Sign in

Faction Security

@factionsecurity.com
544 followers 2.9K following 43 posts

Faction is an open-source tool for: - Automated Pentest Reporting - Track Vulnerability Remediation - Collaborate With Your Team - and more www.factionsecurity.com #appsec #redteam #securitytools #cybersecurity #infosec #hacking

PostsRepliesMedia
Faction Security @factionsecurity.com · 24/09/2026
We just released some new pentesting reporting features into OWASP Faction! #pentest #appsec #owasp #redteam #cybersecurity #pentesttools blog.factionsecurity.com/blog/themabl...
blog.factionsecurity.com
Better Pentest Reports in Faction: Code Blocks, Mermaid Diagrams & Templates | FACTION Security Blog
New in Faction, the open-source pentest reporting tool: themable code blocks, Mermaid attack diagrams, and content templates that automate report writing.
011
Reposted by Faction Security
OWASP® Foundation @owasp.org · 11/09/2026
🎉 OWASP is 25! Celebrate with us! 🎁 Join OWASP in the next 25 days and get 1 FREE year's individual membership to gift to a friend. More people, more knowledge, more AppSec! 🔐 One membership. Twice the impact. bit.ly/OWASPBringaFr... #OWASP25 #AppSec #opensource
022
Faction Security @factionsecurity.com · 11/09/2026
Come see OWASP Faction at SecTor Arsenal 2026 in Toronto! blog.factionsecurity.com/blog/see-you... #pentesting #appsec #cybersecurity #vulnerabilitymanagment #blackhat #sector #owasp
blog.factionsecurity.com
See You at SecTor Arsenal 2026 in Toronto | FACTION Security Blog
We're heading back to Black Hat SecTor Arsenal on October 8th to demo OWASP Faction 2.0 live. Come say hi, grab some stickers, and tell us what would make your reporting workflow better.
012
Faction Security @factionsecurity.com · 09/09/2026
Our new #OWASP Faction Documentation portal is up! docs.factionsecurity.com #appsec #pentesting #aspm #redteam #vulnerabilitymanagement
docs.factionsecurity.com
Faction 2 Documentation
OWASP Faction is open source penetration testing management software. Automate pentest reporting from DOCX templates, write findings with AI, collaborate as a team, and track vulnerability remediation...
021
Faction Security @factionsecurity.com · 09/09/2026
Stop Writing Pentest Reports By Hand - Use Custom AI Prompts in OWASP Faction 2.0 #pentest #owasp #appsec #infosec #cybersecurity www.youtube.com/watch?v=d4nG...
youtube.com
Stop Writing Pentest Reports By Hand — Custom AI Prompts in Faction 2.0
YouTube video by Faction Security - Automate Pentest Reporting
041
Faction Security @factionsecurity.com · 06/08/2026
Thanks everyone for coming out to my OWASP Faction Talk at BlackHat Arsenal. It’s was amazing meeting everyone! #cybersecurity #owasp #pentesting #blackhat #bhusa26 #appsec #redteam
000
Faction Security @factionsecurity.com · 26/07/2026
We are so excited to be releasing OWASP Faction 2.0 at BlackHat Arsenal 2026!!! 🎉👾. If you do a lot of pentesting this this demo is for you! Come see us at 4pm Thurs at BlackHat. We got Stickers! #blackhat #bhusa #owasp #pentesting #redteam #cybersecurity www.linkedin.com/posts/blackh...
linkedin.com
#blackhat26 #blackhat #bhusa #owasp #pentesting #redteam #hacking #defcon #cybersecurity #vulnerabilitymanagment #opensource | Faction Security
We are so excited to be releasing OWASP Faction 2.0 at BlackHat Arsenal 2026!!! 🎉👾. This is a major update to our existing opensource pentesting collaboration platform. If you do a lot of pentesting ...
