- name
- pentestops-dashboard
- description
- Comprehensive penetration testing operations dashboard for managing projects, tasks, findings, clients, and assets with Next.js and MongoDB
- triggers
- ["set up pentestops dashboard","create pentest project management system","configure pentestops with docker","add security findings to pentestops","manage penetration testing tasks","deploy pentestops dashboard","integrate cwe database with pentestops","create pentest checklist pages"]
# PentestOPS Dashboard Skill
> Skill by [ara.so](https://ara.so) — Security Skills collection.
## Overview
PentestOPS Dashboard is a comprehensive penetration testing operations platform built with Next.js, Express, and MongoDB. It provides project management, task tracking (Kanban/table views), finding management with CWE integration, client management, asset tracking, rich text pages with Editor.js, checklists, comments, file attachments, version history, and global search.
**Key Features:**
- Full-stack TypeScript application with JWT authentication
- Rich text editor with Notion-like features
- Single Docker container deployment (includes MongoDB, backend, frontend)
- CWE database integration for security findings
- File upload support (PDF, DOCX, XLSX, ZIP, images)
- Threaded comments and version control
## Installation
### Local Development Setup
```bash
# Clone repository
git clone https://github.com/0xBugatti/PentestOPS.git
cd PentestOPS
# Install dependencies
npm install
cd frontend && npm install && cd ..
cd backend && npm install && cd ..
# Create .env file in root
cat > .env << 'EOF'
NODE_ENV=development
BACKEND_PORT=4000
MONGODB_URI=mongodb://localhost:27017/pentest-dashboard
JWT_SECRET=$(openssl rand -base64 32)
JWT_REFRESH_SECRET=$(openssl rand -base64 32)
CORS_ORIGIN=http://localhost:3000
ALLOW_REGISTRATION=true
MAX_FILE_SIZE=10485760
UPLOAD_DIR=./backend/uploads
NEXT_PUBLIC_API_URL=http://localhost:4000
EOF
# Start MongoDB
docker run -d --name mongodb -p 27017:27017 mongo:latest
# Start development servers
npm run dev
```
Access at:
- Frontend: `http://localhost:3000`
- Backend API: `http://localhost:4000`
### Docker Deployment (Production)
```bash
# Build image
docker build -t pentestops-dashboard:latest .
# Run with environment file
docker run -d \
--name pentestops \
--restart unless-stopped \
-p 3000:3000 \
-p 4000:4000 \
-v pentestops-data:/data/db \
-v pentestops-uploads:/app/uploads \
-e JWT_SECRET=${JWT_SECRET} \
-e JWT_REFRESH_SECRET=${JWT_REFRESH_SECRET} \
-e NODE_ENV=production \
-e CORS_ORIGIN=https://yourdomain.com \
-e ALLOW_REGISTRATION=false \
pentestops-dashboard:latest
```
## Core API Endpoints
### Authentication
```typescript
// Register new user
POST /api/auth/register
{
"username": "pentester",
"email": "pentester@example.com",
"password": "SecurePass123!",
"firstName": "John",
"lastName": "Doe"
}
// Login
POST /api/auth/login
{
"username": "pentester",
"password": "SecurePass123!"
}
// Returns: { accessToken, refreshToken, user }
// Refresh token
POST /api/auth/refresh
{
"refreshToken": "your-refresh-token"
}
// Get profile
GET /api/auth/profile
Headers: Authorization: Bearer {accessToken}
```
### Projects
```typescript
// Create project
POST /api/projects
{
"name": "Web Application Security Assessment",
"description": "Comprehensive security audit of client web application",
"status": "in-progress",
"startDate": "2024-01-15T00:00:00Z",
"endDate": "2024-02-15T00:00:00Z",
"client": "client-id",
"tags": ["webapp", "owasp", "critical"]
}
// List projects with filters
GET /api/projects?status=in-progress&search=webapp&sort=createdAt
// Get project details
GET /api/projects/{projectId}
// Update project
PUT /api/projects/{projectId}
{
"status": "completed",
"progress": 100
}
// Delete project
DELETE /api/projects/{projectId}
```
### Tasks
```typescript
// Create task
POST /api/tasks
{
"title": "SQL Injection Testing",
"description": "Test all input fields for SQL injection vulnerabilities",
"status": "todo",
"priority": "high",
"project": "project-id",
"assignee": "user-id",
"dueDate": "2024-01-20T00:00:00Z",
"tags": ["sqli", "webapp", "owasp-a03"],
"checklist": ["Check login form", "Test search parameters", "Verify API endpoints"]
}
// List tasks with filters
GET /api/tasks?project={projectId}&status=in-progress&priority=high
// Update task status
PUT /api/tasks/{taskId}
{
"status": "in-progress",
"progress": 50
}
// Add subtask
POST /api/tasks/{taskId}/subtasks
{
"title": "Test login form SQL injection",
"completed": false
}
// Add comment to task
POST /api/tasks/{taskId}/comments
{
"content": "Found SQL injection in username parameter",
"parentComment": "parent-comment-id" // Optional for threading
}
```
