Skip to content

Findings and reports

Every assessment produces findings ranked by real-world risk, each backed by evidence. You read them on the run page, using its tabs.

Open a completed run and select the Findings tab. Each finding shows its severity (Critical, High, Medium, Low, or Info), its title, a confidence level, and a status. A finding proven by an exploitation run also carries a Verified badge.

Expand a finding to see the full detail: description, affected assets, any CVEs and CVSS score, and remediation steps. A confirmed finding also shows its proof of concept and the impact demonstrated.

Analysts can set a finding’s status as they review:

  • Candidate: discovered, not yet proven. This is the default from a discovery run.
  • Confirmed: proven exploitable.
  • False positive: not a real issue.
  • Accepted risk: acknowledged and accepted.

Marking a finding as false positive or accepted risk also excludes it from exploitation, so triage first if you want to narrow what a confirmation run covers.

Select the Summary tab for the report view. For a discovery run it shows headline counts (assets discovered, findings, compliance rate, total issues), a severity breakdown, an executive summary, a compliance summary with individual checks, and the report sections.

Select the Artifacts tab to see the raw evidence. Each artifact can be downloaded, and each shows the command that produced it, its exit code, and how long it took. This is the proof behind every finding.