110
Faction Security @factionsecurity.com · 04/07/2026
✨We just made some important updates to the Faction Enterprise and Consulting platforms 🚀✨ These features help streamline pen testing and provide better integration with SSO. FACTION Enterprise 1.8.9 — Multi-Format PenTest Reports, Encrypted PDFs, and Faster SSO medium.com/@we-are-fact...
medium.com
FACTION Enterprise 1.8.9 — Multi-Format PenTest Reports, Encrypted PDFs, and Faster SSO
Your workflow shouldn’t slow you down when you’re already juggling assessments, client deadlines, and a team that needs answers fast. Over…
010
Faction Security @factionsecurity.com · 16/05/2026
OWASP Faction now has and MCP server! 🚀 It's really cool all the ways you an integrate agentic tools like OpenCode into you #pentesting workflow and automate reporting. Check out our video: www.youtube.com/watch?v=gxTG... #mcp #aicybersecurity #appsec #pentesting #redteam #llms #opencode #claude
youtube.com
Faction's New MCP Server to Automate Pentest Reporting with Agentic Workflows
YouTube video by Faction Security - Automate Pentest Reporting
051
Faction Security @factionsecurity.com · 01/03/2026
We just released Faction1.74!! 🧨 which has several improvements you’ve been asking for, like faster report generation and extra visibility features. #appsec #pentesting #redteam #vulnerability github.com/factionsecur...
github.com
GitHub - factionsecurity/faction: Pen Test Report Generation and Assessment Collaboration
Pen Test Report Generation and Assessment Collaboration - factionsecurity/faction
000
Faction Security @factionsecurity.com · 21/11/2025
Did you know you how easy it is to integrate your #pentest reporting into any other system, like GitHub or JIRA. We'll show you how you can vibe code your assessments using Faction Extensions! #appsec #pentesting #cysbersecurity #owasp #redteam #hacking we-are-faction.medium.com/vibe-coding-...
we-are-faction.medium.com
Vibe Coding Faction Extensions at PhreakNic 26
I just got back from speaking at PhreakNic 26 where I vibe coded a GitHub Faction Extension live while also speaking about my many…
021
Reposted by Faction Security
({({(Null Operator)})}) @null0perat0r.bsky.social · 12/11/2025
I just did a quick post about my #blackhat and #sector arsenal experiences this year. #opensource #bh2025 #sector2025 medium.com/@we-are-fact...
medium.com
Black Hat 2025 Arsenal Experience
I know this post is kind of late, but I’m just now getting around to posting about my Black Hat USA 2025 and SECTOR 2025 Arsenal…
031
Faction Security @factionsecurity.com · 27/10/2025
We just released OWASP Faction 1.7 with lots of new features and bug fixes to help automate manual penetration testing and make reporting even easier. we-are-faction.medium.com/owasp-factio... #pentesting #cybersecurity #applicationsecurity #redteam #hacking #appsec #owasp
we-are-faction.medium.com
OWASP Faction 1.7 — Major Updates for Enterprise Security Teams
For Enterprise Penetration Testing teams and Security Consulting Firms managing dozens — or hundreds — of assessments simultaneously…
044
Faction Security @factionsecurity.com · 01/10/2025
About to present Faction at SecTor Arsenal at 4 eastern. Hope to see you there. #appsec #blackhat #sectorca #redteam.
000
Faction Security @factionsecurity.com · 26/09/2025
Lots of new things coming to Faction 2.0 Very Soon. We are excited to share a little preview. Follow us for more updates. #pentesting #appsec #redteam #hacking #vulnerabilitymanagement
011
Faction Security @factionsecurity.com · 26/09/2025
I'm excited to be presenting at SecTor Arsenal! I'll be demoing OWASP Faction, an open source pen-testing collaboration framework. Hope to see you there! #SECTORCA #appsec #owasp #cybersecurity #blackhat #pentesting
021
Faction Security @factionsecurity.com · 08/08/2025
Great views from the level up party last night. #blackhat2025 #blackhat.
