Automated Vulnerability
Assessment and
Management
whoami!
• Bug Hunter on Internet – disclosed vulnerability @Google, @Facebook,
@Twitter etc.
• I’m Anand Tiwari
• Pentester – WebApp, MobApp & Network
• Working @ Philips Healthcare on Securing Medical Devices.
• 5+ Years of Experience in InfoSec.
• I love Automation for repeated work.
agenda
•What is Vulnerability Assessment & Management.
•Archery - Open Source VA/VM Tool.
•Challenges in VA/VM.
•How Archery works ?
•Automated Web Application Dynamic Scanning.
•Demo time.
•Roadmap
•How to Contribute ?
•Q/A
Source - Google
Vulnerability Assessment.
Vulnerability Management.
Source - Google
Challenges in VA/VM
• Multiple scanners.
• Manage huge list of vulnerabilities.
• Analysis and removing false positive.
• Prioritising vulnerabilities.
• Tracking vulnerability mitigation.
• Organizing Periodic scans.
Archery - Open Source VA/VM Tool.
• Open Source Vulnerability Assessment and Management Tool.
• Automate Vulnerability Scanners.
• Vulnerability data Dashboard.
• Helping you on Managing & Prioritising Vulnerabilities.
• Useful for Pentesters & Developers.
• Easy to integrate in CI/CD environment.
• Build in Python using Django.
How Archery works ?
Scanners
Archery	Result	Parsing
Archery	Database
ZAP	Data
Burp	Data
OpenVAS	Data
Dashboard
Web Application Dynamic Authenticated scanning.
Input URL
Cookies db
ZAP Replacer
ZAP Scanner
Selenium Webdriver
Demo
Roadmap
• More open source and commercial tool plugin support.
• API Scanning and management.
• Mobile Vulnerability Management.
• Vulnerability PoC pictures.
• Cloud security scanning.
• Reporting Format.
How to Contribute ?
• Test Archery Tool
• Write scanners plugin or suggest us scanner
support.
• Use / Promote / write about the tool.
• Report issue & feedback @ https://github.com/
archerysec/archerysec/issues
Documentation
• http://www.archerysec.info
• https://archerysec.github.io/archerysec/
• https://archerysec.github.io/archerysecapi/
Contact
• Twitter - https://twitter.com/archerysec
• Facebook - https://www.facebook.com/
ArcherySec/
• GitHub - https://github.com/archerysec/
Automated Vulnerability Assessment and Management

Automated Vulnerability Assessment and Management

  • 1.
  • 2.
    whoami! • Bug Hunteron Internet – disclosed vulnerability @Google, @Facebook, @Twitter etc. • I’m Anand Tiwari • Pentester – WebApp, MobApp & Network • Working @ Philips Healthcare on Securing Medical Devices. • 5+ Years of Experience in InfoSec. • I love Automation for repeated work.
  • 3.
    agenda •What is VulnerabilityAssessment & Management. •Archery - Open Source VA/VM Tool. •Challenges in VA/VM. •How Archery works ? •Automated Web Application Dynamic Scanning. •Demo time. •Roadmap •How to Contribute ? •Q/A
  • 4.
  • 5.
  • 7.
    Challenges in VA/VM •Multiple scanners. • Manage huge list of vulnerabilities. • Analysis and removing false positive. • Prioritising vulnerabilities. • Tracking vulnerability mitigation. • Organizing Periodic scans.
  • 8.
    Archery - OpenSource VA/VM Tool. • Open Source Vulnerability Assessment and Management Tool. • Automate Vulnerability Scanners. • Vulnerability data Dashboard. • Helping you on Managing & Prioritising Vulnerabilities. • Useful for Pentesters & Developers. • Easy to integrate in CI/CD environment. • Build in Python using Django.
  • 9.
    How Archery works? Scanners Archery Result Parsing Archery Database ZAP Data Burp Data OpenVAS Data Dashboard
  • 10.
    Web Application DynamicAuthenticated scanning. Input URL Cookies db ZAP Replacer ZAP Scanner Selenium Webdriver
  • 11.
  • 12.
    Roadmap • More opensource and commercial tool plugin support. • API Scanning and management. • Mobile Vulnerability Management. • Vulnerability PoC pictures. • Cloud security scanning. • Reporting Format.
  • 13.
    How to Contribute? • Test Archery Tool • Write scanners plugin or suggest us scanner support. • Use / Promote / write about the tool. • Report issue & feedback @ https://github.com/ archerysec/archerysec/issues
  • 14.
  • 15.
    Contact • Twitter -https://twitter.com/archerysec • Facebook - https://www.facebook.com/ ArcherySec/ • GitHub - https://github.com/archerysec/