Skip to content
FACTION
All posts

OWASP Faction 1.7 — Major Updates for Enterprise Security Teams

For enterprise penetration testing teams and security consulting firms managing multiple assessments, staying organized is essential. OWASP Faction 1.7…

FACTION Security Updated 5 min read
OWASP Faction 1.7 — Major Updates for Enterprise Security Teams

OWASP Faction 1.7 — Major Updates for Enterprise Security Teams

For enterprise penetration testing teams and security consulting firms managing multiple assessments, staying organized is essential. OWASP Faction 1.7 includes new management and reporting features designed to help teams handle complexity at scale… And its fully Open Source!

Manager Dashboard: Command Center for Your Assessment Program

We are most excited to bring the Manager Dashboard to Faction 1.7. This is your birds-eye view into key metrics of your security assessment program.

What Makes the Manager Dashboard Essential:

Deep Program Visibility Get instant insights into your entire assessment portfolio. Whether you’re overseeing a corporate AppSec program with continuous testing cycles or managing client engagements across a consulting practice, you’ll always know exactly where things stand.

Track Assessments at Scale No more hunting through spreadsheets or struggling to remember which assessments are running behind schedule. The dashboard surfaces the information that matters — bottlenecks, approaching deadlines, and resource allocation — all in one unified view.

Custom Status for Your Unique Workflows Every organization tracks assessments differently. Maybe you need to flag projects as “Awaiting Client Access” or “Pending Remediation Verification.” With custom status options, Faction adapts to your process, not the other way around.

Robust Search and Comparison Need to compare Q3 2024 performance against Q3 2023? Want to see all assessments for a specific client or application? The dashboard’s search and filtering capabilities let you slice your data any way you need — perfect for quarterly business reviews, capacity planning, or identifying trends across your assessment program.

You can pair the Manager Dashboard with our existing Security Metrics to gain key insights into how your clients, applications, and campaigns are performing from a security perspective.

Cleaner UI: More Assessment, Less Clutter

We’ve redesigned the Assessment interface to maximize screen real estate and minimize distractions, while adding new reporting features you’ve been asking for.

Assessment metadata and User-Defined Variables are now collapsed by default, giving you a cleaner workspace. We’ve also added quick-access controls for User-Defined Variables, making it easier to insert them anywhere in your reports.

Enhanced Report Editor

We’ve made significant improvements to the report editor to streamline your workflow and ensure consistency across findings.

WYSIWYG Improvements The editor now better reflects what you’ll see in the final report, reducing surprises during export and giving you more confidence as you document findings.

Automatic Image Borders Images now automatically include borders when inserted into reports. No more inconsistent screenshots or manual formatting — your findings look clean and professional by default.

New Markdown Syntax We’ve extended Markdown to include some features that are not Standard in the Markdown syntax but are much need when writing penetrating testing reports.

  • Underline text using ++ syntax: ++Steps To Reproduce++
  • Center text using > syntax: > Centered Heading

Dynamic Figure Numbering The new ${Figure#.1} variable automatically manages figure caption numbers throughout your report. Add or reorder findings without manually updating figure references—Faction handles the numbering for you.

The screenshot below shows how these features work together to create robust reports with a better authoring experience for your Final report.

Status Workflows: Automation That Adapts to You

Security assessments follow predictable patterns, so why should you manually update status at every stage? Faction 1.7 introduces intelligent Status Workflows that automatically track your assessments through their lifecycle.

Built-in Intelligence, Custom Flexibility

Faction automatically transitions assessments through key gates:

  • Scheduled when assessments are booked
  • In Progress when testing begins
  • Completed when findings are finalized

But real-world scenarios demand flexibility. Need to pause an engagement? Set it to “On Hold.” Dealing with an application being sunset? Add a custom “Decommissioning” status. Your workflow, your rules.

For consulting firms managing client commitments, this means accurate status reporting without manual overhead. For enterprise teams, it means consistent tracking across dozens of assessors — even when team members have different working styles.

CVE-Powered Vulnerability Creation: From Research to Report in Seconds

Tired of copying and pasting from NVD, reformatting descriptions, and hunting down references? Faction 1.7’s CVE integration eliminates the busywork. It’s now built into your vulnerability template search!

Intelligence Built Into Your Workflow

Simply enter a CVE ID, and Faction automatically generates:

  • Comprehensive vulnerability descriptions that are report-ready
  • Updated references to vendor advisories, patches, and security bulletins
  • Accurate severity ratings with support for native scoring, CVSS 3.1, and CVSS 4.0

This is a game-changer for teams dealing with known vulnerabilities across multiple assessments. Instead of recreating the wheel for each instance of Log4Shell, SQL injection, or any other common vulnerability, your team can focus on the context-specific details that matter to your clients.

Expanded REST API: Integration Without Limits

Modern security operations don’t exist in isolation. Faction 1.7 significantly expands the REST API to enable seamless integration with your existing tools and workflows.

New API Capabilities:

Vulnerability Management

  • Create and update vulnerabilities programmatically
  • Bulk import findings from automated scanners
  • Synchronize vulnerability data with GRC platforms

Assessment Orchestration

  • Automatically schedule assessments based on release cycles
  • Update assessment status from external systems
  • Reassign assessors based on availability or expertise

Custom Automation Build the integrations your business needs:

  • Trigger assessments when applications are deployed to production
  • Auto-generate executive reports for stakeholder distribution
  • Sync findings with Jira, ServiceNow, or your ticketing system of choice
  • Feed assessment metrics into business intelligence dashboards

For security consulting firms, this means seamless client reporting and reduced administrative overhead. For enterprise teams, it means Faction becomes a central hub in your DevSecOps pipeline.

Built for Enterprise Scale, Designed for Real Teams

OWASP Faction 1.7 represents a significant leap forward in assessment management maturity. Whether you’re a consulting firm juggling multiple client engagements or an enterprise security team protecting hundreds of applications, these features address the operational challenges that emerge at scale.

Key Benefits:

  • For Managers: Visibility and control over your entire assessment program
  • For Assessors: Less administrative work, more time finding vulnerabilities
  • For Organizations: Consistent processes, better reporting, and seamless tool integration

Get Started with Faction 1.7

The update is available now for all OWASP Faction users. For detailed documentation on the new features, API endpoints, and configuration options, visit the Faction Website.

Github: https://github.com/factionsecurity
Manual: https://docs.factionsecurity.com
OWASP: https://owasp.org/www-project-faction/

OWASP Faction is an open-source security assessment and penetration testing management platform designed for security teams who demand more from their tools.

Originally published on Medium .

Keep reading

6 min read

Releasing Faction 2.0 at BlackHat Arsenal 2026

I’m excited to announce that I’ll be returning to Black Hat Arsenal 2026 in Las Vegas and SecTor 2026 in Canada to demo OWASP Faction 2.0 — the biggest…

FACTION Security
  • Cybersecurity
  • Red Team
  • Pentesting