Exposure: browse, triage and export findings
Browse, filter, triage, bulk-edit and export findings and vulnerabilities, with identity exposures and configuration checks alongside.
- Who can do this: Contributor · Admin
- In the app: Exposure › All Findings
- 10 min
Exposure lists your findings and vulnerabilities. Identity and Configuration are covered in Identity exposures and Configuration checks. To record a finding by hand or bring in a report, see Add or import findings.
Browse and filter findings
- Open Exposure in the sidebar and choose All Findings or Vulnerabilities.
- Use the toolbar to narrow the table. All Findings has an Assigned to me toggle and opens on Open and In Progress, so change the status filter to see the rest.
- The tiles above the table change with the filters. The Observations tile counts observations, apart from findings.
Triage a finding
- Select a row, then choose Edit.
- Set the Status.
- If the status asks for a reason, enter one under Triage reason.
- For Suppressed or Accepted, optionally set Suppress until. After that date, a scan that still finds the issue reopens the finding; leave it empty to keep the decision.
- Save.
| Status | Use it when |
|---|---|
| Open | Newly found or still active. A later scan refreshes it in place. |
| In Progress | Someone is investigating or fixing it. A later scan refreshes it in place. |
| Suppressed | It is noise, or you are deferring it. Stays hidden if a later scan finds it again. |
| Accepted | You are knowingly living with the risk. Stays hidden if a later scan finds it again. |
| False Positive | It is not a real issue. Stays hidden if a later scan finds it again. |
| Resolved | You fixed it. Reopened if a later scan still finds it. |
| Archived | Filed away for the record. Reopened if a later scan still finds it. |
Moving a finding into Suppressed, Accepted, False Positive or Archived asks for a reason, and so does reopening one from Accepted, False Positive or Resolved. To make a decision hold across scans, use Suppressed, Accepted or False Positive.
A vulnerability has no status of its own. On Vulnerabilities, tick rows and choose Triage findings to apply one status to their findings.
Change or delete many at once
Tick rows, choose an action from the toolbar, then confirm. All Findings offers Edit tags, Edit fields (status, severity, priority or assignee) and Delete; Vulnerabilities offers Edit tags, Edit fields, Triage findings and Delete selected. Deleting a finding removes your triage decision with it, and deleting a vulnerability deletes its findings. To keep a decision, set a status instead.
Export findings
Set the filters so the table shows what you want in the file, then choose Export. Paid plans include export; see pricing.
Did this answer your question?
Assets
Assets is your inventory of networks, identities, apps, devices and data: browse, filter, add, tag, edit, export and delete assets, and jump from an asset to its findings.
Add or import findings
Record a finding by hand, report one from the vulnerability library, or import a Nessus, Burp Suite, Nuclei, SARIF or JSON report from your own tools.