Skip to content

Reports

hxEASM can generate organization reports in JSON, CSV, PDF, and HTML formats. PDF and HTML reports use the same deterministic report view model so the sections and counts stay aligned across formats.

Report records show the user who initiated generation. Admin, hacker, and client users can generate, view, and download reports for organizations they are authorized to access.

Output Formats

Format Purpose
json Machine-readable export of report data
csv Spreadsheet-friendly assets and Threat export
pdf Styled enterprise report for stakeholders
html Styled HTML report using the embedded template and CSS

PDF Report Structure

The PDF report is designed as an enterprise EASM report and includes:

  1. Cover page
  2. Table of contents
  3. Executive summary
  4. Organization scope
  5. Scan summary
  6. Asset inventory
  7. Exposure changes
  8. Threat summary
  9. Critical and high findings
  10. Screenshots / evidence metadata
  11. Detailed findings
  12. Recommendations
  13. Appendix

If a section has no data, the report renders a clean empty state instead of failing.

HTML Template

The HTML template lives at:

backend/internal/reports/templates/easm_report.html

The embedded logo lives at:

backend/internal/reports/templates/assets/logo.png

Both files are embedded with Go embed, so the API binary can render reports without depending on repository-relative paths at runtime.

Logo and Version

The report cover shows:

  • hxEASM logo in HTML output
  • product name hxEASM
  • product version from app.version / build-time version wiring
  • organization name
  • generation timestamp
  • confidentiality note

The lightweight PDF renderer does not embed raster images yet; it renders a styled hxEASM brand mark and version text. HTML output embeds the logo as a base64 data URI.

Data Included

Report generation collects available data through existing repositories and services:

  • organization metadata
  • approved scope items
  • recent or selected scans
  • plugin jobs for the selected/latest scan
  • assets
  • threats
  • file artifact metadata
  • exposure changes

Asset inventory rows include lifecycle state (approved, disabled, stale) and existing criticality where the format has an asset table. JSON includes the asset fields directly; CSV, HTML, and PDF include lifecycle and criticality columns.

The report does not change scan, plugin, asset, Threat, file, or RBAC behavior.

Manual Threats are included through the same Threat query path as plugin-discovered vulnerability findings. Reports do not require every finding to have a scan ID or registered plugin source; manual findings render with source_plugin=manual.

Filters

Reports accept existing filters:

{
  "format": "pdf",
  "filters": {
    "severity_min": "medium",
    "asset_type": "webapp",
    "vuln_status": "new",
    "scan_id": "<scan-uuid>",
    "date_from": "2026-06-01",
    "date_to": "2026-06-14"
  }
}

scan_id narrows scan summary, plugin jobs, files, and exposure changes when possible. Asset and Threat filters keep their previous behavior. CSV output keeps common Threat columns common; vulnerability-specific columns are prefixed with vulnerability_ and left empty for other Threat types.

Downloaded report filenames include the generation timestamp in UTC:

hxeasm-report-YYYY-MM-DD_HH-mm-ss-<report-prefix>.<format>

The short report ID suffix avoids same-second filename collisions.

Older report records without a stored creator remain readable and display an unknown initiator in the UI.

Deterministic Recommendations

Recommendations are rule-based. No LLM is used.

Examples:

  • prioritize critical and high Threats
  • review exposed administrative interfaces
  • validate exposed services against approved scope
  • disable TLS 1.0/1.1 where detected
  • set Secure and HttpOnly cookie flags where applicable
  • apply missing security headers where applicable

Customizing the Template

To customize HTML styling or section markup, edit:

backend/internal/reports/templates/easm_report.html

Rebuild the API after changing embedded template files.

For PDF styling, update the native renderer in:

backend/internal/reports/generator.go

Current Limitations

  • PDF rendering uses the existing lightweight native PDF writer rather than a full browser HTML-to-PDF engine.
  • HTML output supports richer CSS than PDF output.
  • PDF screenshot embedding is not implemented yet; screenshot and evidence file metadata are included instead.
  • Very large raw evidence payloads are summarized rather than dumped into the report.

Asset Criticality

Asset inventory sections include asset criticality where the format has an asset table. Reports do not calculate risk scores or infer criticality.

Asset Lifecycle

Asset inventory sections include approved, disabled, and stale state. Reports do not hide disabled assets; disabled assets remain part of inventory and historical reporting.