Advanced
Customization
The Most Configurable Offensive Security Management Platform Available
Switch workflows on and off. Adjust features to match how you want to work. Customize the application to your style and needs.
From whitelabelling to rule based SLAs, from custom fields to automated notifications, every aspect of AttackForge can be configured to match your exact requirements.
Everything You Can Customize
Click any category to jump to detailed configuration options
Branding & Appearance Customization
Make AttackForge look and feel like YOUR platform. From complete whitelabelling to interface preferences, control every visual aspect of the application.
Whitelabelling
Replace AttackForge branding with your own identity throughout the entire platform. Your logo appears on the login page, navigation bar, and throughout the interface. Clients and team members see YOUR brand, not ours.
| Configuration | Description |
|---|---|
| Company Logo | Upload your logo to appear throughout the application |
| Login Page Branding | Custom logo and messaging on the sign-in screen |
| Navigation Branding | Your identity in the main navigation bar |
| Favicon | Your icon in browser tabs |
Use Cases
- Security consultancies delivering branded client portals
- MSSPs providing white-glove service experiences
- Internal teams presenting professional interfaces to stakeholders
Custom Colours
Match AttackForge to your brand palette. Configure primary and accent colors to create a consistent visual experience that aligns with your corporate identity.
| Configuration | Description |
|---|---|
| Primary Color | Main brand color used throughout the interface |
| Accent Color | Secondary color for highlights and interactive elements |
| Navigation Color | Background color for the main navigation |
| Button Colors | Primary and secondary action button styling |
Dark Mode
Easy on the eyes during long testing sessions. Dark mode reduces eye strain and provides a modern interface preferred by security professionals.
| Configuration | Description |
|---|---|
| User Preference | Allow individual users to toggle their own preference |
Table View Customization
See the data that matters to you, the way you want to see it. Configure which columns appear, their order, and how data is displayed across all major tables in the application.
| Configuration | Description |
|---|---|
| Column Visibility | Show/hide columns based on your needs |
| Column Order and Scroll Lock | Drag and drop to arrange columns your way. Lock important columns on scroll |
| Default Sort | Set default sorting for each table |
| Advanced Search | Wildcard matches and glob patterns, Regular Expressions (Regex) |
| Custom Field Columns | Display your custom fields in tables |
| Date Format | US (MM/dd/YYYY) or International format |
Available On
Custom Fields & Forms
Capture the data that matters to YOUR organization. AttackForge supports extensive custom field creation across projects, vulnerabilities, assets, writeups, portfolios, and project requests. With granular access controls for each field.
Custom Fields
Create custom data fields to capture information specific to your organization, compliance requirements, or client needs. Every custom field is available in reports and via the API.
Field Types Available
| Field Type | Description | Use Case Example |
|---|---|---|
| Input (Text) | Single-line text entry | Reference numbers, short identifiers |
| Textarea | Multi-line text entry | Extended notes, descriptions |
| Select (Dropdown) | Single selection from predefined options | Status categories, classifications |
| Multi-Select | Multiple selections from predefined options | Tags, applicable frameworks |
| Datepicker | Date selection | Target dates, review dates |
| Table | Tabular data with multiple columns | Configuration reviews, firewall rules |
| Rich-Text | Formatted text with WYSIWYG editor | Detailed notes that render in reports |
| User Select | Select users from the system | Owners, reviewers, assignees |
| Group Select | Select groups from the system | Team assignments, business units |
Where Custom Fields Can Be Added
Access Controls Per Field
Every custom field supports granular access controls:
VIEW ACCESS - Control who can see the field
- By Role (Admin, Project Coordinator, Consultant, Client)
- By Group
- By Individual User
EDIT ACCESS - Control who can modify the field
- By Role
- By Group
- By Individual User
Custom Forms
Build tailored forms for different clients, teams, or engagement types. Combine standard fields with custom fields to create the exact experience your organization needs.
| Configuration | Description |
|---|---|
| Enable/Disable Standard Fields | Hide fields you don't need |
| Add Custom Fields | Include your custom fields |
| Field Order | Arrange fields in logical sequence |
| Required vs. Optional | Set which fields must be completed |
| Conditional Display | Show/hide fields based on other field values |
| Default Values | Pre-populate fields with standard values |
| Form Access | Control which users/groups see which form configurations |
Use Cases
- Different intake forms for PTaaS subscribers vs. ad-hoc customers
- Simplified or detailed vulnerability forms for different types of tests
- Compliance-specific forms capturing required regulatory information
- Customer-specific forms with their unique metadata requirements
Linked Custom Fields
Automatically carry custom field values from project requests into created projects. When a project request is approved, linked fields populate automatically. No manual data entry required.
