Close

Findings

Evidence-based finding management

Every finding is recorded with its evidence: the request that was sent, the response that came back and the rule that matched. The reviewer verifies the result from that record.

Why evidence matters

A scanning tool reporting that a server is exposed is not enough to decide on. To clear a false alarm, to prioritize a real finding and to answer an auditor, you need to see how the finding was reached. Cyprob keeps the raw data next to every finding: which request went out, which response came back and which rule matched.

Finding list showing severity, asset and status together
Finding list: severity, asset and status together

How findings are managed

Findings are filtered by severity and grouped by asset and by scan. The team marks a finding as verified, as an accepted risk or as closed. If the same finding reopens in a later scan, its history stays with it.

Common questions

How do we weed out false positives?

From the evidence. The raw request and response sit next to every finding, so the reviewer sees exactly why the rule matched and makes the call.

Does a closed finding lose its history?

No. If the same finding comes back in a later scan, its past states stay attached. When it was first seen and what was done about it remain on record.

Can a finding be marked as accepted risk?

Yes. A finding can be marked verified, accepted risk or closed, and lists can be filtered by severity, asset and scan.


Request a demo See reporting

← Cyprob home