Appearance
Exporting Findings
You can export findings to a file for sharing, archival, or use in other tools. Two formats are supported: CSV (for spreadsheets) and JSON (for automation).
Export works anywhere the findings table appears with selection checkboxes:
- Project Findings
- A host's Findings tab
- A scan's results view (from Scans → click a scan row → Findings)
The project Report is a different export: formatted HTML, Markdown, or JSON of curated items, not this Export N findings dump.
How to export
- Open a findings list and optionally filter (severity, tool, reviewed, report).
- Select the findings you want with the checkboxes (or select all currently filtered rows with the header checkbox).
- Click Export N.
- Choose JSON or CSV. The file downloads in your browser.
Only selected findings are exported. The downloaded file is named after the project, for example my_project_findings.csv.
CSV format
A spreadsheet-friendly file with a header row and one row per finding. Columns:
| Column | Description |
|---|---|
severity | critical / high / medium / low / info |
title | Short description of the issue |
tool | The tool that produced the finding |
rule_id | Rule/test identifier, if any |
url | Where the issue was found |
method | HTTP method |
status | HTTP response status code, if captured |
description | Longer description |
references | Reference links, separated by ; |
remediation | Suggested fix, if available |
created_at | When the finding was recorded (UTC, ISO 8601) |
Safe to open in Excel / Sheets
Because finding text can come from a scanned target's responses, cells that would otherwise be interpreted as spreadsheet formulas are escaped so they open as plain text. This prevents formula-injection issues when reviewing results.
JSON format
A structured file with an envelope describing the export plus the full finding records:
json
{
"schema_version": 1,
"project": "My Project",
"exported_at": "2026-01-01T12:00:00Z",
"count": 2,
"findings": [ /* full finding objects */ ]
}JSON preserves the complete detail for each finding (more than the flattened CSV columns). Use JSON when feeding results into other tooling.
Credential redaction
Exports redact discovered credentials by default — passwords, API keys, and secret-detection matches are replaced with <redacted> in downloaded CSV/JSON so files are safer to share. The live UI always shows real values for triage.
Report HTML/Markdown exports offer an explicit Include credentials (passwords/secrets) checkbox in the export modal (off by default). Raw Export N from findings has no such toggle and always redacts.
CSV vs JSON
- CSV — reviewing in a spreadsheet, quick triage, sharing with non-technical stakeholders.
- JSON — importing into other tools, scripting, or when you need every field.
Formatted reports vs raw export
Export N downloads raw finding data (CSV/JSON) for selected rows. For a formatted report with evidence (scan findings + LFI Commander files), open Report and use HTML, Markdown, or JSON.