Help Centre
Updated

Add or import findings

Record a finding by hand, report one from the vulnerability library, or import a Nessus, Burp Suite, Nuclei, SARIF or JSON report from your own tools.

Record a manual finding

  1. Open Exposure › All Findings and choose Manual finding.
  2. Choose an existing Asset, or type a host, IP address or URL under Manual asset, host or URL and choose its asset type.
  3. Under What was found, pick the type that fits what you found, then fill in the fields that appear.
  4. Set the Severity and describe what you saw, such as the banner, the response or how you confirmed it.
  5. Choose Save finding.

Add a finding for a known weakness

On Exposure › All Findings, choose Add Finding, enter a Name, pick the Asset and the Vulnerability, then select Create Finding. To start from a ready-made write-up, use Exposure › Vulnerabilities › Add Vulnerability › Choose from library; see Exposure.

Import a scanner report

  1. On Exposure › All Findings, choose Import.
  2. Pick the Report format your scanner produced and choose the file.
  3. If the report has findings that name no host, such as code-analysis results, pick the application they belong to under Asset for findings that name no host.
  4. Choose Preview. No findings are created until you choose Import.
  5. Read the preview, then choose Import to save.
FormatFile
Nessus.nessus
Burp SuiteXML export
NucleiJSON Lines
SARIF.sarif
CISO360AI JSON.json export from this platform

The preview lists what each entry would become.

Did this answer your question?

On this page