Overview: Pentest Details

Last updated: October 11, 2026

Introduction

The Pentest Details page gives you a complete view of a single manual pentest. You can follow its progress, review and manage the vulnerabilities found, see who is testing your target, and check your security grade. To open it, click a pentest title on the Pentests page. The page title shows the pentest type and start date, along with the target being tested.

Key Functions

  • Summary cards: Three cards at the top show the number of Unsolved vulnerabilities, the number of Critical & High findings, and Loss Saved. The loss values are indicative estimates. Read Understanding Bounty Loss & Potential Loss to see how they’re calculated.

  • Progress: Shows the current status, the ETA or delivery date, and each stage of the pentest:

    1. Start Scan

    2. Credentials Verification

    3. Vulnerability Scanning

    4. Security Review

    5. Verifying Vulnerabilities

    6. Vulnerabilities Reported

    7. Rescan

    8. Pentest Completed

    9. Certificate Awarded

    Completed steps are checked off, and steps that aren’t needed show as Skipped. The ETA reflects when vulnerabilities will be reported to you.

  • Vulnerabilities: Lists the findings with Severity, Vulnerability Name, Risk, Reporter and Created At. Each finding carries a risk score to help you prioritize fixes. Findings are grouped by status:

Status

Meaning

Unsolved

Fix these vulnerabilities, then request a re-scan

Under Review

Being verified by Astra

Need Help

Astra is reviewing your comments and will get back to you

Solved

Verified as fixed, no further action needed

Accepted Risk

You’ve accepted the risk

Draft

Not yet published

False Positive

Marked after internal review

  • Pentesters: Shows the security engineers assigned to your pentest.

  • Details: Shows the pentest ID, status, target, type, coverage, source, start date, last updated date and who created it.

  • Security Grade: Shows your current grade and the vulnerabilities to fix to reach the next one.

  • Vulnerability Severity: Shows the breakdown of findings by severity and status.

Available Actions

  • Search, filter and sort: Find vulnerabilities by keyword, filter the list, sort by Risk Score, or adjust the displayed columns.

  • Open a vulnerability: Click a finding to see its details, impact and remediation recommendations.

  • Mark fixes for review: After fixing a vulnerability, mark it as Ready for Review so it can be included in a rescan.

  • Request a rescan: Click Rescan to have Astra’s security engineers verify your fixes. Before requesting one:

    • Mark every fixed vulnerability as Ready for Review.

    • Fix at least 50% of the critical and high vulnerabilities, so the engineers can verify as many fixes as possible in one pass.

    • Submit the request within 30 days of the vulnerabilities being reported.

    • Keep your rescan quota in mind while requesting for rescan

    Track an active rescan in the Rescan step under Progress. For the full process, see How-To: Rescanning Vulnerabilities.

  • Download reports: Click Reports to generate a summary report of the pentest.

  • Get your certificate: Once the pentest is completed, a Get Certificate button appears on this page. The certificate is valid for 180 days.

Best Practices

  • Start with Critical & High findings, since fixing these improves your security grade fastest.

  • Fix several vulnerabilities before requesting a rescan, then mark each fixed one as Ready for Review, so you use your two rescans well.

  • Use Need Help to ask questions about a finding.

  • Check Progress regularly to see what stage your pentest has reached.

  • Treat Loss Saved and the loss values on findings as a reference for relative impact, not as a financial calculation.

Related Articles