Reports
hxEASM can generate organization reports in JSON, CSV, PDF, and HTML formats. PDF and HTML reports use the same deterministic report view model so the sections and counts stay aligned across formats.
Report records show the user who initiated generation. Admin, hacker, and client users can generate, view, and download reports for organizations they are authorized to access.
Output Formats
| Format | Purpose |
|---|---|
json |
Machine-readable export of report data |
csv |
Spreadsheet-friendly assets and Threat export |
pdf |
Styled enterprise report for stakeholders |
html |
Styled HTML report using the embedded template and CSS |
PDF Report Structure
The PDF report is designed as an enterprise EASM report and includes:
- Cover page
- Table of contents
- Executive summary
- Organization scope
- Scan summary
- Asset inventory
- Exposure changes
- Threat summary
- Critical and high findings
- Screenshots / evidence metadata
- Detailed findings
- Recommendations
- Appendix
If a section has no data, the report renders a clean empty state instead of failing.
HTML Template
The HTML template lives at:
backend/internal/reports/templates/easm_report.html
The embedded logo lives at:
backend/internal/reports/templates/assets/logo.png
Both files are embedded with Go embed, so the API binary can render reports without depending on repository-relative paths at runtime.
Logo and Version
The report cover shows:
- hxEASM logo in HTML output
- product name
hxEASM - product version from
app.version/ build-time version wiring - organization name
- generation timestamp
- confidentiality note
The lightweight PDF renderer does not embed raster images yet; it renders a styled hxEASM brand mark and version text. HTML output embeds the logo as a base64 data URI.
Data Included
Report generation collects available data through existing repositories and services:
- organization metadata
- approved scope items
- recent or selected scans
- plugin jobs for the selected/latest scan
- assets
- threats
- file artifact metadata
- exposure changes
Asset inventory rows include lifecycle state (approved, disabled, stale) and existing criticality where the format has an asset table. JSON includes the asset fields directly; CSV, HTML, and PDF include lifecycle and criticality columns.
The report does not change scan, plugin, asset, Threat, file, or RBAC behavior.
Manual Threats are included through the same Threat query path as plugin-discovered vulnerability findings. Reports do not require every finding to have a scan ID or registered plugin source; manual findings render with source_plugin=manual.
Filters
Reports accept existing filters:
{
"format": "pdf",
"filters": {
"severity_min": "medium",
"asset_type": "webapp",
"vuln_status": "new",
"scan_id": "<scan-uuid>",
"date_from": "2026-06-01",
"date_to": "2026-06-14"
}
}
scan_id narrows scan summary, plugin jobs, files, and exposure changes when possible. Asset and Threat filters keep their previous behavior. CSV output keeps common Threat columns common; vulnerability-specific columns are prefixed with vulnerability_ and left empty for other Threat types.
Downloaded report filenames include the generation timestamp in UTC:
hxeasm-report-YYYY-MM-DD_HH-mm-ss-<report-prefix>.<format>
The short report ID suffix avoids same-second filename collisions.
Older report records without a stored creator remain readable and display an unknown initiator in the UI.
Deterministic Recommendations
Recommendations are rule-based. No LLM is used.
Examples:
- prioritize critical and high Threats
- review exposed administrative interfaces
- validate exposed services against approved scope
- disable TLS 1.0/1.1 where detected
- set Secure and HttpOnly cookie flags where applicable
- apply missing security headers where applicable
Customizing the Template
To customize HTML styling or section markup, edit:
backend/internal/reports/templates/easm_report.html
Rebuild the API after changing embedded template files.
For PDF styling, update the native renderer in:
backend/internal/reports/generator.go
Current Limitations
- PDF rendering uses the existing lightweight native PDF writer rather than a full browser HTML-to-PDF engine.
- HTML output supports richer CSS than PDF output.
- PDF screenshot embedding is not implemented yet; screenshot and evidence file metadata are included instead.
- Very large raw evidence payloads are summarized rather than dumped into the report.
Asset Criticality
Asset inventory sections include asset criticality where the format has an asset table. Reports do not calculate risk scores or infer criticality.
Asset Lifecycle
Asset inventory sections include approved, disabled, and stale state. Reports do not hide disabled assets; disabled assets remain part of inventory and historical reporting.