Reports and exports
Where every report format comes from and where findings can be sent.
Findings leave ScanSuite through several routes. Which ones apply depends on the engine, so this page collects them in one place.
Downloadable reports
Every finished scan has a Report button in Scan History and a Download report button on its page. Either downloads a ZIP archive containing the raw scanner output and the normalised reports.
To download several at once:
| Where | What you get |
|---|---|
| Scan History → Download reports | The reports of the scans you ticked, in one ZIP, each as <scan id>-report.zip. |
| Product page → Download latest reports | The newest report of every target of one product, in one ZIP with a folder per target. See The product page. |
| Products → Export CSV | One row per product: risk, open findings, coverage, secrets, last scan and LLM spend. |
| Format | Where it comes from |
|---|---|
| HTML | A standalone, scrollable report. AI reports carry the risk summary, reachability ordering and the call-path or reachability diagrams inline. |
| XLSX | Spreadsheet export, including the enriched infrastructure and dependency reports with their Exploit and Known Exploit columns. |
| JSON | The normalised findings, for feeding another system. |
| Markdown | The AI Pentest engagement write-up. |
| ZIP | The AI code documentation archive. |
Vulnerability management
Findings from every engine land in Vulnerability Management, which offers full-text search and filtering by product, severity and status. Its Export menu downloads the list as XLSX, as JSON, or as ServiceNow XLSX for import into ServiceNow — see Rescans and fix verification.
In ScanSuite Teams, downloading reports needs report access, and a product's Download latest reports is recorded in the team's security audit.
DefectDojo
DefectDojo is recommended for the classic scanners. Export to it is opt-in and per scanner, with its own Export to DefectDojo checkbox on each engine in the scan configuration page. Once findings are there, DefectDojo's own reporting, metrics and Jira integration apply — see Working with scan results. Without DefectDojo, most classic-scanner findings stay in the scan reports: only the AI-driven scans, Nessus and — with Store scanner findings turned on — Semgrep, Nuclei, ZAP and Acunetix put findings in the Vulnerabilities section.
Some engines do not export to DefectDojo at all. AI Native SAST, dependency reachability, AI DAST and AI Pentest findings are tracked in ScanSuite's own vulnerability management. Secrets and Hidden Paths are held back by default because of what the data contains.
Securitm
Nessus, OpenVAS and Nmap reports upload automatically to SGRC Securitm once the instance URL and API key are configured — see Export to Securitm.
Importing an external report
The Reports page accepts a report file produced outside ScanSuite and imports it into a DefectDojo engagement. Choose the engagement, the report type, and upload the file.
This route requires DefectDojo to be configured. Without it the import is refused, because there is nowhere to put the findings.
Alerts
Email and Telegram notifications can be configured in Settings. They cover scan events and asset changes — a new asset appearing, or an existing one changing its ports or severity.
Last reviewed 2026-09-25