Planned
10Committed and queued
Self-managed Hosting (on prem)
Bug Bounty Platform Integration (HackerOne, BugCrowd, Intigriti)
Automatically generate templates for incoming reports and trigger scans based on the rules.
Policies
Define the asset and template conditions, SLA on identified and remediated vulnerabilities.
Exploit / CVE Insights
API and search engine to navigate the trending exploits on the internet. Aim is to help users find, research and create templates or if already available see the exposure on their assets database. This will have an ability to map from technologies, repositories, internet references, exposed assets on the internet for a given tech, etc
Custom asset enrichment
Allow users to write custom templates that will then enrich assets automatically with tags or technology details to customize the technology and asset discovery phase.
Splunk Integration
Additional Browser Support
PDCP is designed to work best with Chromium-based browsers, but we want to be able to support other browsers like Safari and Firefox.
Elastic Integration
SCIM
CI/CD Integrations (Marketplace apps)
Next
9Actively being built
Cloud Misconfigurations
Streamline vulnerability templates to scan common cloud providers e.g. AWS, GCP, Azure, HashiCorp, etc to detect critical misconfigurations and policies.
Compliance Reporting
Ability to generate reporting for SOC II, ISO27001, HIPAA, OWASP reports from the dashboard.
Asset Level Details
Logs, vulnerability history, screenshot history, for a given asset For screenshot history we could consider both a history of the screenshots taken as well as alerts if the hash of a screenshot changes.
Secrets V2
Improved workflow and templates for detecting and validating tokens exposed on web paths, public repositories, files, etc
Light Mode
ServiceNow Integration
Authentication or Authorization Automation
Easily write authenticated templates using web-assisted automation. This will ease the automation of post authentication related vulnerabilities.
Vercel Integration
Integrate Vercel as an addition Cloud Service for importing assets from Vercel endpoints and preview deploys https://github.com/projectdiscovery/cloudlist/issues/566
Keyboard Shortcuts
In Progress
3Actively being built
Nuclei Enhanced Technology Detection
Enhance the technology detection capabilities by utilizing targeted nuclei templates. This approach will improve our ability to accurately identify and analyze the technologies present on various targets and assets. By leveraging these specialized templates, we can ensure a more precise and comprehensive detection process, enabling us to better understand the technological landscape of the discovered entities. This enhancement will not only increase the accuracy of our detection mechanisms but also streamline the process, making it more efficient and effective in identifying critical technologies.
Expanded technology detection
Today, we use standard technologies like wappalzer to do technology detection on assets, but we also have a whole library of nuclei templates that do expanded technology detection. We will add these templates to help enhance technology detection.
PCI Compliance Support
Provide a module that allows customers to: Specify the subset of their assets that are βin-scopeβ for PCI compliance Attest that the rest of their detected assets are βout of scopeβ Run a βASVβ (Approved Scanning Vendor) scan against the in scope assets on a regular (e.g. quarterly) basis Provide an AoC (Attestation of Compliance) for the customer to use supporting their PCI compliance application and audit
Completed
37Recently shipped
Internal Scanning
Discover and scan assets inside your perimeter that arenβt internet facing by connecting your networks via a secure tunnel to PDCP, allowing for scanned, scalable vulnerability scanning for internal assets and networks.
Executive Reporting
See how your organization is: Seeing active vulnerabilities over time Remediation pace Ratio of exposed vulnerabilities See breakdown of risk
Asset View
Be able to see details of an asset, historical information, vulnerability correlation, and other metadata about a given asset.
Asset Tagging/Labeling
Enhance asset management by introducing the capability to add tags. This allows for efficient filtering and tracking of information such as: β’ Production and staging environments β’ Team ownership β’ Other internal tracking details
Early templates
Early access to the templates before they are released in public repository. This gives an immediate scanning capabilities as new templates are merged or written.
Audit Logs (App)
Conditional Scans & New Asset scans
Trigger scans based on the conditions of new templates and newly found assets. Also allow users to subscribe to alerts (slack, email) for newly discovered assets
Asset Discovery
Asset Alerting for New Asset Detection
Alert users when new assets are detected. Alerts should be sent via webhook, integrations, and email, providing timely notifications to users about new asset discoveries.
Security Regression Testing
Automation vulnerability management & regression testing by automatically updating the status of open vulnerabilities, which currently requires manual retests, and adding automatic regression testing. This enhancement will improve efficiency and reduce manual effort for ongoing vulnerability tracking and testing.