Advanced
Customization

The Most Configurable Offensive Security Management Platform Available

Switch workflows on and off. Adjust features to match how you want to work. Customize the application to your style and needs.

From whitelabelling to rule based SLAs, from custom fields to automated notifications, every aspect of AttackForge can be configured to match your exact requirements.

17+
Modules with toggles
100+
Config options
10+
Field types
Unlimited
Custom rules

Everything You Can Customize

Click any category to jump to detailed configuration options

Branding & Appearance Customization

Make AttackForge look and feel like YOUR platform. From complete whitelabelling to interface preferences, control every visual aspect of the application.

Whitelabelling

Replace AttackForge branding with your own identity throughout the entire platform. Your logo appears on the login page, navigation bar, and throughout the interface. Clients and team members see YOUR brand, not ours.

ConfigurationDescription
Company LogoUpload your logo to appear throughout the application
Login Page BrandingCustom logo and messaging on the sign-in screen
Navigation BrandingYour identity in the main navigation bar
FaviconYour icon in browser tabs

Use Cases

  • Security consultancies delivering branded client portals
  • MSSPs providing white-glove service experiences
  • Internal teams presenting professional interfaces to stakeholders

Custom Colours

Match AttackForge to your brand palette. Configure primary and accent colors to create a consistent visual experience that aligns with your corporate identity.

ConfigurationDescription
Primary ColorMain brand color used throughout the interface
Accent ColorSecondary color for highlights and interactive elements
Navigation ColorBackground color for the main navigation
Button ColorsPrimary and secondary action button styling

Dark Mode

Easy on the eyes during long testing sessions. Dark mode reduces eye strain and provides a modern interface preferred by security professionals.

ConfigurationDescription
User PreferenceAllow individual users to toggle their own preference

Table View Customization

See the data that matters to you, the way you want to see it. Configure which columns appear, their order, and how data is displayed across all major tables in the application.

ConfigurationDescription
Column VisibilityShow/hide columns based on your needs
Column Order and Scroll LockDrag and drop to arrange columns your way. Lock important columns on scroll
Default SortSet default sorting for each table
Advanced SearchWildcard matches and glob patterns, Regular Expressions (Regex)
Custom Field ColumnsDisplay your custom fields in tables
Date FormatUS (MM/dd/YYYY) or International format

Available On

Projects tables
Vulnerabilities tables
Assets tables
Writeups libraries
Users table
Test case tables
Portfolio tables

Custom Fields & Forms

Capture the data that matters to YOUR organization. AttackForge supports extensive custom field creation across projects, vulnerabilities, assets, writeups, portfolios, and project requests. With granular access controls for each field.

Custom Fields

Create custom data fields to capture information specific to your organization, compliance requirements, or client needs. Every custom field is available in reports and via the API.

Field Types Available

Field TypeDescriptionUse Case Example
Input (Text)Single-line text entryReference numbers, short identifiers
TextareaMulti-line text entryExtended notes, descriptions
Select (Dropdown)Single selection from predefined optionsStatus categories, classifications
Multi-SelectMultiple selections from predefined optionsTags, applicable frameworks
DatepickerDate selectionTarget dates, review dates
TableTabular data with multiple columnsConfiguration reviews, firewall rules
Rich-TextFormatted text with WYSIWYG editorDetailed notes that render in reports
User SelectSelect users from the systemOwners, reviewers, assignees
Group SelectSelect groups from the systemTeam assignments, business units

Where Custom Fields Can Be Added

Projects
Project Requests
Vulnerabilities
Vulnerability Writeups (Library)
Assets
Portfolios
Test Cases

Access Controls Per Field

Every custom field supports granular access controls:

VIEW ACCESS - Control who can see the field
  • By Role (Admin, Project Coordinator, Consultant, Client)
  • By Group
  • By Individual User
EDIT ACCESS - Control who can modify the field
  • By Role
  • By Group
  • By Individual User

Custom Forms

Build tailored forms for different clients, teams, or engagement types. Combine standard fields with custom fields to create the exact experience your organization needs.

ConfigurationDescription
Enable/Disable Standard FieldsHide fields you don't need
Add Custom FieldsInclude your custom fields
Field OrderArrange fields in logical sequence
Required vs. OptionalSet which fields must be completed
Conditional DisplayShow/hide fields based on other field values
Default ValuesPre-populate fields with standard values
Form AccessControl which users/groups see which form configurations

Use Cases

  • Different intake forms for PTaaS subscribers vs. ad-hoc customers
  • Simplified or detailed vulnerability forms for different types of tests
  • Compliance-specific forms capturing required regulatory information
  • Customer-specific forms with their unique metadata requirements

Linked Custom Fields

Automatically carry custom field values from project requests into created projects. When a project request is approved, linked fields populate automatically. No manual data entry required.

