> For the complete documentation index, see [llms.txt](https://support.attackforge.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://support.attackforge.com/app/getting-started/retesting.md).

# Retesting & Remediation

## Overview

AttackForge tracks the remediation history for all vulnerabilities - from `Open`, to `Retesting` & `Closed`. This helps to understand the status of a vulnerability - at any point in time - when you or the customer needs it.&#x20;

Every vulnerability has its own history which contains `Remediation Notes`, to help track what remediation actions were performed, when and by whom.

AttackForge also tracks every `Round of Retesting` that has been requested or performed against the project to make the process simple & fast.

## Add Remediation Notes

Any project team member can add remediation notes to a vulnerability. This can be used by engineering teams when updating the remediation actions performed on the vulnerability, or by pentesters when documenting observations during a retest.

To view and create remediation notes, navigate to the vulnerability page and click on the `Remediation` icon on the right hand side.

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2FRTdQT9dLBXeTkQV3DqBT%2FScreenshot%202026-08-29%20at%208.37.54%E2%80%AFam.png?alt=media&amp;token=9f43b10f-bce1-4064-b8c6-eadb083bf27c" alt=""><figcaption></figcaption></figure>

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2FDgVK803Txi4wspnwgR3E%2FScreenshot%202026-08-29%20at%208.38.33%E2%80%AFam.png?alt=media&amp;token=386a0356-4b27-4522-af20-f43d4ce1e2aa" alt=""><figcaption></figcaption></figure>

To bulk add remediation notes, select the vulnerabilities and then click `Actions -> Add Remediation Note`.

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2FspELahMcoBMSmTdMvj95%2FScreenshot%202026-08-29%20at%208.34.37%E2%80%AFam.png?alt=media&amp;token=e8439428-4125-4395-b987-5aa168ba1160" alt=""><figcaption></figcaption></figure>

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2FttN5W6Kulb2DhU8tKJ6b%2FScreenshot%202026-08-29%20at%208.35.06%E2%80%AFam.png?alt=media&amp;token=48551505-7db8-4dd5-bc6c-b2590f49852e" alt=""><figcaption></figcaption></figure>

## Remediation Plan

If the `Remediation Plan` field is enabled (see Administration module), project team members can update the remediation plan for any of the vulnerabilities. This is useful to help get vulnerabilities acknowledged by technical teams, and plan for when those vulnerabilities will be fixed.

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2FVDI1n9PeVIhcZLqfcfS2%2FScreenshot%202026-08-29%20at%208.35.54%E2%80%AFam.png?alt=media&amp;token=d6a0318a-fdc7-46ad-b8fb-79d53acdbb50" alt=""><figcaption></figcaption></figure>

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2FQRCxaYprBYMa17gXQGKl%2FScreenshot%202026-08-29%20at%208.36.35%E2%80%AFam.png?alt=media&amp;token=dd99124b-0926-473c-a6be-f58c335f44bd" alt=""><figcaption></figcaption></figure>

The vulnerability will now track `Target Remediation Date`.

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2FPHMSKw8GqNLQDQAznKy7%2FScreenshot%202026-08-29%20at%208.39.17%E2%80%AFam.png?alt=media&amp;token=4621b1b6-116d-4b40-a43d-3a98c6000706" alt=""><figcaption></figcaption></figure>

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2FjE02ruNqGYFEndfG0nv5%2FScreenshot%202026-08-29%20at%208.40.30%E2%80%AFam.png?alt=media&amp;token=11883100-224e-4fe7-91a6-998e0119329f" alt=""><figcaption></figcaption></figure>

You can use the `Target Remediation Date` to create `Custom Time-Based Emails` which automatically follow up on vulnerabilities for you.

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2FqeqqBxFN33Kj86nAZVdr%2FScreenshot%202026-08-29%20at%208.46.03%E2%80%AFam.png?alt=media&amp;token=1f2c9c22-6e4b-4ea1-81cc-a12fedc51488" alt=""><figcaption></figcaption></figure>

## Assign Vulnerabilities for Retesting

Any project team member can assign a vulnerability for retesting. This can be used by engineering teams indicating that a vulnerability has been resolved and can now be retested.

You can assign a vulnerability for retesting by clicking on `Update Status -> Ready for Retesting` from the vulnerability page.

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2FgNj99ZSNuWUdRCOzEDLH%2FScreenshot%202026-08-29%20at%208.47.07%E2%80%AFam.png?alt=media&amp;token=0d796f24-acf8-4822-b2d6-84663d92ae29" alt=""><figcaption></figcaption></figure>

You will be prompted to enter an optional remediation note which is useful to help the security team understand what fixes have been put in place in order to indicate vulnerability is now ready for retesting.

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2FdVnIesao4fujFxbO4uEt%2FScreenshot%202026-08-29%20at%208.47.35%E2%80%AFam.png?alt=media&amp;token=79032a2b-4c00-4cbc-89e8-262aa3ee179b" alt=""><figcaption></figcaption></figure>

You can view `Remediation History` by clicking on `Remediation` button on the vulnerability page.

