Skip to content

10. Producing Reports

The Reports page turns what you have been looking at into something you can hand over. The Report Builder tab composes a multi-section document with a cover page and markings; the other tabs are direct exports of specific datasets.

The page has five tabs: Report Builder, POA&M Update, Hardware, DVL and Host Info.

  1. Load the scans you want to report on. The builder describes whatever is currently loaded — there is no separate selection of files.

  2. Open Reports. Report Builder is already selected.

  3. Optionally choose a preset under Start from, or load a Saved template. Either gives you a sensible set of sections to adjust rather than a blank page.

  4. Set the scope: Severity floor, Host filter (name or IP) and Include Informational.

  5. Fill in the cover details: Report title, Classification banner, System, Organization, Prepared by, and a Cover logo if you want one.

  6. In the Sections list, tick what to include and use ▲ and ▼ to set the order they appear in.

  7. Read the Preview panel on the right. It tells you how many sections, how many rows, how many Excel sheets and roughly how many PDF pages you are about to produce, and warns you about anything that will be cut short.

  8. Optionally save the whole setup as a template so next month is one click.

  9. Choose Format — Excel, PDF or Excel + PDF — and click Generate.

  10. Choose where to save the file. For Excel + PDF you are asked twice, once per file.

Field What it does
Severity floor Drops findings below the level you choose. Options are All severities (the default), Low, Medium, High and Critical.
Host filter (name or IP) Limits the report to hosts whose name or IP contains what you type. Placeholder: all hosts.
Include Informational Off by default. Informational results are enumeration data rather than weaknesses and outnumber real findings several times over.
Field Default What it does
Report title Vulnerability Report The title on the cover, and the basis of the file name.
Classification banner CUI Printed on the cover and, in the PDF, in the header and footer of every page. Clear it for no marking.
System empty The system the report covers.
Organization empty Your organization.
Prepared by your Windows user name Who produced the report. Edit it to whatever should appear.
Cover logo none Choose… picks a PNG or JPEG; ✕ removes it. The label beside it shows none, the file name, or filename.png (missing) if the file has moved.

Seventeen sections are available. Each row in the Sections list shows a checkbox, the section name, a one-line description, and a live row count on the right. Sections that would come out empty, or that will be cut short in a PDF, carry an amber note.

All sections start ticked. Use All and None to select or clear them in one click.

Section What it contains
Executive Summary Posture at a glance: hosts scanned, credentialed coverage, total findings, the count at each severity, exploitable, on the CISA KEV catalog, end-of-life, average finding age, unique plugins to remediate, and the most-affected host — with a short paragraph of context.
Severity Distribution Findings by severity as a bar chart. Zero counts are kept so the shape is honest.
Most Affected Hosts The ten hosts carrying the most findings, as a chart, with a note explaining that concentrating effort there reduces the total faster than working the list evenly.
Trend Since Last Report Change against the previous report generated over the same scope: hosts and totals then and now, with ▲ for worse and ▼ for better. Empty on your first run — there is nothing to compare against yet.
Scan Inventory Every scan file covered, with its parameters, its compliance verdict and any policy issues.
Section What it contains
Findings Every finding in scope, one row per host, plugin and port, worst first. Columns: Hostname, Host IP, PluginID, Plugin Name, Nessus Severity, DOD Severity, Port, Protocol, CVE, Publication Date, Days Since Publication, Solution, Filename/Path.
Patch Summary The same findings collapsed to one row per plugin with the number of hosts affected — the remediation worklist, ordered by reach.
Findings by Host The same findings grouped machine by machine — the per-system worklist. Columns: Hostname, Host IP, Nessus Severity, PluginID, Plugin Name, Port, Protocol, Solution.
IAVM Summary Findings carrying an IAVA, IAVB or IAVT reference, one row per advisory and plugin.
Section What it contains
Hardware Inventory One row per scanned host: name, addresses, operating system, description, MAC, DNS name, NetBIOS and whether it was credentialed.
Host Information Every host property the scanner recorded, one row per field. Long, and the most complete record of what was seen.
Software Inventory The software enumerated across your hosts, as shown on the Software page.
Ports by Host Open ports grouped by machine.
Ports by Port Open ports grouped by port, with the hosts exposing each.
Section What it contains
POA&M Status Your loaded eMASS POA&M as it currently stands, in full eMASS column layout.
Remediation Plan Your loaded remediation plan: actions, categories, owners and target dates.
Methodology and Definitions How to read the report — what the severities, ages and coverage figures mean. Five short paragraphs.

