Reports
Reports in ACE come in multiple flavors and forms.
Dashboard Views
On the Dashboard views (Security, Executive, ISSO), the widgets have the ability (depending on what they display) to be exported to PDF, HTML, CSV, or PNG format. These exports respect the filters applied to the dashboard, providing the end user the exact view they configured. To do this, click the three dots at the upper right corner of the widget, and select the appropriate export option.
Comprehensive Views
The Reports Page provides a more comprehensive ability to generate reports of environments rather than immediate slices. To get to this page, one must click on the Reporting button on the sidebar.
There are two options available in the report generator: Report Templates and a Custom Report Builder.
Report Templates
Report Templates provide pre-defined structures for generating reports quickly. The immediate types are:
- Executive
- Vulnerability Summary
- Vulnerability Detail
- Compliance Summary
- Compliance Detail
- MITRE ATT&CK Matrix
Executive reports will present the user with a security posture trend, a letter score rating for security of the environment, a breakdown of vulnerability severity, remediation activity, vulnerability trends (how many vulnerabilities of each severity are created or remediated over time), compliance trend (how the compliance status of the environment changes over time), and a compliance score, summarizing the number of passed and failed compliance checks. The report also notes environments needing attention based on the overarching security score and letter grade.
Vulnerability Summary reports provide an overview of the vulnerabilities present in the selected environments. This includes a breakdown of vulnerabilities by severity, the number of vulnerabilities discovered and remediated over time, and the current status of remediation efforts. It also gives an overview list of vulnerabilities present, their asset, CVSS, name, etcetera.
Vulnerability Detail reports provides a severity breakdown and list of vulnerabilities, like the Summary, but gives a low-level overview of each vulnerability, their assets, description, references, remediation and statistics, etcetera.
Compliance Summary reports provide an overview of the compliance status of the selected environments, namely the number of checks passed, failed, with warnings, errors, or were skipped. It provides a trendline for number of succeeding checks over time, and a high level list of compliance checks in the environment.
Compliance Detail reports provide a detailed view of each compliance check in the selected environments, including their status (passed, failed, warning, error, or skipped), description, references, remediation steps, and associated asset.
MITRE ATT&CK Matrix reports provide a heatmap representation of how vulnerabilities overlap, warming up the more vulnerabilities and higher severities are focused on specific techniques, giving the user a representation of weaknesses in their system.
Selecting a report type leads one to select environments next. One can aggregate the results into a single document, or leave each environment as an individual file within a zip folder. Afterwards, the user must select an output format: HTML or PDF.
Then one must select the Delivery method(s): Download directly or Send via Email.
Note: The Send via Email feature is work in progress and does not function currently.
Custom Report Builder
In the custom report builder, the user can select the environment(s) they wish to export, whether to aggregate them, and the output format of the report. The strength of the report builder comes from the Widget system. These allow the user to pick and choose what type of data representation they'd like present on the report. Some are filterable and can be exported as CSV files. The widgets include:
- Overall Security Score (Weighted average score across all selected environments)
- Security Posture Trend (Score trend over the last 6 snapshots per environment)
- Overall Security Posture Trend (Weighted aggregate score trend across all environments)
- Environments Needing Attention (Environments with score < 70 or unpatched critical vulnerabilities)
- Environment Health Breakdown (Score, grade, and severity counts per environment)
- Severity Breakdown (Count cards for critical/high/medium/low with aging metrics)
- Vulnerability Trend (Severity counts over the last 6 snapshots per environment)
- Overall Vulnerability Trend (Summed severity counts across all environments)
- Remediation Activity (New vs. remediated vulnerabilities per snapshot period)
- Worst Offending Assets (Top 10 highest-risk assets per environment)
- Vulnerability Summary Table (Flat table: name, asset, severity, CVSS, status, age, mitigations) (Filterable, CSV)
- Vulnerability Detail List (Full per-vulnerability breakdown with CVE, CWE, and remediation details) (Filterable, CSV)
- Compliance Score (Pass rate per environment with overall delta vs prior snapshot)
- Compliance Trend (Pass rate trend over the last 6 snapshots per environment)
- Overall Compliance Trend (Aggregate compliance pass rate trend across all environments)
- Compliance Breakdown (Status count cards with period deltas and failing-check aging buckets)
- Compliance Summary Table (Flat table: asset, status, framework, control, method, remediation, age) (Filterable, CSV)
- Compliance Detail List (Full per-check breakdown with method and remediation details) (Filterable, CSV)
Data filters can be applied to those widgets that support it. Filters include
- Severity
- Vulnerability Status
- Compliance Status
- Asset Name
One can then select the Delivery Method(s): Download directly or Send via Email.
Note: The Send via Email feature is work in progress and does not function currently.