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2FtYwexSSstUbvc4cCwp17%2FScreenshot%202026-08-29%20at%208.47.56%E2%80%AFam.png?alt=media&amp;token=9d0b92f7-6888-48c8-b86b-b9c02516c8e1" alt=""><figcaption></figcaption></figure>

You can also bulk assign vulnerabilities for retesting.

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2FYtQccJmtUb7Zkxmzf4UU%2FScreenshot%202026-08-29%20at%208.48.35%E2%80%AFam.png?alt=media&amp;token=7fb23c33-3e35-49cd-90b7-75944f46a8d7" alt=""><figcaption></figcaption></figure>

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2FpYBYuAfygoKZnIkp6ob8%2FScreenshot%202026-08-29%20at%208.48.46%E2%80%AFam.png?alt=media&amp;token=424ebcfb-dbb7-44fa-bc95-6ef258bf3f3b" alt=""><figcaption></figcaption></figure>

## Requesting a Retest

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2F4XP2RZiL6hPGmYJz8Sja%2FScreenshot%202026-08-29%20at%2010.38.59%E2%80%AFam.png?alt=media&amp;token=9d53538a-b5ef-4244-a038-2abd9c8891f0" alt=""><figcaption></figcaption></figure>

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2FRz82T1okIc0Gru13M3aX%2FScreenshot%202026-08-29%20at%2010.37.38%E2%80%AFam.png?alt=media&amp;token=fce88a82-b728-4197-b260-0476ab06b187" alt=""><figcaption></figcaption></figure>

You can request a `Retesting Round` to be performed.

To request a round of retesting, click on `Retesting` from the project menu, then click on `Request Retest`.

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2FLCWIbJYJqnxQCNVxdfsD%2FScreenshot%202026-08-29%20at%208.49.43%E2%80%AFam.png?alt=media&amp;token=59cee10e-93fd-42e7-ad6b-bc38b4edd4be" alt=""><figcaption></figcaption></figure>

Select the test window when the retest can occur.&#x20;

Select the vulnerabilities you would like to include in this round of retesting.

You can also add your own [Custom Fields](https://support.attackforge.com/app/getting-started/custom-fields-and-forms) to tailor your retest rounds to include the information you need.

Click `Request Retest` when ready.

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2FQwcXlGQnxXER7KslLcCH%2FScreenshot%202026-08-29%20at%209.27.59%E2%80%AFam.png?alt=media&amp;token=1b325ad8-ae48-4a3c-ad1e-7b2a620be749" alt=""><figcaption></figcaption></figure>

After submitting the request, you will receive a confirmation email. The administrators and anybody else configured will also be notified of your request.

You will also see your request registered as a new round.

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2F6MLx4tbFPFiO5MFsbZxt%2FScreenshot%202026-08-29%20at%209.28.57%E2%80%AFam.png?alt=media&amp;token=0f740a36-50a0-4587-9f42-41d7eb37749e" alt=""><figcaption></figcaption></figure>

## Updating a Retest Round

When the round is in the `Requested` status - the requestor can modify the details for the round by clicking on `Actions > Edit`.

When the round is in the `Approved` status - only users with Edit access to the project can modify the round.

When the round is in the `Completed` or `Cancelled` status - no modifications to the round is permitted.

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2FcVSLTZ23AKixcd60NosR%2FScreenshot%202026-08-29%20at%209.30.06%E2%80%AFam.png?alt=media&amp;token=9ec5b6d2-1686-490d-a9c4-3c7b52a31ca3" alt=""><figcaption></figcaption></figure>

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2FKMAbKBAJmmo3U5ZwI9Ac%2FScreenshot%202026-08-29%20at%209.30.51%E2%80%AFam.png?alt=media&amp;token=143ae0d6-b7c8-4fcd-a217-58acad472c57" alt=""><figcaption></figcaption></figure>

## Approving a Retest Round

Users with Edit access to the project can `Approve` the retest round. Approving a retest round signifies to the requestor that their request has been reviewed and accepted, and an email will be sent to the requestor to inform them of this.

Once a round is approved - the requestor will no longer be able to edit the retest round.&#x20;

However, users with Edit access to the project will still be able to modify the round.

This is ideal for use cases where the requestor fills in the minimal set of data - such as window and scope - and the security team then adjusts the fields, and adds their own custom fields such as assigned tester or notes - which then completes the entire data needed for the retest round.

> **NOTE:** Approving a retest round is an optional step in the workflow.