### Findings
```typescript
// Create finding
POST /api/findings
{
"title": "SQL Injection in Login Form",
"description": "The login form is vulnerable to SQL injection attacks",
"severity": "critical",
"status": "open",
"cweId": "CWE-89",
"cvssScore": 9.8,
"cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"project": "project-id",
"affectedAssets": ["asset-id"],
"steps": [
"Navigate to login page",
"Enter ' OR '1'='1 in username field",
"Observe authentication bypass"
],
"impact": "Attackers can bypass authentication and gain unauthorized access",
"recommendation": "Use parameterized queries or prepared statements",
"references": ["https://owasp.org/www-community/attacks/SQL_Injection"],
"tags": ["sqli", "authentication", "critical"]
}
// List findings
GET /api/findings?project={projectId}&severity=critical&status=open
// Update finding
PUT /api/findings/{findingId}
{
"status": "fixed",
"remediation": "Implemented parameterized queries",
"retestDate": "2024-01-25T00:00:00Z"
}
```
### CWE Database
```typescript
// Import CWE database from CSV
POST /api/cwes/import
Content-Type: multipart/form-data
file: cwes.csv
// Search CWEs
GET /api/cwes?search=injection&type=vulnerability
// Get CWE details
GET /api/cwes/89
// Returns CWE-89 (SQL Injection) details
```
### Clients
```typescript
// Create client
POST /api/clients
{
"name": "Acme Corporation",
"email": "security@acme.com",
"phone": "+1-555-0123",
"website": "https://acme.com",
"industry": "Technology",
"contacts": [
{
"name": "Jane Smith",
"role": "CISO",
"email": "jane.smith@acme.com",
"phone": "+1-555-0124"
}
],
"notes": "Primary contact for all security assessments"
}
// List clients
GET /api/clients?search=acme
// Update client
PUT /api/clients/{clientId}
```
### Pages (Checklists/Documentation)
```typescript
// Create page with Editor.js content
POST /api/pages
{
"title": "OWASP Top 10 Testing Checklist",
"slug": "owasp-top-10-checklist",
"content": {
"time": 1640995200000,
"blocks": [
{
"type": "header",
"data": {
"text": "OWASP Top 10 Testing Checklist",
"level": 1
}
},
{
"type": "paragraph",
"data": {
"text": "Comprehensive checklist for testing OWASP Top 10 vulnerabilities"
}
},
{
"type": "checklist",
"data": {
"items": [
{
"text": "A01:2021 - Broken Access Control",
"checked": false
},
{
"text": "A02:2021 - Cryptographic Failures",
"checked": false
},
{
"text": "A03:2021 - Injection",
"checked": true
}
]
}
},
{
"type": "code",
"data": {
"code": "' OR '1'='1' --",
"language": "sql"
}
}
],
"version": "2.28.0"
},
"isPublic": false,
"tags": ["owasp", "checklist", "webapp"]
}
// Get page by slug
GET /api/pages/owasp-top-10-checklist
// Update page
PUT /api/pages/owasp-top-10-checklist
{
"content": { /* updated Editor.js blocks */ }
}
// Link page to task
PUT /api/tasks/{taskId}
{
"linkedPages": ["owasp-top-10-checklist"]
}
```
### File Attachments
```typescript
// Upload file
POST /api/attachments
Content-Type: multipart/form-data
file: screenshot.png
entityType: finding
entityId: finding-id
// Download file
GET /api/attachments/{attachmentId}/download
// View image
GET /api/attachments/{attachmentId}/view
// List attachments for entity
GET /api/attachments?entityType=finding&entityId={findingId}
```
### Assets
```typescript
// Create asset
POST /api/assets
{
"name": "Web Server - Production",
"type": "server",
"ipAddress": "192.168.1.100",
"hostname": "web-prod-01.acme.com",
"os": "Ubuntu 22.04 LTS",
"ports": [
{
"port": 443,
"protocol": "tcp",
"service": "https",
"version": "nginx/1.18.0"
}
],
"vulnerabilities": ["CVE-2023-1234"],
"project": "project-id",
"notes": "Primary web server for production environment"
}
// List assets
GET /api/assets?project={projectId}&type=server
// Link asset to finding
PUT /api/findings/{findingId}
{
"affectedAssets": ["asset-id"]
}
```
### Global Search
```typescript
// Search across all entities
GET /api/search?q=sql+injection&type=finding,task&project={projectId}
```
## Frontend Integration
### API Client Setup
```typescript
// lib/api.ts
import axios from 'axios';
const api = axios.create({
baseURL: process.env.NEXT_PUBLIC_API_URL,
headers: {
'Content-Type': 'application/json'
}
});
// Request interceptor for auth token
api.interceptors.request.use((config) => {
const token = localStorage.getItem('accessToken');
if (token) {
config.headers.Authorization = `Bearer ${token}`;
}
return config;
});
// Response interceptor for token refresh
api.interceptors.response.use(
(response) => response,
async (error) => {
const originalRequest = error.config;
if (error.response?.status === 401 && !originalRequest._retry) {
originalRequest._retry = true;
const refreshToken = localStorage.getItem('refreshToken');
if (refreshToken) {
try {
Ver no GitHub