Modernizing the Application Penetration Engagement and Reporting Lifecycle - Ryan Armstrong @OWASPGLOBAL
Modernizing the Application Penetration Engagement and Reporting Lifecycle - Ryan Armstrong  @OWASPGLOBAL
Uploaded March 2025 | Updated September 2026, 3 weeks ago
owasp2024globalappsecsanfra.sched.com/event/1g3aZ/modernizing-the-application-penetration-engagement-and-reporting-lifecycle

There exists an abundance of resources addressing the general topic of writing penetration test reports, but few – if any – address the systems and processes holistically within the lifecycle of an engagement. Further, there is an absence of resources and standards that examine the unique challenges and requirements for the reporting of application security tests compared to penetration tests targeting networks and systems. Existing standards and frameworks for report creation also lack consideration for the contemporary needs and challenges of both mature and immature security teams and organizations. These divergent needs themselves dictate for multiple reporting processes, considerations, and ultimately deliverables.


This presentation will focus largely on the evolution of the reporting processes and output of an application security testing team working within an offensive security consulting organization. The presentation will follow the timeline in our journey from a legacy reporting ecosystem to our present implementation and beyond.


Beginning with a discussion of our legacy systems, this presentation will describe our traditional reporting tooling, systems, and processes while highlighting the major challenges and deficiencies. The following key considerations will be centered: ease of use and efficiency, data collection and analytics, error prevention, automation, and client-specific requirements.

Research was conducted to evaluate alternative systems and approaches in reconstructing a reporting ecosystem. We first sought to determine the key requirements for an ideal report and associated deliverables. A comprehensive comparative review of publicly available application penetration test reports was conducted to identify these key attributes. The results of this analysis will be presented and available publicly in written form.

A similarly comprehensive approach was taken to evaluate freely available and commercial reporting platforms. This presentation will discuss the methodology and process but will not present a summary comparison of platforms assessed. The chosen commercial platform will be discussed, but this talk is not a promotion or endorsement and will highlight also challenges and limitations.

Finally, we will examine the processes and systems that have been adopted to manage reporting content and processes beyond the reporting platform itself. This includes significant use of the Microsoft 365 and Power platforms which allow us to manage data and automations around the engagement lifecycle. The discussion will cover our successes, challenges, and future endeavors.

-

Managed by the OWASP® Foundation
owasp.org
Modernizing the Application Penetration Engagement and Reporting Lifecycle - Ryan ArmstrongSecuring Distributed Systems with Privacy-Aware Governance and ML Controls - Track 2Breaking the Black Box - Using the OWASP Threat Model Library to End Security via ObscurityHackuracy: Boosting AST accuracy through hacking - Andres RoldanO My Data: OData Injection attack in Microsoft Power Platform and UiPath - Amichai ShulmanBuilding a Static Analyzer from ScratchHidden Risks of Integrating AI: Extracting Private Data with Real-World ExploitsThreat Modeling Developer Behaviour: The Psychology of Bad CodeLiving off Microsoft Copilot - Michael BarguryEvolving Threat Modeling Through the Open Threat Model Format - Fraser ScottOWASP Corporate Supporter Spotlight - root.ioOne Cluster to Rule Them All: Pentesting Multi-Tenant Kubernetes Clusters
OWASP Foundation |

Modernizing the Application Penetration Engagement and Reporting Lifecycle - Ryan Armstrong

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER