You're spending six figures on pentesting.
Can you prove it's working?
AttackForge delivers the analytics to slice your program across every dimension, trend data that proves whether you're improving or declining, and real-time dashboards that give every stakeholder, from the board to the engineering teams, the view they need.
Analyze your offensive security across every dimension that matters: time, teams, compliance, and technology
Security leaders are drowning in pentest reports but starving for insight. Raw vulnerability counts are not a security posture. Without the ability to slice your program across all of these dimensions simultaneously, you're stuck stitching together spreadsheets and hoping the story holds up under scrutiny.
Time
You can't prove whether your program is improving or declining without historical comparison.
AttackForge Analytics supports filtering by any time period: week, month, quarter, year, or custom date ranges, with pre-defined and custom filters. Measure whether remediation is improving over time. Track Mean-Time-to-Remediate (MTTR) across any period.
Outcome: You can prove to the board that your program is getting better, or identify exactly when and where it started falling behind, backed by hard data, not opinions.
Teams & Business Units
When you manage multiple vendors, divisions, or geographies, aggregated metrics hide the performers and the laggards.
Groups allow segmentation by divisions, vendors, geographies, clients, or suppliers. Portfolios consolidate related testing activities into Work Streams, organized by platform, region, compliance obligation, security program, or any structure that matches your organization. Every Portfolio and every Stream has its own unique dashboard with vulnerability data, project data, and asset data.
Outcome: You know which business unit is remediating fastest, which vendor is falling behind on SLAs, and where to allocate resources next, without asking anyone for a status update.
Compliance
Auditors ask if you tested against specific regulatory requirements. Spreadsheets can't answer that question reliably.
Test Suites come pre-loaded with industry benchmarks from OWASP, MITRE, OSSTMM, CIS and more. These enforce what gets tested and how, every time. Track pass/fail rates against regulatory frameworks across all projects.
Outcome: You discover compliance gaps before auditors do. You demonstrate testing coverage against specific regulatory requirements on demand, not three weeks after someone asks.
Technology & Assets
Without asset-level tracking, you can't answer the question: which systems are most exposed?
The Assets module provides centralized tracking and management of all assets under test. Assets can be categorized, tagged, and enriched with custom fields with configurable access controls. Load assets from external systems. Drill down to see exactly where risk concentrates across your technology estate.
Outcome: You know which systems, applications, and endpoints carry the most unresolved risk, and you can prove you tested them.
Trend Analysis & Comparison
AttackForge's advantage for visibility
This is not just filtering. This is side-by-side comparison of any two time periods, filtered by group, portfolio, or organization. Users click the Compare button in Analytics to compare last year vs. this year, last quarter vs. this quarter, or any two custom periods.
Critical Vulnerabilities
Q3 2025
47
Q4 2025
19
Mean Time to Remediate
Q3 2025
34 days
Q4 2025
12 days
SLA Compliance
Q3 2025
61%
Q4 2025
89%
Outcome: Subjective opinions become hard evidence. When the board asks "Are we getting better?" you answer with a comparison chart, not a confidence interval. When auditors ask for year-over-year improvement, you show it in two clicks.
Questions your board is already asking
AttackForge Analytics answers them instantly
How many open critical vulnerabilities on exposed internet-facing systems do we have right now?
Are we getting better or worse at remediating issues?
Which business unit has the most unresolved risk?
Are our vendors meeting their remediation SLAs?
What is our mean-time-to-remediate for critical and high findings?
Have we tested everything that regulators require this quarter?
Visualize security insights from every angle
When you have hundreds or thousands of vulnerabilities across your program, you need the signal, not the noise. Leaders need to instantly see where risk concentrates: which assets are weakest, which security controls keep failing, and which vulnerability types keep recurring.
Identify which systems, applications, or endpoints carry the most risk across your entire organization, business group, or client. Drill down by group or time period to track whether asset risk is being addressed or growing.
See which test cases from your testing methodologies (OWASP, NIST, PCI, etc.) are failing most frequently across all projects in your program. This reveals systemic weaknesses, not individual bugs, but patterns in development practices or security controls that fail repeatedly.
Understand which vulnerability types appear most frequently across your estate. This helps prioritize developer training, security tooling investments, and architectural improvements where they will have the greatest impact.
