Skip to main content

Hai Triage Summary

Organizations: Learn about this key deliverable and how it can help your team

Updated this week

A Hai Triage Summary is a key deliverable that our Hai Triage analysts provide after validating the report. In the Hai Triage Summary, we aim to provide additional clarity and context on the hacker’s findings to speed up your team’s remediation ability.

In each summary, our analysts:

  • Improve the hacker’s write-up by removing unnecessary steps, adding relevant screenshots or additional necessary steps, additional context on severity or impact, correcting grammar, etc.

  • Add clarity by cleaning up the steps to remediation. If the steps are too long, we clean them up and translate the findings into simple technical language.

  • Remove extraneous information from the hacker’s report and keep it to the point.

We also look to include screenshots to demonstrate our validation findings further and clarify the hacker’s remediation recommendations. These may include:

  • Pre-conditions: If the attack has any pre-conditions, for example, the attacker must have a certain role on the application, or the victim needs to perform a certain action.

  • Pre-attack confirmation: A screenshot showing the system's current state before the attack is executed. For example, this could be a screenshot of the victim’s account showing the information that will be affected by the attacker.

  • The Attack: This is the actual step where the attack takes place. This could be a screenshot from Burp showing the key action that the attacker has to take to exploit the vulnerability.

  • Post-attack confirmation: A screenshot showing the system's resultant state after the attack. This screenshot can be similar to the pre-attack confirmation screenshot, with the affected information highlighted with a box around it.

Did this answer your question?