020
Reposted by Faction Security
({({(Null Operator)})}) @null0perat0r.bsky.social · 06/08/2025
Greetings from BlackHat 2025! If you’re attending this year come check out my talk on OWASP Faction, Thursday at noon - Arsenal station 3! #pentesting #owasp #hacking #blackhat2025 #redteam #appsec
242
Reposted by Faction Security
({({(Null Operator)})}) @null0perat0r.bsky.social · 08/08/2025
#BlackHat Arsenal was awesome!!! 🎉🎉🎉🍺🍺🍺Thanks to all that came to my talk. I forgot to bring stickers with me but will be giving them out at #Defcon. Look for them in the usual spots or DM me. #owasp #appsec #redteam #pentesting @factionsecurity.com
055
Faction Security @factionsecurity.com · 08/07/2025
🎉 I'm excited to be presenting Faction at BlackHat Arsenal 2025! 🚀 Come by Thursday Aug 7th 12-12:55 am to see what Faction can do for you and get some STICKERS!!! #hacking #pentesting #blackhat #BH2025 #appsec www.blackhat.com/us-25/arsena...
032
Faction Security @factionsecurity.com · 08/07/2025
🎉 Faction 1.6 is Here — Powerful New Features for Open Source and Enterprise Users Lots of updates that brings major improvements that make #pentest reporting more flexible and tailored to your needs. docs.factionsecurity.com/blog/2025/07... #appsec #redteam #opensource #cybersecurity #hacking
032
Faction Security @factionsecurity.com · 02/06/2025
🚀 OWASP Faction 1.5.2 is live! This is a major update with improvements to help you deliver more streamlined and professional assessments. What’s new? ✅ Checklist Improvements 🔐 SAML Authentication 📝 Better Markdown Handling github.com/factionsecur... #AppSec #Cybersecurity #OWASP #redteam
github.com
Releases · factionsecurity/faction
Pen Test Report Generation and Assessment Collaboration - factionsecurity/faction
010
Reposted by Faction Security
Tib3rius @tib3rius.bsky.social · 12/05/2025
10 Burp extensions I actually use... BUT none of them are in the top 30 most popular in the BApp Store! I get tired of seeing the same extensions come up in "top 10" lists. Here are some hidden gems you might not have tried... yet. In no particular order. 🧵👇
1111
Faction Security @factionsecurity.com · 05/03/2025
Happy to announce that Faction is now an #OWASP Project!!! 🚀 #appsec #applicationsecurity #pentesting #vulnerability #cybersecurity #redteam #hacking owasp.org/www-project-...
owasp.org
052
Faction Security @factionsecurity.com · 04/01/2025
It’s a new year and time to start the year off right by automating your manual #pentest with Faction. 🎉🍾💥 We got a lot of cool stuff planned for this year! We’ll be releasing more info in the coming months. Stay tuned! #appsec #redteam #hacking www.factionsecurity.com
factionsecurity.com
Automate Pentest Reports and AppSec Posture Management (ASPM)
Automate PenTest Reporting and AppSec Posture Management (ASPM) for penetration testers, red teams, and application security teams.
051
Faction Security @factionsecurity.com · 25/12/2024
Happy holidays from us at Faction Security!!! 🎄🤶🎁 Hope you get some downtime so you hack all the things next year! #cybersecurity
010
Faction Security @factionsecurity.com · 19/12/2024
We just released Faction 1.4! 🚀 If you're currently using Enterprise or Teams versions, then you have already been upgraded 🎉 This release includes bug fixes in pentest report peer reviews and fixes several CVE's. Find out more: www.factionsecurity.com #appsec #redteam #hacking #cybersecurity
factionsecurity
031
Faction Security @factionsecurity.com · 11/12/2024
We published a blog post on how to automate boilerplate text in your #pentesting reports using the #opensouce security tool, Faction. Check out the link below! we-are-faction.medium.com/automate-pen... #appsec #infosec #redteam #pentest #hacking #hacking-tools #security-tools
we-are-faction.medium.com
Automate PenTest Reports with Boilerplates
If you have been doing penetration testing for any length of time, you probably have a personal database of vulnerability descriptions…
191
Reposted by Faction Security
Spix0r @spix0r.bsky.social · 07/12/2024
I've developed a Python tool called Fback that generates wordlists for fuzzing backup files. It takes a JSON-based pattern file and a seed wordlist as input and produces a target-specific wordlist as output. Github: github.com/Spix0r/Fback #bugbounty #bugbountytools #cybersecurity
github.com
GitHub - Spix0r/fback: This is a useful Python script for generating a target specific wordlist for fuzzing backup files.