How It Works
Workflow Configuration
Switch workflows on and off. Enable only what your team uses. AttackForge lets you configure which modules are active, which features are available, and how processes flow - matching the platform to your operational model.
Module & Feature Toggles
Not every team uses every feature. AttackForge lets you enable or disable entire modules and individual features to create a streamlined experience focused on what your team actually needs.
| Module/Feature | What It Controls |
|---|---|
| Project Request Workflow | Enable/disable formal project intake process |
| QA Workflow | Enable/disable vulnerability review/approval stages |
| Retest Workflow | Enable/disable remediation verification process |
| Test Cases | Enable/disable methodology tracking on projects |
| Attack Chains | Enable/disable attack path visualization |
| Portfolios | Enable/disable program-level organization |
| Assets Module | Enable/disable centralized asset management |
| CVSS Scoring | Enable/disable vulnerability scoring fields |
| Remediation Plans | Enable/disable target remediation dates |
| SLAs | Enable/disable automatic SLA assignment |
Workflow Lifecycle Configuration
Configure how work flows through the platform. Set up approval stages, QA checkpoints, and process gates that match your quality and delivery requirements.
Project Workflow Options
| Configuration | Description |
|---|---|
| Project Request Approval | Require approval before projects are created |
| Multi-Stage Approval | Configure approval chains |
| Auto-Approval Rules | Automatically approve requests meeting criteria |
Vulnerability Workflow Options
| Configuration | Description |
|---|---|
| Default Visibility | New vulns start as "Visible" or "Pending" (for QA) |
| QA Review Required | Require review before vulns are visible to clients |
| Retest Rounds | Configure how retesting cycles work |
Default Value Configuration
Set sensible defaults that match your standard practices. Reduce repetitive data entry by pre-configuring values that apply to most of your projects and vulnerabilities.
| Default Setting | Description |
|---|---|
| Project Name Format | Default naming convention for new projects |
| Project Code Format | Default code pattern (auto-incrementing available) |
| Default Scoring System | CVSSv3.1, CVSSv4.0 or custom |
| Default Project Groups | Groups automatically assigned to new projects |
| Default Team Notifications | Which emails team members receive by default |
| Placeholder Steps to Reproduce | Template text for new vulnerabilities |
| Placeholder Notes | Template text for vulnerability notes |
| ... | ... |
Rule Based Automation
Automate policy enforcement with intelligent rules. From SLA assignment to email notifications, configure rules that trigger automatically based on your defined conditions. No manual intervention required.
Rule Based SLAs
Automatically assign remediation SLAs to vulnerabilities based on configurable rules. Match SLAs to severity, asset criticality, compliance requirements, or any combination of conditions.
Rule Configuration Options
| Condition Type | Description | Example |
|---|---|---|
| Severity | Vulnerability priority level | Critical, High, Medium, Low, Info |
| Asset Tags | Tags assigned to affected assets | "Production", "PCI-Scope", "Internet-Facing" |
| Custom Fields | Any custom field value | "Environment = Production" |
| Groups | Project or asset group membership | "Finance Systems", "Client: Acme" |
| Vulnerability Tags | Tags on the vulnerability | "Exploitable", "CISA-KEV" |
SLA Configuration
| Setting | Description |
|---|---|
| Days to Remediate | Number of days for SLA |
| Max Date Option | Absolute deadline (e.g., end of quarter) |
| Auto-Apply | Automatically apply to new vulnerabilities |
| Manual Override | Allow manual SLA assignment/changes |
| Bulk Re-Apply | Recalculate SLAs across existing vulnerabilities |
Rule Examples
THEN SLA = 7 days
THEN SLA = 14 days
THEN SLA = 5 days, Max Date = End of Quarter
Rule Based Email Notifications
Configure intelligent email notifications triggered by conditions you define. Create automated escalations, reminders, and alerts based on vulnerability status, SLA timelines, project events, or custom criteria.
