Skip to main content

Report types

Four report types are available:
The Editable pentest report requires selecting an Engagement and a Report Template to populate client details and standard sections.

Report contents

Standard sections

Findings information

Each finding in a report includes:
  • Title and description
  • Severity and risk rating
  • Affected assets and locations
  • Evidence (screenshots, requests/responses)
  • Remediation guidance
  • References (CVE, CWE, etc.)

Where to generate reports

You can generate reports from three locations in the platform:

Generating reports

1

Select scope

Choose which scans or findings to include. You can generate reports from:
  • A single vulnerability or reconnaissance scan
  • Multiple scans (vulnerability, reconnaissance, or mixed)
  • Selected findings across scans
2

Choose report type

Select the report type that matches your needs. For pentest reports, you’ll also select an Engagement and Report Template.
3

Configure filters

Filter findings by severity or status (fixed, ignored, accepted), and optionally include additional context like finding history and tool configuration.
4

Select format and generate

Pick your output format and generate the report.

Output formats

Not all formats are available for every report type. Discovery scan aggregations support only PDF and HTML.
Use PDF for final deliverables and DOCX when you need to make manual edits or add custom content before sending to clients.

Report settings

Customize your reports with branding and email delivery options:
  • Custom Logo: Add your company logo to reports
  • Email Settings: Configure sender name, reply-to address, and email templates for report delivery
Custom branding features require the White Label add-on. See Add-ons for details.