Skip to main content

Remediation Verification in SpartanX: Confirm Your Fixes Actually Work

Run targeted retests on specific vulnerabilities or all findings on an asset. Schedule recurring retest cycles to continuously verify your remediation is holding.

Written by Antônio Baggio

Remediation Verification closes the loop on the security testing cycle. After vulnerabilities are identified and fixes are applied, SpartanX can retest those findings — either asset-by-asset or on a per-vulnerability basis — to confirm that the remediation is effective.


When to Use Remediation Verification

Use Remediation Verification after developers have deployed a fix for one or more vulnerabilities. Rather than running a full-scope engagement — which would test everything again — Remediation Verification is targeted: it checks exactly what was fixed, nothing more.

This is valuable when:

  • You need to confirm a fix before closing a compliance finding

  • Developers request proof that their patch resolved the issue

  • You want to track remediation velocity without running a full red team cycle

Launching Remediation Verification

From the Engagements menu, click "Launch Engagements" and select "Remediation Verification." The methodology is identical for both external and internal engagements.

You can scope the engagement in two ways:

  • By Asset — select one or more assets and retest every vulnerability found on them. Useful when a significant refactor has occurred and you want comprehensive verification.

  • By Vulnerability — select specific vulnerabilities from a collection to retest. Useful when only a subset of findings have been remediated.

Both scoping methods can be combined. For example, you might choose a specific asset but then filter down to only the critical-severity findings within it.


Configuring Guardrails

The guardrail configuration is identical to standard engagements: no guardrails, standard guardrails, or maximum safety mode. Choose based on your target environment.


Scheduling and Recurring Verification

Remediation Verification supports scheduling and recurrence. If your development team has extended remediation timelines, you can set up a weekly retest that automatically runs until the vulnerability is confirmed resolved. This keeps remediation status current without manual intervention.


What's Next

The next section covers importing scan results from third-party tools — a key step if you're using Nessus, Qualys, or other scanners alongside SpartanX.

Did this answer your question?