License & Deployment Mix: 10 tools – 5 OSS, 5 commercial.
Color: Red team.
What Is This Category?
Findings aggregation, evidence management, engagement tracking, and customer-deliverable report generation for pentest / red-team practices.
Pentest management platforms are the layer that sits between the pentester’s tools (Burp Suite, Nessus, BloodHound, Metasploit) and the customer- facing PDF. A platform tracks findings (with CVSS / OWASP / ATT&CK mapping), evidence (screenshots, command output), authors (per-pentester attribution), versioning (draft, peer review, final), and templated report output. Mature platforms add engagement lifecycle, scanner-output auto-import, customer- facing portals, and retest tracking across cycles.
Distinct from neighbouring categories
- Offensive Frameworks (Exploit / C2) – Offensive frameworks generate the findings; pentest-mgmt records and reports them
- Ticketing / Help Desk – Ticketing is generic; pentest-mgmt has the engagement / finding / evidence schema baked in
- Document Automation – Doc automation is generic templated documents; pentest-mgmt knows what a pentest report looks like
The information on these pages was researched by a combination of human review and large language models. To suggest an addition or correction, please contact us. Prepared by Rhodium Systems Inc., author of the ResorsIT platform — a unified IT operations management platform for IT teams and MSPs that integrates a curated suite of open-source, commercial, and SaaS applications into a single system with shared identity, single sign-on, access control, and a common audit trail. Use this catalogue only as a starting point for your own research, and review any tool carefully against your own requirements before relying on it. Catalogue data version 2026.197.
Comparison
Overview
This category covers everything a pentest practice needs around the actual hacking: engagement tracking, finding aggregation, scanner-output ingest, collaborative editing, branded report generation, customer-facing portals, and retest cycles. The landscape splits four ways: lightweight OSS reporting tools (Pwndoc, SysReptor), full OSS platforms (Dradis CE, Faraday CE, Ghostwriter), commercial platforms (PlexTrac, Dradis Pro, AttackForge, Hexway Hive), and the PtaaS marketplace (Cobalt.io).
Capability Matrix
What each tool does beyond report generation.
| Tool | Reports | Engage Mgmt | Scanner Import | Customer Portal | PtaaS | Real-time Collab |
|---|---|---|---|---|---|---|
| SysReptor | yes | partial | – | – | – | partial |
| Dradis Community | yes | partial | limited | – | – | – |
| Faraday Community | yes | yes | yes (80+) | – | – | yes |
| Ghostwriter | yes | yes (+ infra) | – | – | – | – |
| Pwndoc | yes | – | – | – | – | – |
| PlexTrac | yes | yes | yes | yes | – | yes |
| Dradis Pro | yes | yes | yes (30+) | yes | – | – |
| AttackForge | yes | yes | yes | yes | – | yes |
| Cobalt.io | yes | yes | yes | yes | yes | yes |
| Hexway Hive | yes | yes | partial | – | – | yes |
License Comparison
| Tool | License | OSI | Type |
|---|---|---|---|
| SysReptor | MIT | yes | OSS web (Syslifters Cloud also available) |
| Dradis Community | GPL-2.0-only | yes | OSS web |
| Faraday Community | GPL-3.0-only | yes | OSS web |
| Ghostwriter | BSD-3-Clause | yes | OSS web (SpecterOps) |
| Pwndoc | GPL-3.0-only | yes | OSS web |
| PlexTrac | Proprietary | – | Commercial SaaS |
| Dradis Pro | Proprietary | – | Commercial SaaS + self-host |
| AttackForge | Proprietary | – | Commercial SaaS + self-host |
| Cobalt.io | Proprietary | – | Commercial PtaaS SaaS |
| Hexway Hive | Proprietary | – | Commercial SaaS + self-host |
Deployment Comparison
| Tool | Deployment | Resources | Notes |
|---|---|---|---|
| SysReptor | Docker Compose | Modest | Native OIDC |
| Dradis Community | Docker / native | Modest | Local auth |
| Faraday Community | Docker Compose | Medium | Faraday Agent on operator machine |
| Ghostwriter | Docker Compose | Modest | Cloudflare / Namecheap / DigitalOcean API hooks |
| Pwndoc | Docker Compose | Modest | MongoDB backend |
| PlexTrac | SaaS | – | – |
| Dradis Pro | SaaS or on-prem (Pro Server) | Modest | – |
| AttackForge | SaaS or on-prem | Medium | Self-host MongoDB-based |
| Cobalt.io | SaaS | – | Marketplace model |
| Hexway Hive | SaaS or on-prem Docker | Modest | Real-time collab UX |
SSO / OIDC
| Tool | OIDC | SAML | SCIM | Authentik Notes |
|---|---|---|---|---|
| SysReptor | native | plugin | – | Native OIDC direct |
| Dradis Community | plugin | plugin | – | Reverse-proxy auth |
| Faraday Community | plugin | plugin | – | LDAP in CE; OIDC in Pro |
| Ghostwriter | plugin | plugin | – | Reverse-proxy auth |
| Pwndoc | plugin | plugin | – | Reverse-proxy auth |
| PlexTrac | paid | paid | paid | Enterprise tier |
| Dradis Pro | paid | paid | – | Enterprise tier |
| AttackForge | paid | paid | paid | Enterprise tier |
| Cobalt.io | paid | paid | paid | Business / Enterprise |
| Hexway Hive | paid | paid | – | Enterprise tier |
Stack Composition
Two canonical pentest practice stacks.
