Your country

Tools that support it use your country for local currency, number formats, units and paper size. Your choice is saved only in this browser.

Type a name or a two-letter code. Use the up and down arrow keys to move through the countries, Enter to choose one and Escape to close.

Penetration Test Report Generator

Findings in, a client-ready penetration test report out — written and kept on your device.

Security No upload Free preview, no sign-upIncluded in your pass Premium tool Premium pass: ₹799 for 30 days

Free preview.

  • Free preview: every page of the document as images marked “MySmartCoPilot preview · not for use”.
  • Locked until you unlock it: download.
  • Unlock: Premium pass, ₹799 for 30 days, a one-time payment that never renews.

Ways to unlock shows how to get the full result.

See passes (opens in a new tab)

Printing this result is locked in the free preview.

Report preview

Report details

Scope and method

Approach
Methodology

Findings

No findings yet. Add one, insert one from your library, or import scanner results.

    Executive summary

    Branding

    Logo PNG or JPEG

    Checks

      Report preview

      Next steps

      About the Penetration Test Report Generator

      Writing up a penetration test takes longer than it should: copying scanner output, scoring every finding, keeping IDs, tables and the executive summary in step. This generator does the assembly. Add findings with a title, a severity from the built-in CVSS 4.0 or 3.1 calculator (FIRST’s own scoring rules) or an OWASP Risk Rating, the affected assets, description, impact, steps to reproduce, evidence screenshots and text, remediation and references with CWE, OWASP Top 10 and WSTG links — or draft them from Nessus, Burp Suite, OWASP ZAP or Nmap exports.

      The report builds itself as you type: a cover in your colours with your logo, a contents page with page numbers, document control, an executive summary with severity and retest charts, scope, methodology (OWASP WSTG, PTES), how risk was rated, a findings table and every finding in detail, with a retest appendix for follow-up. Findings you write well once can be saved to your own library on this device and reused. The free preview shows every page of the report as you build it; a Premium pass unlocks the DOCX, PDF, Markdown and CSV files.

      It is meant for reports on testing you are authorised to do. Nothing you enter, open or import is uploaded.

      How to use it

      1. Fill in Report details (client, engagement, dates, testers, classification) and Scope and method.
      2. Add findings one by one, from your library, or with Import scanner results: choose a Nessus (.nessus), Burp Suite (issues as XML), ZAP (traditional XML report) or Nmap (-oX) file, tick the drafts you want and add them.
      3. Score each finding: paste or build a CVSS 4.0 or 3.1 vector, rate it with the OWASP Risk Rating factors, or choose a severity. Add evidence screenshots with captions and text evidence such as requests and responses.
      4. Write or draft the executive summary, add your logo and colours, and read the Checks for anything missing.
      5. Read the report in the preview beside the form. The DOCX, PDF, Markdown and CSV files download with a Premium pass; without one, the preview shows every page.
      6. Use Save project file to keep everything, screenshots included, and open it again later — that works with or without a pass.

      Examples

      A web application test with three findings
      Input
      Client Example Retail Ltd · customer portal · grey box · findings scored CVSS 4.0
      Result
      Cover, contents, document control, an executive summary with the severity chart, scope, methodology (OWASP WSTG v4.2), the CVSS rating scale, a findings table and each finding with its vector, CWE, Top 10 category and evidence.
      Drafting from a Nessus scan
      Input
      An internal network scan: 214 report items on 30 hosts
      Result
      One draft per plugin with every affected host and port listed, the plugin’s synopsis, description and solution, CVE and see-also links, and the plugin output of up to five hosts as text evidence. Informational items are left out unless you ask for them.
      A retest
      Input
      The same project file a month later, retest columns filled in
      Result
      A retest results chart in the summary, a retest box under each finding and an appendix table with the result, date and notes of every finding; the CSV carries the same columns for tracking.

      Common uses

      • Web application and API penetration test reports.
      • Internal and external network assessments drafted from Nessus or Nmap.
      • Vulnerability assessment reports for clients or auditors.
      • Retest reports that show what was fixed.
      • Bug bounty or internal security review write-ups in a consistent format.

