Skip to content

Penetration testing management

Run every penetration test from one platform.

PT-Hub gives security teams one place to scope assets, execute tests, document findings, and prove remediation — with a full audit trail behind every step.

  • Multi-tenant
  • Role-based access
  • Scanner integration

The problem

Pentest programs run on spreadsheets and goodwill.

  • Scattered tools

    Scope lives in a spreadsheet, findings in a scanner export, evidence on a shared drive, and status in email. Nothing reconciles.

  • Manual reporting

    Every report gets rebuilt by hand. Proving the work takes as long as doing it.

  • No audit trail

    When an auditor asks who changed a finding and when, the answer is a search through chat history.

PT-Hub replaces all of it with one system built for how penetration tests actually run.

The workflow

One finding, from discovery to closure.

The same vulnerability, tracked through every stage of the lifecycle — scoped, tested, reported, and retested.

  1. 01

    Asset Inventory

    Define what is in scope.

    Organize applications, servers, and network devices into logical entity groups before testing starts.

    • Record IP ranges, technologies, and business criticality per asset
    • Categorize and tag assets into groups that match your organization
    • Document and approve scope before a test begins
    • Initialize risk assessment at the asset level

    Asset in scope

    V-4271

    Server-Side Template Injection

    In scope
    Asset
    Executive Dashboard
    Type
    Web application
    Criticality
    Critical
  2. 02

    Test Execution

    Run the test, track the progress.

    Create test records inside a test plan, assign assets and testers, and monitor status as work proceeds.

    • Build test plans using BlackBox, GrayBox, or WhiteBox methodology
    • Assign test cases to team members with progress tracking
    • Combine manual testing with automated scanner imports
    • Monitor execution status in real time

    Under test

    V-4271

    Server-Side Template Injection

    In progress
    Test
    TC-42 · Dynamic, Full Test
    Method
    GrayBox
    Assigned
    PT-Hub team
  3. 03

    Vulnerability Reporting

    Document findings once.

    Capture technical detail, risk rating, and evidence against the asset the finding belongs to.

    • Import scanner results automatically or add findings manually
    • Standardized templates with severity classification
    • Attach evidence to every finding
    • Risk scoring and classification built in

    Finding raised

    V-4271

    Server-Side Template Injection

    Open
    Severity
    Critical
    Discovered
    Dynamic
    Asset
    Executive Dashboard
  4. 04

    Remediation Tracking

    Prove it was fixed.

    Track remediation with asset owners, handle retest requests, and keep the trail an auditor will ask for.

    • Track remediation progress and communicate with asset owners
    • Handle retest requests raised by developers
    • Generate reports for technical, management, and compliance readers
    • Maintain audit trails for compliance requirements

    Retest passed

    V-4271

    Server-Side Template Injection

    Closed
    Retest
    Passed
    Closed by
    QA reviewer
    Evidence
    Attached

Features

Everything a pentest program needs.

  • Pentest Findings Management

    Track and manage vulnerabilities discovered during testing with structured categorization, risk assessment, and detailed reporting.

  • Comprehensive Dashboard

    A real-time security overview with customizable widgets, vulnerability statistics, risk metrics, and executive-level reporting.

  • Multi-Tenant Architecture

    Complete entity isolation, customizable entity groups, and granular user access control for secure organizational separation.

  • Team Collaboration

    Role-based access control, team management, and collaborative workflows built for penetration testing teams.

  • Asset Management

    A comprehensive asset inventory covering applications, servers, and network devices with detailed tracking and organization.

  • Advanced Reporting

    Generate detailed security reports, risk assessments, and compliance documentation using customizable templates.

  • Test Planning

    Structured test planning and case management with progress tracking and task assignment.

  • Activity Monitoring

    A comprehensive audit trail with real-time activity tracking, user behavior monitoring, and detailed system event logging.

  • Scanner Integration

    Seamless integration with popular security scanners and tools for consolidated vulnerability management.

Built for

The teams that run offensive security.

  • Internal cybersecurity teams

    Public and private sector security functions running their own testing programs.

  • Managed security service providers

    MSSPs coordinating testing across many client environments at once.

  • Freelance testers and red teamers

    Independent practitioners who need structure without enterprise overhead.

  • Security consultants and advisory firms

    Consultancies delivering assessments under their own methodology and brand.

  • Governance, risk, and compliance

    GRC departments who need evidence, not screenshots pasted into a document.

  • Internal audit teams

    Auditors who need to see what changed, who changed it, and when.

Trust

Security you can show an auditor.

  • Data hosted in Saudi Arabia
  • Cloud or on-premise
  • Built by practitioners

    Developed by cybersecurity experts with hands-on penetration testing experience.

  • Secure by design

    Encryption, role-based access control, and activity logs are built into the foundation.

  • Structured or ad hoc

    Supports formal methodologies and opportunistic testing equally well.

  • Less coordination overhead

    Reduces the load on project managers and QA reviewers chasing status.

Questions

What teams ask before a demo.

Get started

See PT-Hub on your own scope.

Request a demo and we will walk through the workflow with your assets, your methodology, and your reporting requirements.

Prefer email? info@cyberx.sa