Include the following information at the top of the report:
Vulnerabilities: Total vulnerabilities broken down by severity level
Black and White output
Include value labels in bar graphs
Axis labels for history charts: Month Day Year Month Day Month Year Ordinal numbers Data set name
When graphing Status of All, Current, and Old Vulnerabilities, include:
Include a message informing the reader of the selection above
Columns to include in host list:
Merge table cells where possible. (Simple HTML, text, and XML formats only. In XML, merges repeated tags into a new layer.)
Show severity level as a number between 0 and 3 instead of a word in the vulnerability list
Put each CVE on a separate line.
Include all hosts in vulnerability list, even if no vulnerabilities are shown
Severity/Status cross-reference columns
Include host information in technical details section even if no vulnerabilities or services are reported.
Information to include regarding each vulnerability:
Include host status information with technical details Include vulnerability status information with technical details
Show All Critical Vulnerabilities
Show All Areas of Concern
Show All Potential Problems
Show All Services
Show All Information
Combine information (users, shares, etc.) into a single line or element
Vulnerability status categories to include (These selections will not affect totals.)
Show all vulnerabilities which are among SANS Top 20 Internet Security Vulnerabilities
Show all vulnerabilities which have exploits available in SAINTexploit
Show all vulnerabilities which have IAVA numbers
Exclude ignored vulnerabilities from report
Enter list of domains separated by spaces.
Enter list of IP addresses and/or IP ranges separated by spaces. For example: 192.168.1.1-192.168.1.128 192.168.3.7
Note 1: Substrings will be matched. For example, "Windows" will match "Windows NT" or "Windows 95". Note 2: Host type information may be unavailable for some hosts, especially if nmap was not installed when the scan took place.
Enter list of host types separated by spaces. For example: Windows Linux Solaris
Host status categories to include (These selections will not affect totals.)
Top-level element
Introduction
Report Time Scan Time Scan Level Scanner Version Session Note: To enable or disable these tags, see the header section.
Note: To enable or disable these tags, see the header section.
Hosts Detected Critical Vulnerabilities Areas of Concern Potential Problems Services Hosts with Critical Vulnerabilities Hosts with Areas of Concern Hosts with Potential Problems Hosts with Services Only Hosts with no services Subnet Subnet address Vulnerability Class Class Name Data Set Data Set Scan Time Note: Additional XML tags are derived from the chart titles and vulnerability class names (defined in classmap.cm). Note: To enable or disable summary information in XML reports, select or deselect the various chart types.
Note: Additional XML tags are derived from the chart titles and vulnerability class names (defined in classmap.cm).
Note: To enable or disable summary information in XML reports, select or deselect the various chart types.
Host List Vulnerability List Host Information Host Host Name Netbios Name IP Address MAC Address Host Type SANS Top 20 vulnerabilities Host Status Recurrences of a host Consecutive recurrences Authentication status Node Name Vulnerability Severity Vulnerability description Vulnerability category Service CVE SANS Top 20 IAVA Other index Vulnerability ID Vulnerability status Recurrences of vulnerability Consecutive recurrences Vulnerability class BID OSVDB cvss_base_score cvss_base_vector pci_compliant_vuln pci_compliant_host Confirmed Exploit available in SAINTexploit Note: To enable or disable the above tags, use the column settings. Note: Additional XML tags are derived from the status labels.
Host Name Netbios Name IP Address MAC Address Host Type SANS Top 20 vulnerabilities Host Status Recurrences of a host Consecutive recurrences Authentication status Node Name
Severity Vulnerability description Vulnerability category Service CVE SANS Top 20 IAVA Other index Vulnerability ID Vulnerability status Recurrences of vulnerability Consecutive recurrences Vulnerability class BID OSVDB cvss_base_score cvss_base_vector pci_compliant_vuln pci_compliant_host Confirmed Exploit available in SAINTexploit
Note: Additional XML tags are derived from the status labels.
Impact Background Problem Resolution Reference Problem and Resolution Technical Details Category Category description Note: To enable or disable the above tags, select or deselect the various tutorial sections. Note: The Category tag is only used if an appendix is selected.
Note: To enable or disable the above tags, select or deselect the various tutorial sections.
Note: The Category tag is only used if an appendix is selected.
Include HTML hyperlinks in XML reports
saint-data 28 Aug 2006 1:02
Host Name Netbios Name IP Address MAC Address
Labels describing the status categories:
Note: Items will be sorted by the first sort key. When the first sort keys are identical, the second sort key, and then the third sort key will be used.
Hosts
Class/category map file classmap
Report width (pixels) for HTML-based formats
Font size for HTML-based formats 1 2 3 4
Show page numbers in PDF reports.
Count all hosts, even if some are not shown in report.
If any of the vulnerability categories appear under more than one severity level, treat them as the same category. For example, if "FTP vulnerabilities" appears under both red and brown, and either one is selected, then include all FTP vulnerabilities and group all FTP vulnerabilities together in the category table.
Show reference URLs instead of hyperlinks in HTML tutorials
Export results to RiskWatch
Save changes and generate the report.