Skip to main content

pentestops-dashboard

Comprehensive penetration testing operations dashboard for managing projects, tasks, findings, clients, and assets with Next.js and MongoDB

Informações da origem

Repositório
reason-machines/security-skills
Última atividade na origem
7 de junho de 2026 às 21:35
Idioma detectado do SKILL.md
inglês
Estrelas
12
Forks
1

Opções de instalação

Por padrão, está selecionado o prompt que primeiro revisa a origem. Você pode mudar para um comando direto ou baixar uma cópia local.

Revise os arquivos de origem

Leia o SKILL.md e os arquivos complementares exibidos pelo SkillsMP antes de decidir se vai instalar.

Exibindo SKILL.md

SKILL.md
Instruções da origem · Visualização somente leitura
name
pentestops-dashboard
description
Comprehensive penetration testing operations dashboard for managing projects, tasks, findings, clients, and assets with Next.js and MongoDB
triggers
["set up pentestops dashboard","create pentest project management system","configure pentestops with docker","add security findings to pentestops","manage penetration testing tasks","deploy pentestops dashboard","integrate cwe database with pentestops","create pentest checklist pages"]
# PentestOPS Dashboard Skill > Skill by [ara.so](https://ara.so) — Security Skills collection. ## Overview PentestOPS Dashboard is a comprehensive penetration testing operations platform built with Next.js, Express, and MongoDB. It provides project management, task tracking (Kanban/table views), finding management with CWE integration, client management, asset tracking, rich text pages with Editor.js, checklists, comments, file attachments, version history, and global search. **Key Features:** - Full-stack TypeScript application with JWT authentication - Rich text editor with Notion-like features - Single Docker container deployment (includes MongoDB, backend, frontend) - CWE database integration for security findings - File upload support (PDF, DOCX, XLSX, ZIP, images) - Threaded comments and version control ## Installation ### Local Development Setup ```bash # Clone repository git clone https://github.com/0xBugatti/PentestOPS.git cd PentestOPS # Install dependencies npm install cd frontend && npm install && cd .. cd backend && npm install && cd .. # Create .env file in root cat > .env << 'EOF' NODE_ENV=development BACKEND_PORT=4000 MONGODB_URI=mongodb://localhost:27017/pentest-dashboard JWT_SECRET=$(openssl rand -base64 32) JWT_REFRESH_SECRET=$(openssl rand -base64 32) CORS_ORIGIN=http://localhost:3000 ALLOW_REGISTRATION=true MAX_FILE_SIZE=10485760 UPLOAD_DIR=./backend/uploads NEXT_PUBLIC_API_URL=http://localhost:4000 EOF # Start MongoDB docker run -d --name mongodb -p 27017:27017 mongo:latest # Start development servers npm run dev ``` Access at: - Frontend: `http://localhost:3000` - Backend API: `http://localhost:4000` ### Docker Deployment (Production) ```bash # Build image docker build -t pentestops-dashboard:latest . # Run with environment file docker run -d \ --name pentestops \ --restart unless-stopped \ -p 3000:3000 \ -p 4000:4000 \ -v pentestops-data:/data/db \ -v pentestops-uploads:/app/uploads \ -e JWT_SECRET=${JWT_SECRET} \ -e JWT_REFRESH_SECRET=${JWT_REFRESH_SECRET} \ -e NODE_ENV=production \ -e CORS_ORIGIN=https://yourdomain.com \ -e ALLOW_REGISTRATION=false \ pentestops-dashboard:latest ``` ## Core API Endpoints ### Authentication ```typescript // Register new user POST /api/auth/register { "username": "pentester", "email": "pentester@example.com", "password": "SecurePass123!", "firstName": "John", "lastName": "Doe" } // Login POST /api/auth/login { "username": "pentester", "password": "SecurePass123!" } // Returns: { accessToken, refreshToken, user } // Refresh token POST /api/auth/refresh { "refreshToken": "your-refresh-token" } // Get profile GET /api/auth/profile Headers: Authorization: Bearer {accessToken} ``` ### Projects ```typescript // Create project POST /api/projects { "name": "Web Application Security Assessment", "description": "Comprehensive security audit of client web application", "status": "in-progress", "startDate": "2024-01-15T00:00:00Z", "endDate": "2024-02-15T00:00:00Z", "client": "client-id", "tags": ["webapp", "owasp", "critical"] } // List projects with filters GET /api/projects?status=in-progress&search=webapp&sort=createdAt // Get project details GET /api/projects/{projectId} // Update project PUT /api/projects/{projectId} { "status": "completed", "progress": 100 } // Delete project DELETE /api/projects/{projectId} ``` ### Tasks ```typescript // Create task POST /api/tasks { "title": "SQL Injection Testing", "description": "Test all input fields for SQL injection vulnerabilities", "status": "todo", "priority": "high", "project": "project-id", "assignee": "user-id", "dueDate": "2024-01-20T00:00:00Z", "tags": ["sqli", "webapp", "owasp-a03"], "checklist": ["Check login form", "Test search parameters", "Verify API endpoints"] } // List tasks with filters GET /api/tasks?project={projectId}&status=in-progress&priority=high // Update task status PUT /api/tasks/{taskId} { "status": "in-progress", "progress": 