Findings

Each finding is one unique vulnerability detected in an asset.

Detection and reporting for an assessment

XBOW often detects the same vulnerability more than once, and by more than one route, during an assessment. At the end of the assessment, each of these detections are grouped into a single finding for the vulnerability.

XBOW reports each finding at both the asset and assessment levels. You triage and fix the finding, not each individual detection.

Asset-level findings

The first assessment of an asset detects the initial set of findings, while later assessments detect both new and existing findings. XBOW records each new finding at the assessment and asset levels, so the asset list summarizes the findings across all assessments.

When an assessment finding matches an existing asset-level finding:

  • The finding is recorded only as part of the assessment and not duplicated at the asset level.
  • XBOW adds the new detection to the history of the existing asset-level finding and updates its “Last seen” date.
  • The status of the finding does not change. A repeat detection is not a new finding, so it does not trigger reopening or re-classifying the finding.

IDs and missing numbers

XBOW assigns a sequential ID to every finding it records on an asset, including findings it does not show you. IDs are unique within an asset and are never reused, so you may see gaps in the ID range.

Most gaps are findings XBOW has not published to you: either a reviewer has not looked at the finding yet, or a reviewer checked it and did not publish it because it was not a real vulnerability.

A finding can also leave your list. If you challenge a finding, XBOW hides it while a reviewer checks it, and it stays hidden if the reviewer agrees with you.

Finding status

The status of a finding describes its position in triage and remediation. It is separate from severity, CVSS score, and vulnerability class, but it does determine whether the finding counts toward the risk score for the asset. For more information, see Risk score.

StatusWhat it meansCounts toward the risk score
OpenXBOW detected the vulnerability and proved it is exploitableYes
Open (confirmed)An XBOW reviewer has confirmed the findingYes
FixedA retest was not able to reproduce the finding at the time the retest ranNo
IntendedYou marked the behavior as intendedNo

Note: “Fixed” records the result of one retest, not a guarantee that the vulnerability itself is fixed. If XBOW detects it again in a later assessment, the finding keeps its “Fixed” status, but its Last seen date moves forward. Compare Last seen against the date of the retest to see whether XBOW has detected the finding since.

Scope and detail

You can view findings in the Console, exports, reports, and the XBOW API. What differs is the scope you can ask for, and how much detail you get back.

  • Console and exports cover either a whole asset or a single assessment. Open the asset to see every finding on it, or open an assessment to see the findings detected in that assessment, then export from there. An export contains the full detail for every finding it covers, which makes it the simplest way to collect exploits and mitigation advice for many findings at once. See Exporting findings.

  • Reports cover the whole asset. A report summarizes every successful assessment rather than a single one, and presents findings as a narrative with a per-vulnerability list instead of as data. See Reports.

  • XBOW API lists findings for an asset with their summary fields: name, state, severity, dates, and any external ticket you have recorded. To read the description, exploit, impact, mitigation, or proof, request each finding individually. See Findings in the API reference.

Was this helpful?