CVSSv4, DREAD, MITRE ATT&CK and custom Risk Calculators

Use an industry standard or create your own - you can use a different calculator in each project

Common Vulnerability Scoring System (CVSSv4)

Dradis ships with a built-in CVSSv4 calculator (which also supports CVSSv3.1 and CVSSv3).

Use it to quickly assign the different metrics and calculate the risk vector, and have fine-grained control of what values you want to show in your pentest report.

Best of all, it's open-source:  dradis/dradis-calculator_cvss

Screenshot of the CVSSv4 calculator for an issue
Screenshot of the DREAD calculator in action

DREAD Risk Assessment Model

If you favor Microsoft's Damage, Reproducibility, Exploitability, Affected Users, and Discoverability (DREAD) risk assessment model, we have you covered: Dradis ships with a built-in DREAD calculator.

You have full control over what components and scores to include in your security report.

We released it as open-source:  dradis/dradis-calculator_dread

MITRE ATT&CK® Calculator

Map your findings to the MITRE ATT&CK framework without leaving Dradis. The built-in calculator lets you select tactics, techniques, and sub-techniques—automatically populating issue fields with properly formatted references.

You have full control over how MITRE data appears in your security reports.

Perfect for threat intelligence documentation, compliance requirements (NIST CSF, SOC 2), and red team assessments.

You guessed it, also open-source 🙌:  dradis/dradis-calculator_mitre

Screenshot of the MITRE ATT&CK calculator in action
IssueLibrary dashboard view

Custom Risk Calculators

We know that neither CVSS nor DREAD are perfect. Some times you need your own risk assessment model.

Whether it's a combination of an Impact score and a Probability one, or a formula-based calculation, you can create a custom risk scoring system and load it in your Dradis instance, just for you.

You can't do that with any other platform!

Different Risk Models per project

Whether it's because you're whitelabelling your pentest deliverables for a partner, or because you have a customer that has a preferred risk assessment model, we have your back.

In Dradis you can have multiple risk calculators loaded and choose which one you want to use for each project.

IssueLibrary dashboard view

The right Risk Models for each assessment.

See plans

Seven Strategies To Differentiate Your Cybersecurity Consultancy

You don’t need to reinvent the wheel to stand out from other cybersecurity consultancies. Often, it's about doing the simple things better, and clearly communicating what sets you apart.

  • Tell your story better
  • Improve your testimonials and case studies
  • Build strategic partnerships

Your email is kept private. We don't do the spam thing.