Using ScanSuite

Reports and exports

Where every report format comes from and where findings can be sent.

Findings leave ScanSuite through several routes. Which ones apply depends on the engine, so this page collects them in one place.

Downloadable reports

Every finished scan has a Report button in Scan History and a Download report button on its page. Either downloads a ZIP archive containing the raw scanner output and the normalised reports.

To download several at once:

WhereWhat you get
Scan History → Download reportsThe reports of the scans you ticked, in one ZIP, each as <scan id>-report.zip.
Product page → Download latest reportsThe newest report of every target of one product, in one ZIP with a folder per target. See The product page.
Products → Export CSVOne row per product: risk, open findings, coverage, secrets, last scan and LLM spend.
FormatWhere it comes from
HTMLA standalone, scrollable report. AI reports carry the risk summary, reachability ordering and the call-path or reachability diagrams inline.
XLSXSpreadsheet export, including the enriched infrastructure and dependency reports with their Exploit and Known Exploit columns.
JSONThe normalised findings, for feeding another system.
MarkdownThe AI Pentest engagement write-up.
ZIPThe AI code documentation archive.

Vulnerability management

Findings from every engine land in Vulnerability Management, which offers full-text search and filtering by product, severity and status. Its Export menu downloads the list as XLSX, as JSON, or as ServiceNow XLSX for import into ServiceNow — see Rescans and fix verification.

In ScanSuite Teams, downloading reports needs report access, and a product's Download latest reports is recorded in the team's security audit.

DefectDojo

DefectDojo is recommended for the classic scanners. Export to it is opt-in and per scanner, with its own Export to DefectDojo checkbox on each engine in the scan configuration page. Once findings are there, DefectDojo's own reporting, metrics and Jira integration apply — see Working with scan results. Without DefectDojo, most classic-scanner findings stay in the scan reports: only the AI-driven scans, Nessus and — with Store scanner findings turned on — Semgrep, Nuclei, ZAP and Acunetix put findings in the Vulnerabilities section.

Some engines do not export to DefectDojo at all. AI Native SAST, dependency reachability, AI DAST and AI Pentest findings are tracked in ScanSuite's own vulnerability management. Secrets and Hidden Paths are held back by default because of what the data contains.

Securitm

Nessus, OpenVAS and Nmap reports upload automatically to SGRC Securitm once the instance URL and API key are configured — see Export to Securitm.

Importing an external report

The Reports page accepts a report file produced outside ScanSuite and imports it into a DefectDojo engagement. Choose the engagement, the report type, and upload the file.

This route requires DefectDojo to be configured. Without it the import is refused, because there is nowhere to put the findings.

Alerts

Email and Telegram notifications can be configured in Settings. They cover scan events and asset changes — a new asset appearing, or an existing one changing its ports or severity.

Last reviewed 2026-09-25