This is a useful Python script for generating a target specific wordlist for fuzzing backup files. - Spix0r/fback
031
Faction Security @factionsecurity.com · 08/12/2024
Hey #cybersecurity, we are building opensource tools to help streamline #pentesting assessments. We realize every company is different. We want to know where your pain points are and what would make your life as a #pentester easier. Reply or DM us your feedback. #infosec #appsec #redteam
250
Reposted by Faction Security
Slashdot @slashdot.org · 03/12/2024
Slashdot is now on Bluesky!
1417940
Faction Security @factionsecurity.com · 02/12/2024
This was one of our favorite talks from #defon32. This is a really clever approach to getting SQL injection at the protocol level. #appsec #sqlinjection #hacking #applicationsecurity www.youtube.com/watch?v=Tfg1...
youtube.com
DEF CON 32 - SQL Injection Isn't Dead Smuggling Queries at the Protocol Level - Paul Gerste
YouTube video by DEFCONConference
051
Faction Security @factionsecurity.com · 29/11/2024
Happy thanksgiving for all that celebrate! 🦃
000
Reposted by Faction Security
Grype @grypeproject.bsky.social · 21/11/2024
We're 🌟live🌟 in five, working on Open Source. 🌱 Join us with questions, comments & your important Syft & Grype bugs! 🐞 www.youtube.com/watch?v=hCRt... #sbom #opensource #security
youtube.com
21st November | Open Source Gardening | Live with Anchore Devs
YouTube video by Anchore
011
Reposted by Faction Security
Women In Cybersecurity Community Association @womenofwicca.bsky.social · 22/11/2024
Ready to level up your cybersecurity skills? 💻📈 Mireia Cano teaches us how to build an AppSec program at #WICCON2024! Level up here: www.youtube.com/watc... #CyberSecurity #WomenInTech
youtube.com
Building An Appsec Program From Scratch - Mireia Cano
Building an Appsec Program from Scratch In today's digital landscape, application security is crucial for safeguarding sensitive data and maintaining user trust. Without a robust AppSec program, or with one poorly implemented, chaos can ensue, leading to vulnerabilities and breaches. This talk explo
083
Faction Security @factionsecurity.com · 22/11/2024
We got a story up on @medium.com! Learn out how to create your first #pentest report using Faction: we-are-faction.medium.com/how-to-autom... #appsec #redteam #informationsecurity #infosec #pentesting #ethicalhacking
we-are-faction.medium.com
How to Automate Pentest Reporting Using Faction
Faction is an open-source security assessment collaboration framework designed to streamline and enhance your security workflows. With…
000
Reposted by Faction Security
Whitney Merrill @wbm312.bsky.social · 21/11/2024
Must read of the week: Ronan Farrow is looking at how governments (including the US) use spyware tech on individuals, activists, and journalists. www.newyorker.com/news/news-de...
newyorker.com
The Technology the Trump Administration Could Use to Hack Your Phone
Other Western democracies have been roiled by the use of spyware to target political opponents, activists, journalists, and other vulnerable groups. Could it happen here?
38032
Faction Security @factionsecurity.com · 20/11/2024
When building your #pentest reports, Do you prefer CVSS scoring, critical/high/med/low, or something else to explain the severity of a finding? #appsec #infosec #redteam #infosec
120
Reposted by Faction Security
BleepingComputer @bleepingcomputer.com · 20/11/2024
Cybercriminals have devised a novel method to cash out from stolen credit card details linked to mobile payment systems such as Apple Pay and Google Pay, dubbed 'Ghost Tap,' which relays NFC card data to money mules worldwide. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
New Ghost Tap attack abuses NFC mobile payments to steal money
Cybercriminals have devised a novel method to cash out from stolen credit card details linked to mobile payment systems such as Apple Pay and Google Pay, dubbed 'Ghost Tap,' which relays NFC card data...
