Giter Club home page Giter Club logo

netrisk's People

Contributors

ffquintella avatar

Stargazers

 avatar  avatar

Watchers

 avatar  avatar

netrisk's Issues

“Tecnologia” field content

Possibility to include values in the list of technologies (such as Apache). This way you can also remove/rename duplicates (such as “Web portal”) at the moment

Problem associating Risco with Vulnerabilidade

After you first edit a Vulnerabilidade in NetRisk, associate the Risco and save. When I re-edit the Vulnerabilidade, it is without the associated risk.

To work around it I re-edit the Vulnerabilidade. It works, but I notice that it associates timedate with the "Última detecção" field

Possibility of associating applications and ports with a vulnerability

Within a Vulnerabilidade, I can already associate a Computador, but it would be interesting to also associate an Aplicação and a Porta (when applicable). There are cases of different web vulnerabilities reported for the same Computador, for example Apache Docker applications running on the same Computador. Today we do not have the option of fields to link Application and Port, even manually.
In addition to the possibility of linking these fields, you can also display this information in the vulnerability table.

Change vulnerability states

The tool already has intelligence that does not allow some vulnerability state changes, such as Rejeitada->Verificada or Ajuste solicitado->Verificada, but cases like this may be necessary to correct attribution errors

Dynamic search

In any vulnerability record, when associating a "Tecnologias" or "Computador", it would be interesting to include a dynamic search, so that when typing, records that match the text typed are dynamically displayed

Include the scan source

Within the record of a given vulnerability, it would be interesting to include the scan source (Nessus or SerucityScorecard), in case it is necessary to research further detection details

Sorting and filtering

Inside Vulnerabilities. The sorting and filtering part seems to be generating some inconsistency.
Ex.:
- A descending sorting of Notas displays (disregarding duplicates) notas 28, 22 and 1 (first page)
- A descending sorting of Notas (applying the 'Score > 5' filter) displays (disregarding duplicates) notas 28, 22 and 6 (first page)

Create a business entity API

There should be an CRUD rest api to maintain business entities (entities related to business witch can represent, business process, business organizations, or assets)

Reporting view

Creates a reporting window to show custimizable reports

Delay in updating the state of objects

I found that an change in NetRisk, it may take time to be replicated to other users of the tool. Sometimes it is necessary for the other user to close and reopen the application. To facilitate collaborative work, this time could be reduced to the minimum possible.
Note: It was validated through the creation of a new “Entidade”

Multiple risk associations simultaneously

Using the tool, new needs for multiple simultaneous changes were identified.
Imagine handling many critical vulnerabilities from the same server and from the same owner. It is necessary to associate the same risks for all vulnerabilities simultaneously.

Inclusion of new fields

Including new fields for vulnerabilities (even if for manual input), sometimes this data that is already in the information sources report. Even if it is not possible to automate the filling of these fields at the moment, allow manual filling.
Ex.:
IP Associado
Porta Associada
Aplicação

Inaccessible fields and buttons in the vulnerability window

Using version 0.73.1, I found that in the vulnerability editing window, the window size is not enough to display all fields and buttons (especially fields and buttons at the bottom of the window). As resizing is not enabled, these fields and buttons cannot be accessed

Fields at Vulnerabilities table

Include new fields in the Vulnerabilities table (Vulnerabilidades area) and enable filtering by these fields.

The suggested fields are:

  • Computador (mainly)
  • Time
  • Tecnologia

Bug when adding computer

When trying to add a new computer (either through the shortcut in the upper right corner of the system, or through the shortcut within the vulnerabilities area. EditHostDialog window) NetRisk is closed when clicking the "Guardar" button.
Searching later the computer is also not added to the base.

Match column names in base and "Vulnerabilidades" table

In vulnerabilities area, to facilitate the application of filters, it would be interesting give to table columns the same name displayed in table.
Ex.: If you want to search for a titulo, the filter would be "titulo == Redirect*"
Ex.: If you want to search for a nota, the filter would be "nota > 5"

Unable to Disassociate a Risk from a Vulnerability

In the context of a vulnerability, when we remove a previously selected risk and click "Guardar," the change is not persisted. Upon revisiting the vulnerability, we observe that the risk is not disassociated.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.