50 } // Add subtask POST /api/tasks/{taskId}/subtasks { "title": "Test login form SQL injection", "completed": false } // Add comment to task POST /api/tasks/{taskId}/comments { "content": "Found SQL injection in username parameter", "parentComment": "parent-comment-id" // Optional for threading } ``` ### Findings ```typescript // Create finding POST /api/findings { "title": "SQL Injection in Login Form", "description": "The login form is vulnerable to SQL injection attacks", "severity": "critical", "status": "open", "cweId": "CWE-89", "cvssScore": 9.8, "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "project": "project-id", "affectedAssets": ["asset-id"], "steps": [ "Navigate to login page", "Enter ' OR '1'='1 in username field", "Observe authentication bypass" ], "impact": "Attackers can bypass authentication and gain unauthorized access", "recommendation": "Use parameterized queries or prepared statements", "references": ["https://owasp.org/www-community/attacks/SQL_Injection"], "tags": ["sqli", "authentication", "critical"] } // List findings GET /api/findings?project={projectId}&severity=critical&status=open // Update finding PUT /api/findings/{findingId} { "status": "fixed", "remediation": "Implemented parameterized queries", "retestDate": "2024-01-25T00:00:00Z" } ``` ### CWE Database ```typescript // Import CWE database from CSV POST /api/cwes/import Content-Type: multipart/form-data file: cwes.csv // Search CWEs GET /api/cwes?search=injection&type=vulnerability // Get CWE details GET /api/cwes/89 // Returns CWE-89 (SQL Injection) details ``` ### Clients ```typescript // Create client POST /api/clients { "name": "Acme Corporation", "email": "security@acme.com", "phone": "+1-555-0123", "website": "https://acme.com", "industry": "Technology", "contacts": [ { "name": "Jane Smith", "role": "CISO", "email": "jane.smith@acme.com", "phone": "+1-555-0124" } ], "notes": "Primary contact for all security assessments" } // List clients GET /api/clients?search=acme // Update client PUT /api/clients/{clientId} ``` ### Pages (Checklists/Documentation) ```typescript // Create page with Editor.js content POST /api/pages { "title": "OWASP Top 10 Testing Checklist", "slug": "owasp-top-10-checklist", "content": { "time": 1640995200000, "blocks": [ { "type": "header", "data": { "text": "OWASP Top 10 Testing Checklist", "level": 1 } }, { "type": "paragraph", "data": { "text": "Comprehensive checklist for testing OWASP Top 10 vulnerabilities" } }, { "type": "checklist", "data": { "items": [ { "text": "A01:2021 - Broken Access Control", "checked": false }, { "text": "A02:2021 - Cryptographic Failures", "checked": false }, { "text": "A03:2021 - Injection", "checked": true } ] } }, { "type": "code", "data": { "code": "' OR '1'='1' --", "language": "sql" } } ], "version": "2.28.0" }, "isPublic": false, "tags": ["owasp", "checklist", "webapp"] } // Get page by slug GET /api/pages/owasp-top-10-checklist // Update page PUT /api/pages/owasp-top-10-checklist { "content": { /* updated Editor.js blocks */ } } // Link page to task PUT /api/tasks/{taskId} { "linkedPages": ["owasp-top-10-checklist"] } ``` ### File Attachments ```typescript // Upload file POST /api/attachments Content-Type: multipart/form-data file: screenshot.png entityType: finding entityId: finding-id // Download file GET /api/attachments/{attachmentId}/download // View image GET /api/attachments/{attachmentId}/view // List attachments for entity GET /api/attachments?entityType=finding&entityId={findingId} ``` ### Assets ```typescript // Create asset POST /api/assets { "name": "Web Server - Production", "type": "server", "ipAddress": "192.168.1.100", "hostname": "web-prod-01.acme.com", "os": "Ubuntu 22.04 LTS", "ports": [ { "port": 443, "protocol": "tcp", "service": "https", "version": "nginx/1.18.0" } ], "vulnerabilities": ["CVE-2023-1234"], "project": "project-id", "notes": "Primary web server for production environment" } // List assets GET /api/assets?project={projectId}&type=server // Link asset to finding PUT /api/findings/{findingId} { "affectedAssets": ["asset-id"] } ``` ### Global Search ```typescript // Search across all entities GET /api/search?q=sql+injection&type=finding,task&project={projectId} ``` ## Frontend Integration ### API Client Setup ```typescript // lib/api.ts import axios from 'axios'; const api = axios.create({ baseURL: process.env.NEXT_PUBLIC_API_URL, headers: { 'Content-Type': 'application/json' } }); // Request interceptor for auth token api.interceptors.request.use((config) => { const token = localStorage.getItem('accessToken'); if (token) { config.headers.Authorization = `Bearer ${token}`; } return config; }); // Response interceptor for token refresh api.interceptors.response.use( (response) => response, async (error) => { const originalRequest = error.config; if (error.response?.status === 401 && !originalRequest._retry) { originalRequest._retry = true; const refreshToken = localStorage.getItem('refreshToken'); if (refreshToken) { try {
Ver no GitHub
Este SKILL.md e muito grande, entao o SkillsMP mostra aqui apenas a primeira secao. Ver no GitHub