How It Works

Project Request: Client Contact Email
Project: Client Contact Email
Project Request: Compliance Framework
Project: Compliance Framework
Project Request: Budget Code
Project: Budget Code

Workflow Configuration

Switch workflows on and off. Enable only what your team uses. AttackForge lets you configure which modules are active, which features are available, and how processes flow - matching the platform to your operational model.

Module & Feature Toggles

Not every team uses every feature. AttackForge lets you enable or disable entire modules and individual features to create a streamlined experience focused on what your team actually needs.

Module/FeatureWhat It Controls
Project Request WorkflowEnable/disable formal project intake process
QA WorkflowEnable/disable vulnerability review/approval stages
Retest WorkflowEnable/disable remediation verification process
Test CasesEnable/disable methodology tracking on projects
Attack ChainsEnable/disable attack path visualization
PortfoliosEnable/disable program-level organization
Assets ModuleEnable/disable centralized asset management
CVSS ScoringEnable/disable vulnerability scoring fields
Remediation PlansEnable/disable target remediation dates
SLAsEnable/disable automatic SLA assignment

Workflow Lifecycle Configuration

Configure how work flows through the platform. Set up approval stages, QA checkpoints, and process gates that match your quality and delivery requirements.

Project Workflow Options

ConfigurationDescription
Project Request ApprovalRequire approval before projects are created
Multi-Stage ApprovalConfigure approval chains
Auto-Approval RulesAutomatically approve requests meeting criteria

Vulnerability Workflow Options

ConfigurationDescription
Default VisibilityNew vulns start as "Visible" or "Pending" (for QA)
QA Review RequiredRequire review before vulns are visible to clients
Retest RoundsConfigure how retesting cycles work

Default Value Configuration

Set sensible defaults that match your standard practices. Reduce repetitive data entry by pre-configuring values that apply to most of your projects and vulnerabilities.

Default SettingDescription
Project Name FormatDefault naming convention for new projects
Project Code FormatDefault code pattern (auto-incrementing available)
Default Scoring SystemCVSSv3.1, CVSSv4.0 or custom
Default Project GroupsGroups automatically assigned to new projects
Default Team NotificationsWhich emails team members receive by default
Placeholder Steps to ReproduceTemplate text for new vulnerabilities
Placeholder NotesTemplate text for vulnerability notes
......

Rule Based Automation

Automate policy enforcement with intelligent rules. From SLA assignment to email notifications, configure rules that trigger automatically based on your defined conditions. No manual intervention required.

Rule Based SLAs

Automatically assign remediation SLAs to vulnerabilities based on configurable rules. Match SLAs to severity, asset criticality, compliance requirements, or any combination of conditions.

Rule Configuration Options

Condition TypeDescriptionExample
SeverityVulnerability priority levelCritical, High, Medium, Low, Info
Asset TagsTags assigned to affected assets"Production", "PCI-Scope", "Internet-Facing"
Custom FieldsAny custom field value"Environment = Production"
GroupsProject or asset group membership"Finance Systems", "Client: Acme"
Vulnerability TagsTags on the vulnerability"Exploitable", "CISA-KEV"

SLA Configuration

SettingDescription
Days to RemediateNumber of days for SLA
Max Date OptionAbsolute deadline (e.g., end of quarter)
Auto-ApplyAutomatically apply to new vulnerabilities
Manual OverrideAllow manual SLA assignment/changes
Bulk Re-ApplyRecalculate SLAs across existing vulnerabilities

Rule Examples

RULE 1: Critical + Production = 7 days
IF Severity = Critical AND Asset Tag = "Production"
THEN SLA = 7 days
RULE 2: High + PCI Scope = 14 days
IF Severity = High AND Asset Tag = "PCI-Scope"
THEN SLA = 14 days
RULE 3: Critical + Compliance Project = 5 days with Max Date
IF Severity = Critical AND Custom Field "Compliance" = "PCI"
THEN SLA = 5 days, Max Date = End of Quarter

Rule Based Email Notifications

Configure intelligent email notifications triggered by conditions you define. Create automated escalations, reminders, and alerts based on vulnerability status, SLA timelines, project events, or custom criteria.

