Add or import findings
Record a finding by hand, report one from the vulnerability library, or import a Nessus, Burp Suite, Nuclei, SARIF or JSON report from your own tools.
- Who can do this: Contributor · Admin
- In the app: Exposure › All Findings
- 10 min
Record a manual finding
- Open Exposure › All Findings and choose Manual finding.
- Choose an existing Asset, or type a host, IP address or URL under Manual asset, host or URL and choose its asset type.
- Under What was found, pick the type that fits what you found, then fill in the fields that appear.
- Set the Severity and describe what you saw, such as the banner, the response or how you confirmed it.
- Choose Save finding.
Add a finding for a known weakness
On Exposure › All Findings, choose Add Finding, enter a Name, pick the Asset and the Vulnerability, then select Create Finding. To start from a ready-made write-up, use Exposure › Vulnerabilities › Add Vulnerability › Choose from library; see Exposure.
Import a scanner report
- On Exposure › All Findings, choose Import.
- Pick the Report format your scanner produced and choose the file.
- If the report has findings that name no host, such as code-analysis results, pick the application they belong to under Asset for findings that name no host.
- Choose Preview. No findings are created until you choose Import.
- Read the preview, then choose Import to save.
| Format | File |
|---|---|
| Nessus | .nessus |
| Burp Suite | XML export |
| Nuclei | JSON Lines |
| SARIF | .sarif |
| CISO360AI JSON | .json export from this platform |
The preview lists what each entry would become.
Did this answer your question?
Exposure
Browse, filter, triage, bulk-edit and export findings and vulnerabilities, with identity exposures and configuration checks alongside.
Identity exposures
Review leaked credentials and account addresses found in breaches and on the dark web, resolve them once the account is secured, and reveal a leaked password.