Skip to content

← Back to the Labs

L3:vulnerability-scanning-automation · Software Wing · Featured

Vulnerability scanning automation

Automated scan scheduling, asset ownership and remediation reporting for Indonesia's national cyber agency.

Client
BSSN
Role
Backend Engineer (part-time)
Period
May 2023 to Jul 2023

Results

  • 28 PRs

    Pull requests merged over about three and a half months, from initial migration to scheduled exports

    Counted in the repository's pull request history.

    Verified

Problem

BSSN scans protected sites and systems for vulnerabilities. Starting scans, tracking asset owners and preparing reports required extensive manual work in the scanner console.

What I did

  • I designed the data model and REST API with Express, Sequelize and Swagger for protected sites, assets, platforms, owners, scans and vulnerabilities, including audit logs.
  • I integrated the Nessus API to start, pause and resume scans, with email notifications and scheduled jobs for progress and expected completion tracking.
  • I added severity counts, remediation-stage statistics and dashboard summaries with Redis caching.
  • I generated per-asset PDF vulnerability reports across scans and scheduled exports comparing results between scan dates.

Architecture

  1. ClientAnalyst dashboardAssets, scans and reports
  2. ServiceExpress APISequelize, Swagger
  3. ServiceScan schedulerScheduled cron jobs and exports
  4. ExternalNessusVulnerability scanner
  5. DataMySQLAssets and findings
  6. DataRedisStats cache

Data flow

  • Analyst dashboard to Express API (REST)
  • Express API to Nessus (launch, pause, resume)
  • Scan scheduler sends asynchronously to Nessus (progress)
  • Express API to MySQL (SQL)
  • Scan scheduler sends asynchronously to MySQL (results)
  • Express API to Redis (stats)

Tech stack

  • Node.js
  • Express
  • Sequelize
  • MySQL
  • Redis
  • Nessus API
  • Swagger
  • AWS EC2
  • Sentry

L2 · Related career entryBackend Engineer (part-time) · BSSN