Skip to main content

Review security findings

Findings consolidates and prioritizes the security issues detected during EASM scans, so you can quickly identify and address the highest-priority risks across your external attack surface. It aggregates the issues found across multiple assets, scans, and data sources, applies a proprietary risk-scoring model to each consolidated finding, and ranks findings from highest to lowest priority.

Use Findings to review your overall findings posture, search and filter findings, prioritize remediation, and open individual findings to view supporting evidence and recommended solutions.

Findings is built around a structured approach that simplifies how security issues are consolidated, evaluated, and prioritized:

  • Groups related instances of the same issue across the environment to reduce duplication.
  • Evaluates each aggregated finding using a proprietary scoring model.
  • Considers frequency of occurrence, asset importance, exposure, and potential business and security impact.
  • Presents findings in priority order, from highest to lowest risk.
  • Clearly indicates where action is required first.

Prerequisites

  • You must have a UI user account with the Security Lead or Reviewer role.

Get access to the Findings

Findings displays a comprehensive list of all consolidated findings, along with summary widgets that break down your findings by type, priority, severity, and asset type.

To complete this task:

  1. Sign in to the Veracode Platform.
  2. Select Scans and Analysis > EASM.
  3. From the top-left corner of the screen, select the project you want to review.
  4. Select Findings or the findings icon findings.png.

Review your findings summary

At the top of the Findings, summary widgets give you a high-level overview of your findings posture. Use these widgets to understand where risk is concentrated and to prioritize remediation.

  • Findings types: displays the total number of findings and the proportion of Smart Findings and Classic Findings. Smart Findings are enriched, consolidated findings. Classic Findings are individual detections.
  • Priority action: breaks down findings by recommended action: Fix now, Fix soon, Monitor, and Track. Each priority level shows the number of findings assigned to it.
  • Severity counts: shows the number of findings at each severity level: Critical, High, Medium, Low, and Info.
  • Findings by thing type: lists the number of findings grouped by asset type, such as Web Application, Cookie, SSL service, Certificate, Software, DNS record, File, URL, Domain, Storage Bucket, and Script variant.

The following table lists the available Things.

ThingsDescription
Web ApplicationAny software exposed on the internet, such as web applications, SSH servers, databases, and more.
CertificateSSL digital entity's identity.
CookieRetained user information stored by web applications.
DomainInternet domain names as described in WHOIS records.
FileInformation attached to a digital asset, including metadata such as creation date or file type.
SSL serviceIdentified SSL servers, each of which may support multiple HTTPS web applications.
SoftwareDistributed software entities offering specific services through well defined interfaces.
Script variantJavaScript code instances identified by checksum. A script variant is linked to either a script (from a URI) or a URL (inline script).
Storage BucketCloud storage resources that store and serve data and files.
URLUniform Resource Locators used by browsers to retrieve web resources (e.g., HTML pages, CSS, images).
DNS recordProvide information about a domain name, including its IP address, mail server, and other key data. All DNS record types are now grouped under DNS Record, while still appearing in their original contexts such as applications or domains where relevant.

To complete this task:

  1. Open the Findings.
  2. Review the Findings types, Priority action, severity, and Findings by thing type widgets at the top of the page. Use the counts to identify where the highest-priority and highest-severity risks are concentrated across your assets.

Search and filter findings

Use the search bar and column filters to locate specific findings or narrow the results based on your criteria.

Search for findings

Enter search terms to locate findings by title, thing, or evidence.

To complete this task:

  1. Open the Findings.
  2. To search for a finding, in the search bar at the top of the page, enter your search criteria, such as a finding title, thing, or evidence keyword. Results appear as you type.
  3. To view all the findings instead of just consolidated findings, select the All findings toggle next to the search bar.

Filter and sort the findings table

Sort or filter the findings table by column to focus on the findings that matter most.

To complete this task:

  1. Open the Findings.
  2. To sort findings, select the column header, such as Source, Priority action, Type, or Thing.
  3. To filter results, select the filter icon in the column header.

Review findings in the table

The findings table displays key information for each finding, including its source and classification, recommended priority action, the affected asset, supporting evidence, and recommended solution. Use this information to assess each finding and plan remediation. To view the full evidence or solution, select See more. To understand more, about indicators, see here.

View finding details

note

Because AI-generated resolutions might contain errors, carefully review all suggested resolutions before applying them. If you encounter unexpected behavior, contact Veracode Technical Support.

When you select a finding, a detail panel displays with the information you need to assess and remediate the issue, including the description, evidence, analysis, and recommended solution.

To complete this task:

  1. Open the Findings.
  2. In the findings table, select the finding you want to review.
  3. In the detail panel, review the Description, Evidence, and Recommended remediation sections to understand the issue and plan remediation.
  4. To close the panel, select the close icon at the top-right corner.

Prioritize findings for remediation

Findings are ranked from highest to lowest priority so that you can focus first on the risks that require immediate action. To support consistent and efficient remediation workflows, each finding is mapped to a priority action:

  • Fix now: findings that require immediate remediation.
  • Fix soon: findings that should be remediated in the near term.
  • Monitor: findings that should be watched for changes in risk.
  • Track: findings that are recorded for awareness and future reference.

To complete this task:

  1. Open the Findings.
  2. In the Priority action widget, review the count of findings for each priority level.
  3. In the findings table, use the Priority action column to sort or filter findings by priority. Start with Fix now findings and work through the remaining priority levels to reduce your external attack surface.