations.
How do I add people to my organization?
Organization Owners can manage users for their organization. For instructions, see Invite Users.
For pentests, an asset is a software component of value, such as a web application or API. Learn more about the asset types we support. Once you've created an asset, you can launch pentests for it.
Get in Touch
If you need help, don’t hesitate to contact us.
If you have a named Customer Success Manager, get in touch with them.