Skip to main content
Evidence shows what an agent tested and what happened. It supports a vulnerability with material your team can inspect to understand and reproduce the issue. An evidence item belongs to a vulnerability and can identify the run that produced it. A vulnerability may have several items that demonstrate different parts of the issue.

What evidence can include

  • Requests and responses showing how a service handled an action.
  • Screenshots capturing application behavior or exposed information.
  • Code and scripts used to reproduce a weakness.
  • Logs and other files containing observations from testing.
For example, evidence for an access-control vulnerability might include a request made as one user and a response containing another user’s data. Together, they show the action the agent took and the result that demonstrates the weakness.

Review evidence

Open a vulnerability in the platform to inspect its supporting evidence. Use it to understand the conditions that made the issue exploitable and the steps needed to reproduce it. The vulnerability’s description explains the issue; the evidence shows the observations behind that explanation.