praetorian-inc / chariot-ui

Chariot Offensive Security Platform
https://chariot.praetorian.com
MIT License
21 stars 6 forks source link

Historical Record For Risks / Assets #533

Open Ameston opened 3 weeks ago

Ameston commented 3 weeks ago

https://praetorianlabs.slack.com/archives/C06RDPMGZJS/p1724104837715959

Summary: Risks that are no longer detected lose their attributes and associated assets, such that they cannot be used for historical record. There’s no reference information for where the former risk was exposed / the URL / port / etc or origination information for the associated asset (after that information has TTLed out of the system).

aashish-sec commented 3 weeks ago

I found a few more instances of this. An open finding was incorrectly automatically closed, and attributes disappeared. The finding is now open without any indication of the asset and its attributes. More details shared on the slack thread

praetorian-matt-schneider commented 1 day ago

one thing we might be able to do as a stopgap to alleviate some of the confusion on the frontend is use the dns value in the risk object to display as an affected asset if no attributes are available. this value is visible in the risks lists view but not once you click into the risk card.