Track how many vulnerabilities are within SLA, approaching breach, or overdue. AttackForge supports rule-based SLAs (configurable in Administration) that automatically assign remediation timelines matching your internal policies for every vulnerability.
76%
Within SLA
18%
Approaching
6%
Breached
Configured SLA Timeframes
Every one of these analytics widgets can be filtered by time period and by group, so you can view the Top 10 for a specific business unit, a specific quarter, a specific vendor, or any combination. All analytics can be clicked on to see the underlying data for further analysis.
Build custom dashboards with AI assistants
Pre-built analytics are powerful, but every security leader has bespoke questions unique to their organization, questions that don't fit neatly into a standard widget. What if you could just ask for the dashboard you need in plain language and get it built from your live vulnerability data in seconds?
Natural Language Dashboard Creation
Create an interactive vulnerability composition dashboard for all open critical and high findings, grouped by OWASP Top 10 category.
Pulling live data from AttackForge...
- Found 147 open vulnerabilities across 23 active projects
- Classified by OWASP Top 10 categories
- Generated interactive HTML dashboard
[RENDERED: Interactive dashboard with radar chart, severity heatmap, and drill-down by business unit]
Add MTTR trends and identify the single highest-risk vulnerability across the entire program.
Analyzing remediation timelines and risk scores...
Highest risk: "Unauthenticated API endpoint exposing PII"
Asset: api.payments.internal | Severity: Critical
Days open: 47 | SLA Status: Breached (40 days overdue)
✓ Added MTTR trend cards to dashboard
✓ Highlighted highest-risk finding with direct link to AttackForge
Natural Language Queries
Ask questions about vulnerabilities, projects, and assets in plain English. No scripting, no query syntax, no export-and-pivot workflows. Ask and get answers from your live AttackForge data.
Interactive Charts & Dashboards
Generate vulnerability composition metrics, radar charts, severity heatmaps, and trend visualizations, rendered as interactive HTML you can share, embed, or present.
Your Data Stays Yours
With MCP, sensitive vulnerability data is not sent to other AI providers for training. Your AI accesses your data only when needed and only for your specific requests. Every MCP tool must be explicitly enabled by an AttackForge administrator on a per-user basis.
Executive Summaries on Demand
Generate executive summaries, vulnerability descriptions and recommendations, and review vulnerabilities in retest, all contextualized to your actual program data.
Supported AI Providers
MCP is provider-agnostic. You are not locked into a specific AI provider. You can switch AI assistants while keeping all your integrations working.
MCP is available with AttackForge Enterprise. For AttackForge Core, MCP can be added from Administration → Subscriptions. Enable from Administration → Integrations.
Integrate with data visualization platforms
Security data that lives in a silo is security data that gets ignored. The executives who control budget and prioritization already have dashboards they check every morning in Power BI, Tableau, or other BI tools. AttackForge bridges this gap by making your offensive security data available wherever decisions happen.
Connect via Flows or REST API
AttackForge Flows enables automated data pipelines triggered by real-time events: new vulnerability discovered, SLA breached, project completed, vulnerability updated, retest requested, and more. Alternatively, query 150+ REST API endpoints directly via the Self-Service RESTful API (OpenAPI v3 compliant), plus the Self-Service Events API for real-time push-based updates.
Shape and filter your data
Advanced query filters on the Self-Service API let you select the exact dataset you need. Filter by priority, status, group, date range, custom fields, and more using structured filter syntax. Support for CSV export and JSON consumption, both compatible with direct ingestion into any BI tool.
Build executive dashboards
Once data flows into Power BI, Tableau, or any BI platform, security teams can build: vulnerability trend dashboards, SLA compliance scorecards, risk heatmaps by business unit, remediation velocity charts, and any custom visualization their stakeholders require. Auto-refresh using the Events API keeps dashboards always current.
Share across the business
When security data lives in the same BI platform as finance, operations, and compliance, security posture becomes a first-class business metric, not a PDF buried in someone's inbox. Security gets a seat at the table because the data is where the decisions are already being made.
Supported Integration Platforms
Stop guessing. Start proving it.
Full visibility into your offensive security program, from day one, with minimal setup required.