Retesting Findings
Verify whether Aikido Pentest findings are fixed after remediation.
Last updated
Was this helpful?
Verify whether Aikido Pentest findings are fixed after remediation.
After you fix a finding, use a retest to verify the fix in your pentest environment. Aikido retests one finding at a time, validates that the remediation properly fixes the issue, and checks for related risks introduced by the change. Aikido automatically closes the finding when the retest confirms that it is fixed.
Deploy your fix to the environment used for the assessment before you start a retest.
To retest a finding, you need the Manage Pentests permission, and any pending credits for the assessment must be settled. You can retest findings from assessments started within the last six months.
While a retest runs, the assessment shows Retest Running. For findings with Attack Analysis, open the live retest to follow its progress.
When the retest finishes, Aikido marks the finding as Solved if it can't reproduce the issue. Otherwise, the finding remains open with a Not fixed result and updated remediation guidance.
For an Android assessment, build a new APK that includes your fix and upload it before retesting the finding:
Open the assessment overview.
Under Configuration Details, find Android App.
Select the edit icon and upload the new APK.
Start the finding retest as described above.
Future retests use the newly uploaded APK. You can replace the APK only when the assessment isn't running.
Make sure the replacement APK meets the Android pentest requirements, including the 500 MB limit and no certificate pinning, root detection, or emulator detection.
Review the retest result in the finding. Once all relevant findings are resolved, download a Post-Remediation Report to share your current security posture with stakeholders.
Last updated
Was this helpful?
Was this helpful?