10. Producing Reports
The Reports page turns what you have been looking at into something you can hand over. The Report Builder tab composes a multi-section document with a cover page and markings; the other tabs are direct exports of specific datasets.
The page has five tabs: Report Builder, POA&M Update, Hardware, DVL and Host Info.
10.1 Building a report, start to finish
Section titled “10.1 Building a report, start to finish”-
Load the scans you want to report on. The builder describes whatever is currently loaded — there is no separate selection of files.
-
Open Reports. Report Builder is already selected.
-
Optionally choose a preset under Start from, or load a Saved template. Either gives you a sensible set of sections to adjust rather than a blank page.
-
Set the scope: Severity floor, Host filter (name or IP) and Include Informational.
-
Fill in the cover details: Report title, Classification banner, System, Organization, Prepared by, and a Cover logo if you want one.
-
In the Sections list, tick what to include and use ▲ and ▼ to set the order they appear in.
-
Read the Preview panel on the right. It tells you how many sections, how many rows, how many Excel sheets and roughly how many PDF pages you are about to produce, and warns you about anything that will be cut short.
-
Optionally save the whole setup as a template so next month is one click.
-
Choose Format — Excel, PDF or Excel + PDF — and click Generate.
-
Choose where to save the file. For Excel + PDF you are asked twice, once per file.
10.2 Report scope and cover markings
Section titled “10.2 Report scope and cover markings”| Field | What it does |
|---|---|
| Severity floor | Drops findings below the level you choose. Options are All severities (the default), Low, Medium, High and Critical. |
| Host filter (name or IP) | Limits the report to hosts whose name or IP contains what you type. Placeholder: all hosts. |
| Include Informational | Off by default. Informational results are enumeration data rather than weaknesses and outnumber real findings several times over. |
Cover page and markings
Section titled “Cover page and markings”| Field | Default | What it does |
|---|---|---|
| Report title | Vulnerability Report | The title on the cover, and the basis of the file name. |
| Classification banner | CUI | Printed on the cover and, in the PDF, in the header and footer of every page. Clear it for no marking. |
| System | empty | The system the report covers. |
| Organization | empty | Your organization. |
| Prepared by | your Windows user name | Who produced the report. Edit it to whatever should appear. |
| Cover logo | none | Choose… picks a PNG or JPEG; ✕ removes it. The label beside it shows none, the file name, or filename.png (missing) if the file has moved. |
10.3 The report sections
Section titled “10.3 The report sections”Seventeen sections are available. Each row in the Sections list shows a checkbox, the section name, a one-line description, and a live row count on the right. Sections that would come out empty, or that will be cut short in a PDF, carry an amber note.
All sections start ticked. Use All and None to select or clear them in one click.
Summary sections
Section titled “Summary sections”| Section | What it contains |
|---|---|
| Executive Summary | Posture at a glance: hosts scanned, credentialed coverage, total findings, the count at each severity, exploitable, on the CISA KEV catalog, end-of-life, average finding age, unique plugins to remediate, and the most-affected host — with a short paragraph of context. |
| Severity Distribution | Findings by severity as a bar chart. Zero counts are kept so the shape is honest. |
| Most Affected Hosts | The ten hosts carrying the most findings, as a chart, with a note explaining that concentrating effort there reduces the total faster than working the list evenly. |
| Trend Since Last Report | Change against the previous report generated over the same scope: hosts and totals then and now, with ▲ for worse and ▼ for better. Empty on your first run — there is nothing to compare against yet. |
| Scan Inventory | Every scan file covered, with its parameters, its compliance verdict and any policy issues. |
Findings sections
Section titled “Findings sections”| Section | What it contains |
|---|---|
| Findings | Every finding in scope, one row per host, plugin and port, worst first. Columns: Hostname, Host IP, PluginID, Plugin Name, Nessus Severity, DOD Severity, Port, Protocol, CVE, Publication Date, Days Since Publication, Solution, Filename/Path. |
| Patch Summary | The same findings collapsed to one row per plugin with the number of hosts affected — the remediation worklist, ordered by reach. |
| Findings by Host | The same findings grouped machine by machine — the per-system worklist. Columns: Hostname, Host IP, Nessus Severity, PluginID, Plugin Name, Port, Protocol, Solution. |
| IAVM Summary | Findings carrying an IAVA, IAVB or IAVT reference, one row per advisory and plugin. |
Inventory sections
Section titled “Inventory sections”| Section | What it contains |
|---|---|
| Hardware Inventory | One row per scanned host: name, addresses, operating system, description, MAC, DNS name, NetBIOS and whether it was credentialed. |
| Host Information | Every host property the scanner recorded, one row per field. Long, and the most complete record of what was seen. |
| Software Inventory | The software enumerated across your hosts, as shown on the Software page. |
| Ports by Host | Open ports grouped by machine. |
| Ports by Port | Open ports grouped by port, with the hosts exposing each. |
Compliance and appendix sections
Section titled “Compliance and appendix sections”| Section | What it contains |
|---|---|
| POA&M Status | Your loaded eMASS POA&M as it currently stands, in full eMASS column layout. |
| Remediation Plan | Your loaded remediation plan: actions, categories, owners and target dates. |
| Methodology and Definitions | How to read the report — what the severities, ages and coverage figures mean. Five short paragraphs. |
10.4 Presets
Section titled “10.4 Presets”The Start from dropdown fills in the sections for a common purpose, in a sensible order. Everything stays editable afterwards.
