Finding templates are available on the Pentest Suite plan. View plans
Template types
Two template types are available:Template fields
Each finding template contains the following information:Core details
Standards and scoring
Threat intelligence
Evidence and reproduction
Creating a template
1
Navigate to Templates
Go to Findings and click the Templates tab.
2
Click Add
Click the Add button.
3
Fill in template details
Enter the vulnerability information you want to save:
- Provide a descriptive name
- Set the appropriate risk level
- Add description, recommendation, and other relevant fields
4
Save the template
Click Save to create your template.
Using a template
When you create a new finding, you can select a template to pre-populate the form:1
Start creating a finding
Go to Findings and click Add.
2
Click Use template
Click the Use template button, or navigate to the Templates tab and click Use Template on a template card.
3
Select a template
Choose from your custom templates, shared templates, or default templates. Use the search to filter by name.
4
Review and customize
The form pre-fills with the template data. Modify any fields as needed for this specific finding.
5
Add target-specific details
Fill in target-specific information like the affected target, port, and specific evidence.
6
Save the finding
Click Save to create the finding.
Managing templates
Filtering templates
Filter your template list by:- Type: Show all templates, only custom templates, or only default templates
- Name: Search for templates by keyword
Viewing templates
Click on any template card to view its full details in a modal. The card displays:- Template name
- Description preview
- Owner (for shared templates)
- Your permission level (Owner, Edit, or View)
Editing templates
To edit a custom template:- Navigate to Findings > Templates tab
- Find the template you want to edit
- Click the options menu (three dots) and select Edit
- Make your changes
- Click Save
Default templates provided by Pentest-Tools.com cannot be edited. You can only edit templates you own or templates shared with you with Edit permission.
Deleting templates
To delete a custom template:- Navigate to Findings > Templates tab
- Find the template you want to delete
- Click the options menu (three dots) and select Delete
- Confirm the deletion
Sharing templates
You can share finding templates with team members.Permission levels
How to share templates
- Go to Settings > Team
- Select the team members you want to configure sharing for
- Click Share
- Set the Finding Templates permission level
- Click Save
Best practices
Standardize naming conventions
Standardize naming conventions
Use consistent naming patterns for your templates. Include the vulnerability type and any relevant context (e.g., “SQL Injection - Blind Boolean-based”).
Include complete references
Include complete references
Add CVE, CWE, and OWASP classifications to help with compliance reporting and vulnerability tracking.
Document reproduction steps
Document reproduction steps
Include clear, step-by-step instructions in the “How to Reproduce” field. This helps team members validate findings and demonstrates impact to stakeholders.
Use templates for recurring vulnerabilities
Use templates for recurring vulnerabilities
Create templates for vulnerabilities you encounter frequently during pentests to save time and ensure consistent documentation.
Keep recommendations actionable
Keep recommendations actionable
Write specific, actionable remediation guidance rather than generic advice.
Use cases
Penetration testing teams
Create templates for vulnerabilities commonly found during engagements:- Authentication bypass techniques
- Injection vulnerabilities
- Misconfigurations
- Business logic flaws
Compliance reporting
Standardize how compliance-related findings are documented:- Include relevant compliance framework references
- Ensure consistent severity ratings
- Add standard remediation guidance
Knowledge sharing
Build an organizational knowledge base of vulnerability templates:- Share templates with team members for consistent documentation
- Document company-specific security policies
- Maintain consistent reporting quality across team members