Trigger Conditions

Trigger TypeDescription
SLA StatusApproaching SLA, SLA breached
Vulnerability StatusOpen, Ready for Retest, Closed
Remediation Plan StatusApproaching date, overdue
Time-BasedVulnerabilities created/updated in past X hours/days
SeverityCritical, High, Medium, Low, Info
Custom Field ValuesAny custom field matching criteria
Custom TagsVulnerabilities with specific tags

Recipient Options (20+ audiences)

Project Team (all members)
Project Coordinators only
Administrators
Specific Roles
Specific Groups
Individual Users
Vulnerability Owners
Asset Owners
Remediation Owners
Custom Email Distribution Lists

Email Personalization

Every recipient receives a personalized email showing only vulnerabilities and projects they have access to (by default). Custom access checks when needed.

Scheduled Update Emails

Keep stakeholders informed with automated scheduled summaries. Configure daily or weekly digest emails that provide dashboard-style overviews of projects, vulnerabilities, and SLA status.

Update TypeDescriptionAudience
Daily Project UpdatesSummary of project activityProject teams
Weekly Project UpdatesWeekly rollup of progressProject teams
Daily Admin UpdatesPlatform-wide activity summaryAdministrators
Weekly Admin UpdatesWeekly platform overviewAdministrators
SLA SummaryVulnerabilities approaching/breaching SLAsConfigurable
Vulnerability SummaryNew findings over defined periodConfigurable

What's Included

Projects started/completed
Vulnerabilities found/closed
SLA compliance status
Testing progress
Team activity
Overdue items

Reporting Customization

Control every aspect of your reporting. From who can access which templates to completely custom report designs with ReportGen.

Report Access Controls

Control which users can access which report templates and formats. Segment reports by audience. Executive summaries for leadership, technical details for remediation teams, compliance packs for auditors.

ControlDescription
Template Access by RoleRestrict templates to specific application roles
Template Access by GroupLimit templates to group members
Template Access by UserAssign templates to individual users
Client User RestrictionsDifferent templates for client vs. internal users

Use Cases

  • Executive templates visible only to Admins and Project Coordinators
  • Client-branded templates available only to specific client groups
  • Technical templates for internal testers only
  • Compliance templates restricted to GRC team

ReportGen - Custom Report Templates

Create fully customized DOCX report templates with ReportGen. Use your existing Word templates and add ReportGen tags to dynamically populate project data, vulnerabilities, charts, and custom fields.

FeatureDescription
DOCX-BasedBuild templates in Microsoft Word - no coding custom styles required
Dynamic Data Tags200+ tags for projects, vulns, assets, custom fields
Conditional LogicShow/hide sections based on data conditions
Charts & GraphsBar charts, pie charts, line charts from project data
Dynamic TablesAuto-populated vulnerability tables
Custom StylingFull control over fonts, colors, layouts
Loops & IterationsRepeat sections for each vuln, asset, or test case
Filters & FunctionsTransform and format data in templates
Multiple TemplatesCreate unlimited templates for different purposes

Template Examples

  • Executive Summary (2-3 pages, high-level metrics)
  • Technical Report (detailed findings, steps to reproduce)
  • Compliance Report (mapped to framework controls)
  • Remediation Tracking (status-focused for dev teams)
  • Client-Branded Report (per-client logos and styling)
  • Retest Report (remediation verification results)

Automation Options

MethodUse Case
ReportGen CLICommand-line report generation for scripting
ReportGen Node.js LibraryEmbed in custom applications
REST APIProgrammatic generation from any system
Flows IntegrationTrigger report generation on events

Import & Data Mapping

Standardize data from any source. AttackForge supports imports from dozens of scanners and tools, with custom mapping rules to transform external data into your internal taxonomy.

Custom Import Mapping

Define rules that control how imported vulnerability data maps to your writeup libraries and standards. Transform scanner output into consistent, standardized findings automatically.

Mapping TypeDescription
Library MatchingMap imported vulns to existing writeup library entries
Severity MappingTranslate scanner severity to your severity scale
Field MappingMap scanner fields to AttackForge fields
Custom Field PopulationAuto-populate custom fields from import data
Tag AssignmentAutomatically tag vulnerabilities based on import data

Smart Mapping Rules

RULE: Map Nessus "Critical" to "Critical" and tag "Scanner: Nessus"
RULE: Map Burp "High" to "High" and set custom field "Tool" = "Burp Suite"
RULE: Match plugin ID to writeup library entry
RULE: Auto-assign to portfolio based on asset tag

Scanner & Tool Imports

Import vulnerability data from industry-leading scanners and tools. Native parsers transform tool output into standardized AttackForge findings.

