Reports
XBOW automatically produces a penetration testing report for each successful assessment. Reports are downloadable PDFs with a summary of findings, evidence, and testing activity.
In addition to the full report, XBOW also creates an executive summary and letter of attestation. These shorter reports are useful for sharing progress or results with an auditor, prospect, or your leadership without broadcasting the details of any vulnerabilities.
Penetration testing report
A summary of the results of all successful assessments run on an asset. The report includes a cover page, a summary narrative with the total number of findings, a per-vulnerability list, and exploit detail for validated findings. XBOW generates the report automatically once an assessment succeeds, then generates a new version each time you verify a fix.
All XBOW users can download the penetration testing report for an assessment. For more information, see Explore and fix XBOW results.
Note: Findings marked “Intended” are excluded from reports.
Executive summary
A short, leadership-facing overview of the full report covering scope, testing methodology, and risk posture without including exploit detail. The executive summary is available after XBOW creates the full report.
Letter of attestation
A brief letter confirming that XBOW tested your asset. The letter includes a high-level summary of XBOW’s approach and conclusions, as well as XBOW’s signature.
This document is best used as evidence for an auditor or procurement contact, and is available after XBOW creates the full report.