Using ScanSuite

Reports and exports

Where every report format comes from and where findings can be sent.

Findings leave ScanSuite through several routes. Which ones apply depends on the engine, so this page collects them in one place.

Downloadable reports

Every finished scan has a Report button in Scan History. It downloads a ZIP archive containing the raw scanner output and the normalised reports.

FormatWhere it comes from
HTMLA standalone, scrollable report. AI reports carry the risk summary, reachability ordering and the call-path or reachability diagrams inline.
XLSXSpreadsheet export, including the enriched infrastructure and dependency reports with their Exploit and Known Exploit columns.
JSONThe normalised findings, for feeding another system.
MarkdownThe AI Pentest engagement write-up.
ZIPThe AI code documentation archive.

Vulnerability management

Findings from every engine land in Vulnerability Management, which offers full-text search, filtering by product, severity and status, and a one-click Export to XLSX.

DefectDojo

Export is per scanner: each engine on the scan configuration page has its own Export to DefectDojo checkbox. Once findings are there, DefectDojo's own reporting, metrics and Jira integration apply — see Working with scan results.

Some engines do not export to DefectDojo at all. AI Native SAST, dependency reachability, AI DAST and AI Pentest findings are tracked in ScanSuite's own vulnerability management. Secrets and Hidden Paths are held back by default because of what the data contains.

Securitm

Nessus, OpenVAS and Nmap reports upload automatically to SGRC Securitm once the instance URL and API key are configured — see Export to Securitm.

Importing an external report

The Reports page accepts a report file produced outside ScanSuite and imports it into a DefectDojo engagement. Choose the engagement, the report type, and upload the file.

This route requires DefectDojo to be configured. Without it the import is refused, because there is nowhere to put the findings.

Alerts

Email and Telegram notifications can be configured in Settings. They cover scan events and asset changes — a new asset appearing, or an existing one changing its ports or severity.

Last reviewed 2026-08-16