D-DRA
Dradis
Platform for centralizing evidence and assembling the engagement report.
OVERVIEW
Dradis centralizes the evidence generated during an engagement: it imports output from Nmap, Burp, Nessus, and other tools via plugins, and organizes it into a project structure of nodes and findings.
A reusable issue library standardizes how each finding type is described across projects, and export templates generate the final report in the format the client expects.
USE CASES
Practical use cases
- 01
Consolidating output from multiple tools into a single per-project evidence repository.
- 02
Standardizing how recurring findings are written up via the issue library.
- 03
Splitting documentation work across several team members on the same project.
- 04
Exporting a final client-ready report with a consistent template.
QUICK START
When the technical work is done and findings, evidence, and remediation need to become a coherent deliverable.
- Create a new project and define the node structure (hosts, applications) for the scope.
- Import the output of the tools used during the engagement via the matching plugins.
- Tag and describe each finding using the issue library as a base.
- Export the report with the template agreed on with the client.
BEFORE YOU RUN IT
What to check before running it
The Community edition lacks multi-user collaboration and some integrations that the paid Pro tier includes.
Evidence is centralized in a single instance: apply retention and deletion per the client's NDA.
Import plugins don't cover every tool; manually review anything that doesn't import automatically.