Skip to main content

How to use the checklist

The interactive checklist is built for the real assessment loop: scope, work through controls, record findings, and confirm nothing was skipped.

The loop

  1. Pick a platform. Choose from the 23 platforms — Web Application, API, Mobile, Cloud, Active Directory, Containers & Kubernetes, LLM Security, and more (see the roadmap for the full list). Each platform is organised into categories → technologies → checks. Expand and collapse categories and technologies to navigate; every section shows its item count, and Expand all / Collapse all are one click away.
  2. Jump with search. Press ⌘K / Ctrl+K from any page to search every platform, category, technology, check, tool, and reference. Selecting a result jumps straight to it, expands the right sections, and highlights the item.
  3. Scope & recon first. Start with information-gathering checks to map the stack, endpoints, and entry points. What you find tells you which technologies matter.
  4. Filter to your surface. Use the severity filters to focus. When time is short, filter to High and Critical first.
  5. Work top to bottom. Expand a check to read what to verify and why, follow the references, then set its status when you've assessed the control.
  6. Track each finding. Mark every check Open, Closed, or N/A. At the end of the engagement you can review all the Open findings to make sure nothing is left unresolved.
  7. Take notes as you go. Each item has a notes field — record payloads, request IDs, and evidence. Notes are saved in your browser.
  8. Export your evidence. The Export menu produces Markdown, CSV, Excel (.xlsx), or JSON of your progress, statuses, and notes that you can paste into a report or attach to an engagement folder. Re-import the JSON to resume later.

What a status means

Setting a status means you assessed this control. Use Open for an unresolved finding, Closed once it's handled, and N/A where the control doesn't apply. The checklist tracks coverage and status; your notes track the detail.

Privacy

There is no backend. Progress and notes live in your browser's localStorage and are never transmitted. Clearing site data (or the Reset button) wipes them.

Severity

Each check carries a typical severity (criticalinfo) for the control it covers. Treat it as a prioritisation hint, not a verdict — real severity depends on the application's context and the exploitability you demonstrate.