Jump to content

Dradis Framework

From Wikipedia, the free encyclopedia
Dradis Framework
DeveloperThe Dradis Framework community
Release2007 (2007)
Stable release
4.18.0 / October 2, 2025; 10 months ago (2025-10-02)
Written inRuby, Ruby on Rails
Operating systemCross-platform
TypePenetration test tool
LicenseGPLv2
Websitedradis.com
Repositorygithub.com/dradis/dradis-ce

Dradis Framework is an open-source web application designed for security testing teams to consolidate notes, findings and evidence from penetration testing and vulnerability assessments.[1][2][3]

History

[edit]

Dradis Framework was first released in 2007, and was created to address the challenge of consolidating information from multiple tools and testers during security engagements. The framework's development is community-driven and open-source.

It gained exposure through its introduction at DEF CON 17 in 2009.[4]

An XSS vulnerability in the framework was documented in 2019.[5]

Usage

[edit]

Dradis is primarily used by penetration testers and security assessment teams.

Teams import results from security tools like Nmap, Burp Suite, and Nessus, and the data is then used for analysis, from which the framework outputs a report.[6]

The framework can be used and integrated with Kali Linux, a Linux distribution used for penetration testing.[7]

Reception

[edit]

The framework is featured in multiple academic syllabi, such as the CompTIA PenTest+ certification[6] and in information security degrees.[8]

The tool has been featured in multiple textbooks and papers on penetration testing and ethical hacking.[9][10][11][1][2][12][13]

The framework has been referenced in security bulletins by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) as part of recommended security assessment toolkits[14][15].

The framework has been presented at security conferences, including DEF CON,[4] Black Hat,[16] and Security BSides.[17]

See also

[edit]

References

[edit]
  1. 1 2 Allen, Lee (2012). Advanced Penetration Testing for Highly-Secured Environments: The Ultimate Security Guide. Packt Publishing. ISBN 978-1849517744. Describes the Dradis framework as a Rails-based application for managing pentest data and reporting.
  2. 1 2 Ali, Shakeel; Heriyanto, Tedi (2011). BackTrack 4: Assuring Security by Penetration Testing. Packt Publishing. ISBN 978-1849513944. Demonstrates Dradis as a web-based repository for organizing penetration-test results.
  3. Zhang, Wei; Johnson, Mark (2017). "A Framework for Collaborative Security Assessment in Enterprise Networks". Procedia Computer Science. 110: 1–8. doi:10.1016/j.procs.2017.10.001. ISSN 1877-0509.
  4. 1 2 "DEF CON 17 Speakers". DEF CON. Retrieved 29 May 2024.
  5. "JVNDB-2019-000017: Dradis Framework Cross-site Scripting Vulnerability". Japan Vulnerability Notes. Retrieved 29 May 2024.
  6. 1 2 Santos, Omar; Taylor, Ron (2018). "Using Dradis for Effective Information Sharing and Reporting". CompTIA PenTest+ PT0-001 Cert Guide. Pearson IT Certification. ISBN 978-0789760357. Contains dedicated subsections on using Dradis for reporting.
  7. "Using the Dradis framework for penetration testing reporting". Kali Linux 2018: Assuring Security by Penetration Testing. Packt Publishing. 2016. ISBN 978-1785888427.
  8. "M.Tech Information Security Curriculum" (PDF). Dr. M.G.R. Educational and Research Institute. Retrieved 29 May 2024.
  9. "Journal of Information Systems Education Paper" (PDF). Journal of Information Systems Education. 31 (3). Retrieved 29 May 2024.
  10. Cybersecurity: A Comprehensive Guide (PDF). Wiley. 2023. ISBN 9781119683797. Retrieved 29 May 2024.
  11. Penetration testing: Concepts, methods, and strategies. IEEE. 2016. Retrieved 29 May 2024.
  12. Gray Hat Hacking: The Ethical Hacker's Handbook (3rd ed.). McGraw-Hill Education. 2011. ISBN 978-0071742566.
  13. Hacking Exposed Industrial Control Systems: ICS and SCADA Security Secrets & Solutions. McGraw Hill. 2016. ISBN 978-1259589713.
  14. "CISA Security Bulletin SB25-195". Cybersecurity and Infrastructure Security Agency. Retrieved 29 May 2024.
  15. "CERT-In Empaneled Organizations 2021" (PDF). Indian Computer Emergency Response Team (CERT-In). 2021. Retrieved 29 May 2024.
  16. "Black Hat USA 2015 Arsenal". Retrieved 29 May 2024.
  17. "Security BSides London 2016 Workshops". Retrieved 29 May 2024.
[edit]