Guides
Read and triage findings
Work the findings list, read proof, and record suppression decisions.
Findings arrive normalised, deduplicated and severity-ranked. This is how to work them.
Read a finding
Open a finding to see its severity, category, confidence and status, and its proof:
- proven - a reproducible exploit ran. Trust it.
- evidence / reproducer - supporting evidence or steps.
Remember the rule: no HIGH or CRITICAL exploitation finding is shown to you unproven. A deterministic detection (SCA, secrets, misconfig, licence) is its own proof.
Triage with suppression
When a finding is a known accepted risk or a false positive, record a suppression rather than ignoring it. A suppression is scoped and carries a verdict:
| Scope | Mutes |
|---|---|
finding | This one finding. |
rule | Every finding from this rule. |
endpoint | Everything at this endpoint. |
category | A whole category. |
Suppressions are decisions, recorded and auditable - not a delete.
Occurrences
The finding row is the canonical merged record; its occurrences are the per-run history of where and when it was seen.