Overview: Pentest Details
Last updated: October 11, 2026
Introduction
The Pentest Details page gives you a complete view of a single manual pentest. You can follow its progress, review and manage the vulnerabilities found, see who is testing your target, and check your security grade. To open it, click a pentest title on the Pentests page. The page title shows the pentest type and start date, along with the target being tested.
Key Functions
Summary cards: Three cards at the top show the number of Unsolved vulnerabilities, the number of Critical & High findings, and Loss Saved. The loss values are indicative estimates. Read Understanding Bounty Loss & Potential Loss to see how they’re calculated.
Progress: Shows the current status, the ETA or delivery date, and each stage of the pentest:
Start Scan
Credentials Verification
Vulnerability Scanning
Security Review
Verifying Vulnerabilities
Vulnerabilities Reported
Rescan
Pentest Completed
Certificate Awarded
Completed steps are checked off, and steps that aren’t needed show as Skipped. The ETA reflects when vulnerabilities will be reported to you.
Vulnerabilities: Lists the findings with Severity, Vulnerability Name, Risk, Reporter and Created At. Each finding carries a risk score to help you prioritize fixes. Findings are grouped by status:
Status | Meaning |
|---|---|
Unsolved | Fix these vulnerabilities, then request a re-scan |
Under Review | Being verified by Astra |
Need Help | Astra is reviewing your comments and will get back to you |
Solved | Verified as fixed, no further action needed |
Accepted Risk | You’ve accepted the risk |
Draft | Not yet published |
False Positive | Marked after internal review |
Pentesters: Shows the security engineers assigned to your pentest.
Details: Shows the pentest ID, status, target, type, coverage, source, start date, last updated date and who created it.
Security Grade: Shows your current grade and the vulnerabilities to fix to reach the next one.
Vulnerability Severity: Shows the breakdown of findings by severity and status.
Available Actions
Search, filter and sort: Find vulnerabilities by keyword, filter the list, sort by Risk Score, or adjust the displayed columns.
Open a vulnerability: Click a finding to see its details, impact and remediation recommendations.
Mark fixes for review: After fixing a vulnerability, mark it as Ready for Review so it can be included in a rescan.
Request a rescan: Click Rescan to have Astra’s security engineers verify your fixes. Before requesting one:
Mark every fixed vulnerability as Ready for Review.
Fix at least 50% of the critical and high vulnerabilities, so the engineers can verify as many fixes as possible in one pass.
Submit the request within 30 days of the vulnerabilities being reported.
Keep your rescan quota in mind while requesting for rescan
Track an active rescan in the Rescan step under Progress. For the full process, see How-To: Rescanning Vulnerabilities.
Download reports: Click Reports to generate a summary report of the pentest.
Get your certificate: Once the pentest is completed, a Get Certificate button appears on this page. The certificate is valid for 180 days.
Best Practices
Start with Critical & High findings, since fixing these improves your security grade fastest.
Fix several vulnerabilities before requesting a rescan, then mark each fixed one as Ready for Review, so you use your two rescans well.
Use Need Help to ask questions about a finding.
Check Progress regularly to see what stage your pentest has reached.
Treat Loss Saved and the loss values on findings as a reference for relative impact, not as a financial calculation.