Findings
Each finding is one unique vulnerability detected in an asset.
Detection and reporting for an assessment
XBOW often detects the same vulnerability more than once, and by more than one route, during an assessment. At the end of the assessment, each of these detections are grouped into a single finding for the vulnerability.
XBOW reports each finding at both the asset and assessment levels. You triage and fix the finding, not each individual detection.
Asset-level findings
The first assessment of an asset detects the initial set of findings, while later assessments detect both new and existing findings. XBOW records each new finding at the assessment and asset levels, so the asset list summarizes the findings across all assessments.
When an assessment finding matches an existing asset-level finding:
- The finding is recorded only as part of the assessment and not duplicated at the asset level.
- XBOW adds the new detection to the history of the existing asset-level finding and updates its “Last seen” date.
- The status of the finding does not change. A repeat detection is not a new finding, so it does not trigger reopening or re-classifying the finding.
IDs and missing numbers
XBOW assigns a sequential ID to every finding it records on an asset, including findings it does not show you. IDs are unique within an asset and are never reused, so you may see gaps in the ID range.
Most gaps are findings XBOW has not published to you: either a reviewer has not looked at the finding yet, or a reviewer checked it and did not publish it because it was not a real vulnerability.
A finding can also leave your list. If you challenge a finding, XBOW hides it while a reviewer checks it, and it stays hidden if the reviewer agrees with you.
Finding status
The status of a finding describes its position in triage and remediation. It is separate from severity, CVSS score, and vulnerability class, but it does determine whether the finding counts toward the risk score for the asset. For more information, see Risk score.
| Status | What it means | Counts toward the risk score |
|---|---|---|
| Open | XBOW detected the vulnerability and proved it is exploitable | Yes |
| Open (confirmed) | An XBOW reviewer has confirmed the finding | Yes |
| Fixed | A retest was not able to reproduce the finding at the time the retest ran | No |
| Intended | You marked the behavior as intended | No |
Note: “Fixed” records the result of one retest, not a guarantee that the vulnerability itself is fixed. If XBOW detects it again in a later assessment, the finding keeps its “Fixed” status, but its Last seen date moves forward. Compare Last seen against the date of the retest to see whether XBOW has detected the finding since.
Scope and detail
You can view findings in the Console, exports, reports, and the XBOW API. What differs is the scope you can ask for, and how much detail you get back.
-
Console and exports cover either a whole asset or a single assessment. Open the asset to see every finding on it, or open an assessment to see the findings detected in that assessment, then export from there. An export contains the full detail for every finding it covers, which makes it the simplest way to collect exploits and mitigation advice for many findings at once. See Exporting findings.
-
Reports cover the whole asset. A report summarizes every successful assessment rather than a single one, and presents findings as a narrative with a per-vulnerability list instead of as data. See Reports.
-
XBOW API lists findings for an asset with their summary fields: name, state, severity, dates, and any external ticket you have recorded. To read the description, exploit, impact, mitigation, or proof, request each finding individually. See Findings in the API reference.