| Preset | Sections, in order |
|---|---|
| Executive Summary | Executive Summary, Severity Distribution, Trend Since Last Report, Most Affected Hosts, Scan Inventory, Methodology and Definitions. No raw finding tables. |
| Technical Findings | Executive Summary, Scan Inventory, Findings, IAVM Summary, Methodology and Definitions. |
| Remediation Worklist | Patch Summary, Most Affected Hosts, Findings by Host, Hardware Inventory, Methodology and Definitions. |
| Inventory | Hardware Inventory, Host Information, Software Inventory, Ports by Host, Ports by Port. |
| Compliance Package | Executive Summary, POA&M Status, Remediation Plan, Findings, Methodology and Definitions. |
| Everything | All seventeen sections. |
10.5 Saved templates
Section titled “10.5 Saved templates”A template stores your whole setup: which sections and in what order, the format, the full scope, and every cover and marking field including the logo.
| Action | How |
|---|---|
| Save | Type a name in Save current setup as and click Save. Saving over an existing name replaces it. |
| Load | Pick it from the Saved template dropdown. Everything is restored at once and the preview refreshes. |
| Delete | Select it and click Delete. |
If you load a template built with a section that no longer exists, NESSviewer tells you: Loaded “{name}”. {n} section(s) in it are no longer available and were skipped.
10.6 Generating
Section titled “10.6 Generating”The Format dropdown offers Excel, PDF and Excel + PDF; the default is Excel. Click Generate, and NESSviewer builds the document in the background — the button is disabled and a spinner appears while it works — then opens a save dialog.
The suggested file name is your report title followed by the date and time, for example Vulnerability Report-20260810-1435.xlsx. You choose the folder; there is no fixed output location.
| Message | Meaning |
|---|---|
| Report written to {path} | Done. For both formats, both paths are listed. |
| Export cancelled. | You cancelled the save dialog. Note that cancelling the Excel dialog in an Excel + PDF run abandons the whole thing — the PDF is never offered. |
| Select at least one section. | Nothing was ticked. Nothing is written. |
| Report generation failed: {message} | Something went wrong. The message gives the reason. |
10.7 The direct-export tabs
Section titled “10.7 The direct-export tabs”Hardware
Section titled “Hardware”One row per scanned host: Hostname, HostIP, OS, Host Description, MAC Address and DNS Name. Export from the toolbar as hardware.xlsx or hardware.csv.
DVL — the Detailed Vulnerability List
Section titled “DVL — the Detailed Vulnerability List”One row per finding, in the column layout expected for a DVL deliverable: Plugin ID, Plugin Name, DOD Severity, IP Address, Protocol, Port, Exploit Available, Mac Address, DNS Name, NetBIOS, Plugin Text, Synopsis, Description, STIG Severity, CVE, Plugin Publication Date, Patch Publication Date and Exploit Framework.
At the top right is a control group reading Excel export: All-in-one [switch] One file per scan.
| Setting | What the Excel export does |
|---|---|
| All-in-one (switch off) | Writes a single combined workbook, dvl.xlsx. |
| One file per scan (switch on) | Asks for a folder, then writes one workbook per scan file into it, each named after that scan’s report name. Duplicate names get (2), (3) and so on. |
After a per-scan export a dialog titled DVL export confirms Exported {count} file(s) to: followed by the folder. If there was nothing to write it says No scan data to export., and a failure appears as DVL export failed with the reason.
Host Info
Section titled “Host Info”Every host property the scanner recorded, as Hostname, Field and Value. Clicking a row opens a panel headed with the host name and the caption Host information, listing every field and value for that machine. Copy puts the whole set on the clipboard — the button reads Copied for a moment afterwards. Export as host-info.xlsx or host-info.csv.
POA&M Update
Section titled “POA&M Update”The POA&M Update tab hosts the eMASS POA&M update tools. It works with the POA&M you loaded under Files → eMASS POA&M (chapter 4).
10.8 Choosing the right output
Section titled “10.8 Choosing the right output”| You need | Use |
|---|---|
| A formal deliverable with a cover page and markings | Report Builder, PDF or Excel + PDF |
| Data someone will sort, filter and work in | Report Builder, Excel — every row, every column |
| A quick list of something specific | Filter the Analyze grid and export from its toolbar (section 6.7) |
| A DVL for a package | The DVL tab |
| A hardware list for a package | The Hardware tab, or the Hardware Inventory section |
| The same report every month | A saved template in the Report Builder |