SecurityRiskAdvisors / VECTR

VECTR is a tool that facilitates tracking of your red and blue team testing activities to measure detection and prevention capabilities across different attack scenarios
1.36k stars 161 forks source link

[FEATURE REQUEST] Enable more granular management of access. #97

Open forkrul opened 3 years ago

forkrul commented 3 years ago

Allow the creation of per assessment access roles, read/write and blue team / red team only roles.

We also test across various teams, and these teams don't require insight into other ongoing projects.

PS. Thanks for MFA in the new release

SRAPSpencer commented 3 years ago

We're working on a form of Attribute-based access control (ABAC) that will likely satisfy some of these requirements. We'll update this when that is released. Thanks for the feedback!

thebleucheese commented 3 years ago

The core of VECTR's more granular ABAC system was released earlier this year. That will let you restrict users to particular databases. Currently, there isn't a way to add red or blue team only roles due to the way data is saved and retrieved from the Test Case panel, but we've had similar requests and are looking at ways to accomplish this on the longer-term roadmap.

Brainmoustache commented 1 year ago

Hey guys, do you have an idea when this is going to be implemented into Vectr ? Thanks

tmslgr commented 1 year ago

Hey guys,

Asking to have this feature added as well. Would it be feasible to narrow done the RBAC level to assessment and even campaigns ?

SRAPSpencer commented 1 year ago

Hey guys,

Asking to have this feature added as well. Would it be feasible to narrow done the RBAC level to assessment and even campaigns ?

Nothing new to report on when this is expected to be released but it is still a roadmap item internally. If you'd like to discuss in more depth you can reach out to us at vectrops@sra.io

nenser commented 8 months ago

Hey guys, Thank you for developing VECTR! I have a similar need to separate rights within Purple Team into rights for Red Team and for Blue Team users when editing the corresponding data fields in the test case panel. It will be great if you implement this in the near future! Thanks!