Trigger Conditions
| Trigger Type | Description |
|---|---|
| SLA Status | Approaching SLA, SLA breached |
| Vulnerability Status | Open, Ready for Retest, Closed |
| Remediation Plan Status | Approaching date, overdue |
| Time-Based | Vulnerabilities created/updated in past X hours/days |
| Severity | Critical, High, Medium, Low, Info |
| Custom Field Values | Any custom field matching criteria |
| Custom Tags | Vulnerabilities with specific tags |
Recipient Options (20+ audiences)
Email Personalization
Every recipient receives a personalized email showing only vulnerabilities and projects they have access to (by default). Custom access checks when needed.
Scheduled Update Emails
Keep stakeholders informed with automated scheduled summaries. Configure daily or weekly digest emails that provide dashboard-style overviews of projects, vulnerabilities, and SLA status.
| Update Type | Description | Audience |
|---|---|---|
| Daily Project Updates | Summary of project activity | Project teams |
| Weekly Project Updates | Weekly rollup of progress | Project teams |
| Daily Admin Updates | Platform-wide activity summary | Administrators |
| Weekly Admin Updates | Weekly platform overview | Administrators |
| SLA Summary | Vulnerabilities approaching/breaching SLAs | Configurable |
| Vulnerability Summary | New findings over defined period | Configurable |
What's Included
Reporting Customization
Control every aspect of your reporting. From who can access which templates to completely custom report designs with ReportGen.
Report Access Controls
Control which users can access which report templates and formats. Segment reports by audience. Executive summaries for leadership, technical details for remediation teams, compliance packs for auditors.
| Control | Description |
|---|---|
| Template Access by Role | Restrict templates to specific application roles |
| Template Access by Group | Limit templates to group members |
| Template Access by User | Assign templates to individual users |
| Client User Restrictions | Different templates for client vs. internal users |
Use Cases
- Executive templates visible only to Admins and Project Coordinators
- Client-branded templates available only to specific client groups
- Technical templates for internal testers only
- Compliance templates restricted to GRC team
ReportGen - Custom Report Templates
Create fully customized DOCX report templates with ReportGen. Use your existing Word templates and add ReportGen tags to dynamically populate project data, vulnerabilities, charts, and custom fields.
| Feature | Description |
|---|---|
| DOCX-Based | Build templates in Microsoft Word - no coding custom styles required |
| Dynamic Data Tags | 200+ tags for projects, vulns, assets, custom fields |
| Conditional Logic | Show/hide sections based on data conditions |
| Charts & Graphs | Bar charts, pie charts, line charts from project data |
| Dynamic Tables | Auto-populated vulnerability tables |
| Custom Styling | Full control over fonts, colors, layouts |
| Loops & Iterations | Repeat sections for each vuln, asset, or test case |
| Filters & Functions | Transform and format data in templates |
| Multiple Templates | Create unlimited templates for different purposes |
Template Examples
- Executive Summary (2-3 pages, high-level metrics)
- Technical Report (detailed findings, steps to reproduce)
- Compliance Report (mapped to framework controls)
- Remediation Tracking (status-focused for dev teams)
- Client-Branded Report (per-client logos and styling)
- Retest Report (remediation verification results)
Automation Options
| Method | Use Case |
|---|---|
| ReportGen CLI | Command-line report generation for scripting |
| ReportGen Node.js Library | Embed in custom applications |
| REST API | Programmatic generation from any system |
| Flows Integration | Trigger report generation on events |
Import & Data Mapping
Standardize data from any source. AttackForge supports imports from dozens of scanners and tools, with custom mapping rules to transform external data into your internal taxonomy.
