

Finding DetailsĬontains the common data types that may be needed to include in reporting metadata and allow for toolset integration. You will find three major sections:Įach major section contains multiple sub-sections to help automate and use canned vocabulary. The data within this project is broken out into multiple headers and lists this allows for easy data serialization to JSON or other future formats as long as an MD parser exists.

Moving forward this project hopes to help small, over-tasked, and startups produce valuable data for clients and their organizations they support. However, this can raise a greater question of how we can integrate into automation. These constraints were due to lack of a centralized repository for findings, a single source of truth. Too often in prior experience reporting was repetitive, inaccurate and time loss incurred during the phase of the assessment. OS-CFDB: Open Source - Common Findings Data Base.If you do not contribute, who will? Please take the time to correct, update, or even make a pull request when you are feeling up to the task. Please understand that this is Open Source project that is driven by community feedback.

While this project is scalable, it may not cover every single scenario applicable to your needs or reporting SOP (Standard Operating Procedures). This project aims to provide a single source of common findings seen on Web/Application, Network, and Red Team assessments. OS-CFDB: Open Source - Common Findings Data Base