OSS-only stack
Ghostwriter -- engagement / infrastructure / client tracking Faraday CE -- scanner-output aggregation during the engagement SysReptor -- final customer deliverable MISP -- IOC pivoting (see tools/threat-intel/)
Output: full pentest practice surface at zero license cost. Operator overhead for self-hosting the four platforms.
Commercial stack
PlexTrac -- one platform for engagement + reporting + portal (Faraday CE) -- optional shift-left scanner aggregation
Output: managed SaaS for the customer-facing experience; lower operational overhead at higher per-seat cost.
Cost Tier
Rough TCO for a 5-pentester practice.
| Tier | Tooling | Approx Cost |
|---|---|---|
| Free | SysReptor + Faraday CE + Ghostwriter | $0 + operator time |
| Mid | Dradis Pro / Hexway Hive | $1,000-5,000 / year |
| High | PlexTrac / AttackForge | $15,000+ / year (per-seat) |
| PtaaS | Cobalt.io | Per-engagement; alternative model |
Tools
10 tools.
AttackForge
Commercial pentest-management platform; deep customer-side vulnerability-management workflow; on-prem self-hosted tier widely deployed.
License: Proprietary (proprietary) · Kind: web · Deploy: saas, native · SSO: OIDC, SAML
Cobalt.io
Pentest-as-a-Service platform; matches customers with vetted pentesters via the Cobalt Core talent pool; SaaS workflow.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: OIDC, SAML
Dradis Community Edition
Open-source pentest collaboration and reporting platform; the longest-running OSS tool in this category.
License: GPL-2.0-only (OSS) · Kind: web · Deploy: docker, native · SSO: OIDC, SAML
Dradis Pro
Commercial edition of Dradis with scanner integrations and advanced workflow; Dradis Pro / Pro Server / Pro Cloud tiers.
License: Proprietary (proprietary) · Kind: web · Deploy: saas, native · SSO: OIDC, SAML
Faraday Community
Collaborative pentest IDE from Infobyte; 80+ tool integrations automatically import findings; agent-driven workflow.
License: GPL-3.0-only (OSS) · Kind: web · Deploy: docker, native · SSO: OIDC, SAML
Ghostwriter
Open-source engagement-management platform from SpecterOps; same team behind BloodHound; covers infra / domain / client-tracking alongside reporting.
License: BSD-3-Clause (OSS) · Kind: web · Deploy: docker, native · SSO: none
Hexway Hive
Pentest team workspace and report-generation platform; real-time collaboration differentiator; on-prem and SaaS tiers.
License: Proprietary (proprietary) · Kind: web · Deploy: saas, native · SSO: OIDC, SAML
PlexTrac
Commercial SaaS pentest reporting and findings-mgmt platform; the category leader for consulting / MSP pentest practices.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: OIDC, SAML
Pwndoc
Lightweight open-source pentest report generator; CVSS-driven, DOCX- templated, single-purpose report tool.
License: GPL-3.0-only (OSS) · Kind: web · Deploy: docker, native · SSO: none
SysReptor
Open-source collaborative pentest reporting platform from Syslifters; Django + Vue, native OIDC, Markdown-based finding library.
License: MIT (OSS) · Kind: web · Deploy: docker, saas · SSO: OIDC