Exports · 4 min read

Export findings as PDF, CSV, or NDJSON

Three formats, one keyboard shortcut. ⌘E opens the export sheet - pick your format, choose what to include, save. Use PDF for monthly reports, CSV for spreadsheet analysis, and NDJSON when you're piping into a SIEM.

PDF report

Multi-page document with a cover page, per-host detail sections, and a remediation summary. Suitable as the attachment on a monthly security review, a client deliverable, or evidence for an audit.

Generated client-side via Apple's PDFKit; nothing leaves your Mac. Page size follows the system locale's default (US Letter / A4); a UI toggle is planned for a future release.

CSV (flat findings)

One row per finding, one finding per row. Designed for spreadsheet pivot-table analysis or as the input to a custom reporting pipeline. Columns:

scan_time,host,category,severity,title,cve_id,detail,remediation

RFC 4180 compliant - CRLF line endings, and fields containing commas, newlines, or quotes are double-quoted with embedded quotes doubled. Encoding is UTF-8 without a byte-order mark; if Excel mis-reads accented characters, import the file rather than double-clicking it, and choose UTF-8.

NDJSON for SIEM ingest

JSON Lines - one JSON object per line, LF-delimited. Wazuh, Splunk, Elastic / OpenSearch, Loki, and most other log aggregators accept this format directly. Each line is a flat finding event; the schema:

{
  "@timestamp": "2026-04-27T03:14:22Z",
  "category": "cve",
  "cve_id": "CVE-2024-3094",
  "cvss_score": 10.0,
  "description": "Malicious code in xz-utils 5.6.0/5.6.1",
  "env": "prod",
  "host": "edge-nuc",
  "matched_cpe": "cpe:2.3:a:tukaani:xz:5.6.0:*:*:*:*:*:*:*",
  "package_name": "xz-utils",
  "package_version": "5.6.0",
  "scan_started_at": "2026-04-27T03:14:22Z",
  "severity": "critical",
  "source": "noxen"
}

Every record is flat - there is no nested host or finding object - and keys are emitted in sorted order, so a diff between two exports is readable. category is one of cve, open_port, tls, http_header or admin_surface, and the remaining keys vary by category: an open_port record carries port and service, a tls record carries detail, an admin_surface record carries kind, display_name and surface_url.

Global tags (env, region, etc.) can be supplied when invoking the SIEM export from the share sheet; each invocation emits one consistent set of tags across every event in the batch, merged in at the top level of each record, which simplifies downstream filtering (e.g. a Splunk query like search noxen env=prod severity=critical). A persistent Settings pane for per-tenant tag maps is planned for a future release.

Scope picker

The export sheet asks "what do you want to export?" with three options:

Where the file lands

Standard macOS save panel - pick anywhere you have write access. The default filename includes the scope and date:

Full keyboard flow: ⌘E → select format → ↵ to confirm scope → ↵ to confirm save panel. Three keystrokes from "I want a report" to "report saved".