Custom Import Mapping
Define rules that control how imported vulnerability data maps to your writeup libraries and standards. Transform scanner output into consistent, standardized findings automatically.
| Mapping Type | Description |
|---|---|
| Library Matching | Map imported vulns to existing writeup library entries |
| Severity Mapping | Translate scanner severity to your severity scale |
| Field Mapping | Map scanner fields to AttackForge fields |
| Custom Field Population | Auto-populate custom fields from import data |
| Tag Assignment | Automatically tag vulnerabilities based on import data |
Smart Mapping Rules
Scanner & Tool Imports
Import vulnerability data from industry-leading scanners and tools. Native parsers transform tool output into standardized AttackForge findings.
Network Scanners
Web App Scanners
Infrastructure
Code Analysis
Generic Formats
Grouped Asset Imports
Automatically consolidate multiple affected assets under single vulnerability entries during import. Reduce vulnerability count while preserving all affected asset data.
How It Works
Notifications & Communication
Control how, when, and what is communicated. From email templates to notification rules, configure every aspect of stakeholder communication.
Custom Email Templates
Brand your email communications and customize content for different scenarios. Every automated email can be tailored to match your communication standards.
Template Types
| Template | Purpose |
|---|---|
| Project Invitation | Inviting users to projects |
| Project Status Updates | Testing started, completed, on-hold |
| Vulnerability Notifications | New findings, status changes |
| Retest Notifications | Retest requested, completed |
| SLA Notifications | Approaching, breached |
| User Registration | Welcome emails, password resets |
| Daily/Weekly Summaries | Scheduled digest emails |
| ... | ... |
60+ Merge Tags for Dynamic Content
{project_name}- Project name{vulnerability_count}- Number of vulnerabilities{critical_count}- Critical severity count{sla_date}- SLA deadline{recipient_name}- Personalized recipient name{custom_field_*}- Any custom field valueNotification Configuration
Granular control over which notifications are sent, to whom, and when. Configure at the platform level, project level, and individual user level.
Configuration Levels
| Level | What It Controls |
|---|---|
| Platform Defaults | Global notification settings for all projects |
| Project Settings | Override defaults for specific projects |
| User Preferences | Individual user notification choices |
| Forced Notifications | Admin-mandated notifications that can't be overwridden |
Notification Events
Access Control Customization
Distribute authority without losing control. AttackForge provides granular delegation capabilities and access controls that scale with organizational complexity.
Delegation Framework
Empower trusted users to perform administrative functions without granting full admin access. Delegate specific capabilities to roles or individual users.
| Delegation | What It Allows |
|---|---|
| Create Projects | User can create new projects, edit their projects, manage access |
| Action Pending Project Requests | View, edit, approve, reject project requests |
| Add Test Suites to Projects | Add/modify test suites on projects |
| Add Abuse Cases to Projects | Add/modify abuse cases on projects |
| Manage Group Members | Administer group membership |
| Member Administration | Manage project team access (with configurable limits) |
| ... | ... |
Group and Project Member Administration Controls
When delegating member administration, you can set boundaries:
Application Roles
Four application roles with distinct module access and capabilities. Assign users to roles that match their responsibilities.
| Role | Description | Module Access |
|---|---|---|
| Administrator | Full platform access | All modules, all functions |
| Project Coordinator | Project management focus | Projects, vulnerabilities, reporting, limited admin |
| Consultant | Testing and finding creation | Projects assigned to, vulnerabilities, workspace |
| Client | View and remediation tracking | View access to assigned projects |
Project-Level Access Control
Three access levels control what users can see and do on each project. Assign appropriate access based on user responsibilities.
| Level | Capabilities |
|---|---|
| View | View vulnerabilities, generate reports, request retests, export to tools |
| Upload | All View capabilities + upload files, create project notes |
| Edit | All Upload capabilities + create/edit vulnerabilities, action test cases, create attack chains, participate in QA, manage workspace and more |
Access Assignment
Access can be assigned directly to individual users, inherited through Group membership, or delegated via Member Administration.
See the Configuration Depth
for Yourself
AttackForge is the most configurable offensive security platform available. Every feature on this page is ready to customize in a free trial. No limitations, no feature gates, full configuration access.