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2F0ihyuNr7PwR9KgUMBJ87%2FScreenshot%202026-08-29%20at%209.32.17%E2%80%AFam.png?alt=media&amp;token=f53e166e-ab71-4ad0-9365-4cbbd003668e" alt=""><figcaption></figcaption></figure>

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2FhUJ0xvxntYhN26CN20tS%2FScreenshot%202026-08-29%20at%209.37.46%E2%80%AFam.png?alt=media&amp;token=e9a5250a-0df6-4634-823d-9432ea83a159" alt=""><figcaption></figcaption></figure>

## Performing a Retest

Once a retest has been requested, the testers can commence the retesting. The vulnerabilities in-scope for the retest can be accessed from the `Retesting` section on the project.

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2FrhtJkf4Z14q2yzjKApDV%2FScreenshot%202026-08-29%20at%209.41.11%E2%80%AFam.png?alt=media&amp;token=10af59d6-59ed-455b-8f36-1b335f9dc5b3" alt=""><figcaption></figcaption></figure>

Click on a vulnerability to bring up a list of in-scope vulnerabilities for the given round.

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2F2GAp8u7cRSGRBDBRjoi6%2FScreenshot%202026-08-29%20at%209.42.16%E2%80%AFam.png?alt=media&amp;token=43b5b43d-bbae-4895-85c3-f6bc3bff8a49" alt=""><figcaption></figcaption></figure>

Perform your retesting for each vulnerability. Note you will need to have Edit permissions on the project in order to perform the retest.

* **Check the Workspace** - get all the information and context you need to set up for the retest.
* **View Remediation Notes** - to understand what steps have been taken to mitigate this vulnerability.
* **Upload Evidence** - upload screenshots and proof of the findings/observations from the retest.
* **Add Remediation Note** - add further remediation notes to include the findings/observations from the retest.
* **Re-Open Vulnerability** - re-open the vulnerability if it is deemed to be not fixed.
* **Close Vulnerability** - close the vulnerability if it is deemed to be fixed.

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2FfA94iuTGoh4jYf6NHfn4%2FScreenshot%202026-08-29%20at%209.42.59%E2%80%AFam.png?alt=media&amp;token=f7eb1bf0-289c-45d3-8762-469924d2e1a8" alt=""><figcaption></figcaption></figure>

Once you have performed the retest for all the in-scope vulnerabilities, click on `Complete Round` from the actions menu for the round of retesting you are working on. An email notification will be sent to the project team to inform them that the retest is now completed. A record of the retested vulnerabilities will also be visible and also accessible in reports.

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2FJvrdxwl9aE5F9tJbC63h%2FScreenshot%202026-08-29%20at%209.43.38%E2%80%AFam.png?alt=media&amp;token=33fc3616-9c5d-497e-9f4b-3b17fcff5650" alt=""><figcaption></figcaption></figure>

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2FwhLkXho6zgUt1C2ONswv%2FScreenshot%202026-08-29%20at%209.43.50%E2%80%AFam.png?alt=media&amp;token=11732de5-fab4-461b-a4cc-cb12a008ae7b" alt=""><figcaption></figcaption></figure>

## Tracking Retesting

You can track retesting history on a project by simply viewing the project dashboard page.

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2FvkOQhxp7rLLAMMaSAVj7%2FScreenshot%202026-08-29%20at%209.46.30%E2%80%AFam.png?alt=media&amp;token=e689404a-91f8-46f1-9ca6-beb4417eda3c" alt=""><figcaption></figcaption></figure>

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2FsXXGvIkJ6QwvDVjVt2Yo%2FScreenshot%202026-08-29%20at%209.46.42%E2%80%AFam.png?alt=media&amp;token=72a4bf9a-8383-4476-a170-3fc7d14f7816" alt=""><figcaption></figcaption></figure>

You can also see all your retest rounds on the project table:

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2FdZKmJyEu2z6V69XhKJAH%2FScreenshot%202026-08-29%20at%209.47.52%E2%80%AFam.png?alt=media&amp;token=e74c6856-4503-4c3b-a4f1-6fab83553fd9" alt=""><figcaption></figcaption></figure>

## Cancelling a Retest

Requestors and users with Edit access on the project can cancel a retest round if it is no longer required. Once a retest has been cancelled, no further actions can be taken for that round - however a new round can always be requested.

All in-scope vulnerabilities for the cancelled round of retesting will be reset back to Open status.&#x20;

A remediation note will also be created to track the status change due to cancelled retest.

You can cancel a retest by clicking on `Cancel Round` from the actions menu.

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2FVH4TFKWb4M1L3uSny5mw%2FScreenshot%202026-08-29%20at%209.57.41%E2%80%AFam.png?alt=media&amp;token=b7c9346f-83d9-4339-bc98-e7b490048765" alt=""><figcaption></figcaption></figure>

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2FKoka8f75FZsNSaGnxn9u%2FScreenshot%202026-08-29%20at%209.57.53%E2%80%AFam.png?alt=media&amp;token=1626c525-16b4-4b96-b443-525ffa2f6a60" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://support.attackforge.com/app/getting-started/retesting.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