      What goes into the report

      • Cover and contents: the engagement, client, version, dates and classification; contents with page numbers in the PDF (Word fills them in when the file opens).
      • Document control and executive summary: your text, or a draft built from the findings you can edit; the overall risk and charts of findings by severity (and by retest result).
      • Scope: what was in and out of scope, the approach (black, grey or white box), the testing period and any limitations.
      • Methodology: the OWASP Web Security Testing Guide, the Penetration Testing Execution Standard (pentest-standard.org), your own method and the tools used.
      • Risk ratings: the CVSS qualitative scale and, when used, the OWASP risk matrix.
      • Findings: a summary table, then every finding with severity, score, status, affected assets, CWE weakness IDs, the OWASP Top 10 category, WSTG tests, vector, description, impact, steps, evidence, remediation and references; the CWE, Top 10 and WSTG entries link to their pages.
      • Retest appendix, when you track retests.

      Scoring

      CVSS vectors are scored with the rules of FIRST’s reference calculators: v4.0 from its MacroVector lookup table and severity distances, v3.1 and v3.0 from their formulas, so the score matches what those calculators show. Paste a vector or build it metric by metric; v4.0 scores carry their nomenclature (CVSS-B, CVSS-BT, CVSS-BE, CVSS-BTE). The OWASP Risk Rating uses the same engine as the OWASP Risk Rating Calculator. A severity you choose yourself is marked as such in the report. Findings are numbered F-01, F-02 … by severity, or in the order you entered them.

      Importing scanner results

      • Nessus: export the scan as .nessus. Items are grouped by plugin across hosts; CVSS vectors in the file are used when present.
      • Burp Suite: select the issues and choose Report selected issues, as XML. Issues of the same type are grouped, with the request and response as evidence.
      • OWASP ZAP: the traditional XML report. Alerts keep their risk, CWE, solution and references, with the reported instances as evidence.
      • Nmap: XML output (-oX), also of a scan that was stopped part-way. Each open service becomes an unscored draft listing the hosts; the Nmap Scan Viewer can send just the ports you tick.

      Issues and alerts you marked as false positives in Burp Suite or ZAP are left out, and the import says how many.

      Scanner text is a starting point: check every draft against your own testing, rescore it for the client’s environment and delete false positives before the report goes out.

      Your findings library

      When a finding is well written, choose Save to library: its title, scoring, CWE, Top 10, WSTG, description, impact, remediation and references are kept in this browser (never the client’s assets, evidence or retest notes). Insert it into the next report and adapt it. Export the library as a file to move it to another browser or share it with your team, and import theirs.

      Limitations

      • Only for testing you are authorised to do; the report records your scope and dates, not permission itself.
      • Scanner drafts carry the scanner’s own wording and severity: they still need a tester’s review.
      • Screenshots are kept only in the project file you save, not in the browser draft; save the project file before closing the page.
      • The PDF uses Noto Sans for Latin, Greek and Cyrillic text; scripts that need shaping (such as Devanagari or Arabic) show as “?” in the PDF and in the free preview’s pages — use the DOCX for them.
      • The Word table of contents is a field: Word fills in its page numbers when the document opens (other apps may need you to update it).

      Privacy

      Everything happens in your browser. Findings, screenshots and scanner files are never uploaded. Keep this report in this browser is off unless you switch it on, so client data is not left on a shared computer; your findings library stays in this browser until you clear it.

      Frequently asked questions

      What do I get without a pass?

      Without a pass, Penetration Test Report Generator shows every page of the document as images marked “MySmartCoPilot preview · not for use”. Until you unlock it, the result can’t be downloaded. A Premium pass, a one-time payment that never renews, unlocks the full result. The pricing page lists the passes and their prices.

      Which CVSS versions can I use?

      CVSS 4.0 and 3.1, built metric by metric or pasted as a vector, and 3.0 vectors such as those Nessus exports. Each is scored by the rules of its own version.

      Can I use my own report template?

      You choose the logo, the two brand colours, the classification, the footer and a cover note, and every section takes your own text. Export DOCX to restyle it further in Word.

      Where are my findings kept?

      Only in this page while it is open, unless you switch on Keep this report in this browser (text only) or save the project file, which holds the screenshots too. The findings library is kept in this browser.

      Does it check whether findings are real?

      No. It assembles and scores what you enter or import. Verify every finding, especially scanner drafts, before you report it.

      What does the CSV contain?

      One row per finding: ID, title, severity, score, scoring method, vector, status, retest result, date and notes, affected assets, CWE, OWASP Top 10, WSTG tests, remediation and source — ready for a tracking sheet or a ticket import.

      Quick answers and tool search

      Type to search tools or to get a quick answer, for example 18% of 2500. Use the up and down arrow keys to move through the results, Enter to choose, and Escape to close.