Network Scanners

Nessus
Qualys
Tenable.io
Tenable.sc
Rapid7 Nexpose

Web App Scanners

Burp Suite
Acunetix
Invicti (Netsparker)
OWASP ZAP

Infrastructure

NMAP
Masscan

Code Analysis

Checkmarx
Various SAST tools via standard formats

Generic Formats

CSV
JSON

Grouped Asset Imports

Automatically consolidate multiple affected assets under single vulnerability entries during import. Reduce vulnerability count while preserving all affected asset data.

How It Works

Traditional Import
100 hosts with same vulnerability = 100 vulnerability entries
Grouped Import
100 hosts with same vulnerability = 1 vulnerability with 100 affected assets
Result: 99% reduction in vulnerability entries, same data preserved

Notifications & Communication

Control how, when, and what is communicated. From email templates to notification rules, configure every aspect of stakeholder communication.

Custom Email Templates

Brand your email communications and customize content for different scenarios. Every automated email can be tailored to match your communication standards.

Template Types

TemplatePurpose
Project InvitationInviting users to projects
Project Status UpdatesTesting started, completed, on-hold
Vulnerability NotificationsNew findings, status changes
Retest NotificationsRetest requested, completed
SLA NotificationsApproaching, breached
User RegistrationWelcome emails, password resets
Daily/Weekly SummariesScheduled digest emails
......

60+ Merge Tags for Dynamic Content

{project_name}- Project name
{vulnerability_count}- Number of vulnerabilities
{critical_count}- Critical severity count
{sla_date}- SLA deadline
{recipient_name}- Personalized recipient name
{custom_field_*}- Any custom field value

Notification Configuration

Granular control over which notifications are sent, to whom, and when. Configure at the platform level, project level, and individual user level.

Configuration Levels

LevelWhat It Controls
Platform DefaultsGlobal notification settings for all projects
Project SettingsOverride defaults for specific projects
User PreferencesIndividual user notification choices
Forced NotificationsAdmin-mandated notifications that can't be overwridden

Notification Events

Project created/started/completed/on-hold
Vulnerability created/updated/closed
Retest requested/completed
Comment added
File uploaded
User invited/role changed
SLA approaching/breached
Daily/weekly summaries

Access Control Customization

Distribute authority without losing control. AttackForge provides granular delegation capabilities and access controls that scale with organizational complexity.

Delegation Framework

Empower trusted users to perform administrative functions without granting full admin access. Delegate specific capabilities to roles or individual users.

DelegationWhat It Allows
Create ProjectsUser can create new projects, edit their projects, manage access
Action Pending Project RequestsView, edit, approve, reject project requests
Add Test Suites to ProjectsAdd/modify test suites on projects
Add Abuse Cases to ProjectsAdd/modify abuse cases on projects
Manage Group MembersAdminister group membership
Member AdministrationManage project team access (with configurable limits)
......

Group and Project Member Administration Controls

When delegating member administration, you can set boundaries:

Access Level Limit
Maximum access level they can assign
Add User Method
Dropdown selection or email entry
Allow User Invite
Can they invite new users to the platform

Application Roles

Four application roles with distinct module access and capabilities. Assign users to roles that match their responsibilities.

RoleDescriptionModule Access
AdministratorFull platform accessAll modules, all functions
Project CoordinatorProject management focusProjects, vulnerabilities, reporting, limited admin
ConsultantTesting and finding creationProjects assigned to, vulnerabilities, workspace
ClientView and remediation trackingView access to assigned projects

Project-Level Access Control

Three access levels control what users can see and do on each project. Assign appropriate access based on user responsibilities.

LevelCapabilities
ViewView vulnerabilities, generate reports, request retests, export to tools
UploadAll View capabilities + upload files, create project notes
EditAll Upload capabilities + create/edit vulnerabilities, action test cases, create attack chains, participate in QA, manage workspace and more

Access Assignment

Access can be assigned directly to individual users, inherited through Group membership, or delegated via Member Administration.

See the Configuration Depth
for Yourself

AttackForge is the most configurable offensive security platform available. Every feature on this page is ready to customize in a free trial. No limitations, no feature gates, full configuration access.

SOC 2 Type II CertifiedInstant DeploymentNo credit card required