Until now, the only tools that read OPF were ones we wrote. DefectDojo 3.3.0 changes that with a native OPF parser: no converter, no generic-import hop, just upload the .opf.json.
Read →Notes from building Cairn
Occasional writing on the craft of pentest delivery: the formats, the workflows, and the decisions behind the platform. Written by the people who build it, for the people who run engagements.
The testing is the work; the report is the deliverable. What separates a report that stands up in front of a risk committee from one that gets sent back with questions.
Read →CVSS 4.0 is the better model; 3.1 is the version your client’s tooling expects. A practical read on what changed and how to decide which one (or both) belongs on a finding.
Read →Most findings die in a PDF. SARIF is the language GitHub, Azure DevOps and CI already speak, so findings arrive as alerts in the developer’s own queue instead of an attachment.
Read →The finding is half the deliverable. The sentence telling a developer what to change is the half that decides whether the bug is still there at the retest.
Read →A small, open toolkit that converts the Open Pentest Format to SARIF, DefectDojo, GitLab and back.
Read →Your write-ups outlast any one tool. The format they live in should too. So we published one.
Read →What we write about
Most writing about penetration testing covers how to find the bug. Almost none of it covers what happens afterwards: the scoping call that set the boundaries, the Statement of Work that priced it, the finding library that had to be rewritten because it lived in a format nothing else could read, and the client who wanted the report as something other than an emailed PDF. That gap is what these notes are about.
Recurring themes: portable data, because a finding library outlasts any tool that stores it, which is why we published the Open Pentest Format as an open specification anyone can implement rather than a Cairn feature. The whole engagement, because the pre-sales half decides margin and nobody tools it. And keeping data where it belongs, because an offensive team’s findings are among the most sensitive documents in its clients’ estate, which is what drives the on-prem and air-gapped work described under capabilities and security.
If you want to see what the platform actually does rather than read about the thinking behind it, the screenshots are real captures from a live tenant, and pricing is published in full.