The Start from dropdown fills in the sections for a common purpose, in a sensible order. Everything stays editable afterwards.

Preset Sections, in order
Executive Summary Executive Summary, Severity Distribution, Trend Since Last Report, Most Affected Hosts, Scan Inventory, Methodology and Definitions. No raw finding tables.
Technical Findings Executive Summary, Scan Inventory, Findings, IAVM Summary, Methodology and Definitions.
Remediation Worklist Patch Summary, Most Affected Hosts, Findings by Host, Hardware Inventory, Methodology and Definitions.
Inventory Hardware Inventory, Host Information, Software Inventory, Ports by Host, Ports by Port.
Compliance Package Executive Summary, POA&M Status, Remediation Plan, Findings, Methodology and Definitions.
Everything All seventeen sections.

A template stores your whole setup: which sections and in what order, the format, the full scope, and every cover and marking field including the logo.

Action How
Save Type a name in Save current setup as and click Save. Saving over an existing name replaces it.
Load Pick it from the Saved template dropdown. Everything is restored at once and the preview refreshes.
Delete Select it and click Delete.

If you load a template built with a section that no longer exists, NESSviewer tells you: Loaded “{name}”. {n} section(s) in it are no longer available and were skipped.

The Format dropdown offers Excel, PDF and Excel + PDF; the default is Excel. Click Generate, and NESSviewer builds the document in the background — the button is disabled and a spinner appears while it works — then opens a save dialog.

The suggested file name is your report title followed by the date and time, for example Vulnerability Report-20260810-1435.xlsx. You choose the folder; there is no fixed output location.

Message Meaning
Report written to {path} Done. For both formats, both paths are listed.
Export cancelled. You cancelled the save dialog. Note that cancelling the Excel dialog in an Excel + PDF run abandons the whole thing — the PDF is never offered.
Select at least one section. Nothing was ticked. Nothing is written.
Report generation failed: {message} Something went wrong. The message gives the reason.

One row per scanned host: Hostname, HostIP, OS, Host Description, MAC Address and DNS Name. Export from the toolbar as hardware.xlsx or hardware.csv.

One row per finding, in the column layout expected for a DVL deliverable: Plugin ID, Plugin Name, DOD Severity, IP Address, Protocol, Port, Exploit Available, Mac Address, DNS Name, NetBIOS, Plugin Text, Synopsis, Description, STIG Severity, CVE, Plugin Publication Date, Patch Publication Date and Exploit Framework.

At the top right is a control group reading Excel export: All-in-one [switch] One file per scan.

Setting What the Excel export does
All-in-one (switch off) Writes a single combined workbook, dvl.xlsx.
One file per scan (switch on) Asks for a folder, then writes one workbook per scan file into it, each named after that scan’s report name. Duplicate names get (2), (3) and so on.

After a per-scan export a dialog titled DVL export confirms Exported {count} file(s) to: followed by the folder. If there was nothing to write it says No scan data to export., and a failure appears as DVL export failed with the reason.

Every host property the scanner recorded, as Hostname, Field and Value. Clicking a row opens a panel headed with the host name and the caption Host information, listing every field and value for that machine. Copy puts the whole set on the clipboard — the button reads Copied for a moment afterwards. Export as host-info.xlsx or host-info.csv.

The POA&M Update tab hosts the eMASS POA&M update tools. It works with the POA&M you loaded under Files → eMASS POA&M (chapter 4).

You need Use
A formal deliverable with a cover page and markings Report Builder, PDF or Excel + PDF
Data someone will sort, filter and work in Report Builder, Excel — every row, every column
A quick list of something specific Filter the Analyze grid and export from its toolbar (section 6.7)
A DVL for a package The DVL tab
A hardware list for a package The Hardware tab, or the Hardware Inventory section
The same report every month A saved template in the Report Builder