Skip to main content

Coverage & activity report

Generate a document that provides clear visibility into what was tested on your scope.

The Coverage & Activity report provides all the key information about how our Agentic Pentest solution behaved on your scope, helping you achieve full traceability over what was tested and how.


What is included in the Coverage & Activity report?

The coverage & activity report is one of the 3 key deliverables of an Agentic Pentest campaign. It details key metrics about which tests were carried out on the different assets, whether or not they led to a valid vulnerability.

ℹ️ Access all key metric about your findings in your audit report. Learn more here.

Structure

  • An executive summary which displays:

    • Security tests performed

    • Vulnerability categories covered

    • OWASP WSTG test cases covered

    • Signals investigated

  • The testing coverage by functional area (i.e., API endpoints, administration, applications surface, authentication & user management, Content & Publishing, File management, Infrastructure & Configuration, etc.) including the number of endpoints, security tests, and categories covered for each area.

  • The coverage by vulnerability category, with an explicit mapping to the associated OWASP WSTG test cases.

  • The list of attack techniques applied.

  • The list of WSTG test cases executed.

  • A detailed security verification that summarises the security tests performed on the most actively endpoints:

    • the techniques applied, the number of security tests, and, most importantly, a conclusion explaining why each endpoint is or is not exploitable.


Where can I find my Coverage & Activity report?

  • Go to the “Admin Panel”

  • Open an Agentic Pentest program

  • Click on “Audit reports” in the left-side menu

  • The Coverage & activity report is displayed in the list of custom reports

  • Click the “Upload” icon to be able to share it with your teams

Did this answer your question?