Skip to main content

Coverage & activity report

Generate a document that provides clear visibility into what was tested on your scope.

You subscribed to the YesWeHack agentic Pentest solution, launched your first campaign, and want to know more about what was tested on your scope and the results, including endpoints, security checks, categories, methodology, and more.

The Coverage & Activity report provides all the key information about how our agentic pentest solution performed on your scope, helping you meet your traceability needs. You can easily share this report with your internal/external auditors or teams to demonstrate the coverage and activity of your pentest campaign.


What is included in the Coverage & Activity report?

The coverage & activity report is one of the deliverables of an Agentic Pentest campaign. It details key metrics about the exhaustivity and the methodology of the campaign, regardless of the number of findings.

ℹ️ Access all key metric about your findings in your audit report. Learn more here.

Structure

  • An executive summary which displays:

    • Security tests performed

    • Vulnerability categories covered

    • OWASP WSTG test cases covered

    • Signals investigated

  • The testing coverage by functional area (ie., API endpoints, administration, applications surface, authentication & user management, Content & Publishing, File management, Infrastructure & Configuration) including the number of endpoints, security tests, and categories covered for each area.

  • The coverage by vulnerability category, with an explicit mapping to the associated OWASP WSTG test cases.

  • The list of attack techniques applied.

  • The list of WSTG test cases executed.

  • A detailed security verification that summarises the security tests performed on the most actively endpoints:

    • the techniques applied, the number of security tests, and, most importantly, a conclusion explaining why each endpoint is or is not exploitable.


Where can I find my Coverage & Activity report?

  • Go to the “Admin Panel”

  • Open an Agentic Pentest program

  • Click on “Audit reports” in the left-side menu

  • The Coverage & activity report is displayed in the list of custom reports

  • Click the “Upload” icon to be able to share it with your teams

Did this answer your question?