Burp Suite User Forum

Create new post

Report

Imran | Last updated: Oct 26, 2015 11:20AM UTC

Team, Currently we are able to get report of identified vulnerabilities. But we want to get Clearance Report as well. Like If we have no vulnerabilities identified then We want a Clearance report That No issue identified etc.. or if there are few issues identified then Report should mention That Following are the Vulnerability Identified and alo list all Issues that are Cleared Thanks

PortSwigger Agent | Last updated: Oct 27, 2015 12:04PM UTC

Burp's reporting function just reports the issues that were identified. It doesn't try to make any statement that no other issues are present. You would need to carry out whatever other testing is appropriate before being in a position to make such a conclusion.

PortSwigger Agent | Last updated: Feb 19, 2016 09:37AM UTC

False positive issues are excluded from the report and there isn't a way to include them without unmarking them as false positives.

Burp User | Last updated: Jul 12, 2016 08:35PM UTC

On similar topic, for audit purpose - I am using Pro version 6.39, would like to include "false-positive" issue in my Burp scan report. Current report doesn't include this -- is there a way I can export false-positive issues as part of Burp Scan report? Thanks, Vinay

Burp User | Last updated: Jul 16, 2019 08:19PM UTC

Is there no way to get a report that shows either 1) You had some issues that you identified as False Positives which shows you researched and made a determination or 2) You ran the tool and it did not identify any issues? This is so basic I cannot grasp how that is not available. Having a report to this affect from the tool is what product stake holders want to see before you push out a new release. Yes, you can create a report yourself that says this but having something that the tool creates is essential. Please consider adding this functionality.

Liam, PortSwigger Agent | Last updated: Jul 18, 2019 10:53AM UTC

Thanks for your feedback Jim. Are your feature requests in regards to Burp Pro or Burp Enterprise?

Burp User | Last updated: Oct 29, 2019 02:49PM UTC

Hi there Liam / Portswigger support. I would like to request this feature as well, from Dafydd Stuttard above: The ability to choose whether False Positive findings are included in a report within Burp Pro. As it is now, if I go through and validate that all the findings on a scan are false positive, there is no way to generate a report that shows this. The report generation wizard will not open if there are no non-FP findings. I should be able to open the wizard, and simply select a checkbox that I want FP findings included. Thank you, Karl

Mike, PortSwigger Agent | Last updated: Oct 30, 2019 08:57AM UTC

Karl, I have registered your interest with this feature request. We will notify this thread if it gets implemented.

Rui | Last updated: Nov 10, 2022 07:35PM UTC

Any update on this? What is the ETA for delivering on this functionality? Rui

Hannah, PortSwigger Agent | Last updated: Nov 11, 2022 09:46AM UTC

Hi This is currently an ongoing feature request. I've added your +1 to this to help us prioritize this work in the future. There is no ETA available at the moment.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.