142
Reposted by Faction Security
TechCrunch @techcrunch.com · 19/11/2024
GitHub launches $1.25M open source fund with a focus on security
tcrn.ch
GitHub launches $1.25M open source fund with a focus on security
The open source funding problem is very real, but a slew of initiatives have emerged of late, with startups, corporations, and venture capitalists launching various programs to support some of the most critical projects via equity-free financing. Today…
29613
Reposted by Faction Security
SirAppSec @sirappsec.bsky.social · 20/11/2024
Checkout my vulnerable web application, allows security teams to verify tools, educate developers and hone their skills! github.com/SirAppSec/vu...
github.com
GitHub - SirAppSec/vuln-node.js-express.js-app: A Very Vulnerable Node.js Express.js Web Application and API. Used for testing Security tools, Application security and penetration testing. Using Swagg...
A Very Vulnerable Node.js Express.js Web Application and API. Used for testing Security tools, Application security and penetration testing. Using Swagger, Sqlite, Sequelize. - SirAppSec/vuln-node....
1154
Reposted by Faction Security
BleepingComputer @bleepingcomputer.com · 19/11/2024
Spotify playlists and podcasts are being abused to push pirated software, game cheat codes, spam links, and "warez" sites. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Spotify abused to promote pirated software and game cheats
Spotify playlists and podcasts are being abused to push pirated software, game cheat codes, spam links, and "warez" sites. By injecting targeted keywords and links in playlist names and podcast descri...
031
Faction Security @factionsecurity.com · 18/11/2024
Oh hey #infosec! We have a Black Friday deal for you. If you signup for Faction Enterprise before Dec 1, you get 20% off for the first year no matter how big your team is. Faction will reduce your time writing #pentest reports by 70% or more. www.factionsecurity.com.
factionsecurity.com
Open-Source Pentest Report Generation Framework
Automate PenTest Reporting and Enable Collaboration for Penetration Testers, Red Teams, and Application Security Teams.
020
Faction Security @factionsecurity.com · 17/11/2024
If you hate writing #pentest / #vulnerability reports then we have #securitytools for you! You can download Faction here: github.com/factionsecur.... We are looking for feedback. We want to make #pentesting easier and give you more time to hack! #cybersecurity #opensource #redteam #hacking
github.com
GitHub - factionsecurity/faction: Pen Test Report Generation and Assessment Collaboration
Pen Test Report Generation and Assessment Collaboration - factionsecurity/faction
073
Faction Security @factionsecurity.com · 17/11/2024
We've adding new features to our #pentest report plugins! Now you can customize report graphics to match your assessment style 🚀 . Check out Faction here: github.com/factionsecur... Chart plugin here: github.com/factionsecur... #appsec #infosec #cybersecurity #security
021
Reposted by Faction Security
Learn Linux with Dan @dan-nanni.bsky.social · 16/11/2024
Internet of Things (IoT) platforms offer a complete set of tools and libraries for connecting to various #IoT devices, such as sensors, actuators, and gateways, and for managing these smart devices and their communication. Here are some available #opensource IoT platforms 😎👇 #smarthome
1132
Reposted by Faction Security
MiguelHzBz @miguelhzbz.bsky.social · 16/11/2024
EMERALDWHALE, a large-scale global campaign exploiting exposed Git configurations. This sophisticated operation led to the theft of over 15,000 cloud service credentials and impacted more than 10,000 private repositories. #CyberSecurity #CloudSecurity #ThreatIntelligence
sysdig.com
EMERALDWHALE:  15k Cloud Credentials Stolen in Operation Targeting Exposed Git Config Files
EMERALDWHALE is an operation targeting exposed Git configurations, resulting in more than 15,000 cloud service credentials stolen.
072
Reposted by Faction Security
Nicolas Grégoire @agarri.fr · 15/11/2024
OMG, it's so easy!! 🤩 docs.bsky.app/docs/get-sta...
docs.bsky.app
Get Started | Bluesky
Make your first post to the Bluesky app via the API in under 5 minutes.
0101
Reposted by Faction Security
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 16/11/2024
🔒 Ready to mature your AppSec program? Check out my talk from DEF CON, where I break down three key maturity levels and actionable steps to boost your security. securityboulevard.com/2024/10/def-...
0175