Export findings as PDF, CSV, or NDJSON
Three formats, one keyboard shortcut. ⌘E opens the export sheet - pick your format, choose what to include, save. Use PDF for monthly reports, CSV for spreadsheet analysis, and NDJSON when you're piping into a SIEM.
PDF report
Multi-page document with a cover page, per-host detail sections, and a remediation summary. Suitable as the attachment on a monthly security review, a client deliverable, or evidence for an audit.
- Cover - fleet snapshot date, host count, finding totals by severity, top 5 critical findings.
- Per-host - host metadata, scan timestamp, full finding list grouped by category, severity, and remediation column.
- Compliance appendix (optional) - see compliance mapping.
Generated client-side via Apple's PDFKit; nothing
leaves your Mac. Page size follows the system locale's default
(US Letter / A4); a UI toggle is planned for a future release.
CSV (flat findings)
One row per finding, one finding per row. Designed for spreadsheet pivot-table analysis or as the input to a custom reporting pipeline. Columns:
scan_time,host,category,severity,title,cve_id,detail,remediation
RFC 4180 compliant - CRLF line endings, and fields containing commas, newlines, or quotes are double-quoted with embedded quotes doubled. Encoding is UTF-8 without a byte-order mark; if Excel mis-reads accented characters, import the file rather than double-clicking it, and choose UTF-8.
NDJSON for SIEM ingest
JSON Lines - one JSON object per line, LF-delimited. Wazuh, Splunk, Elastic / OpenSearch, Loki, and most other log aggregators accept this format directly. Each line is a flat finding event; the schema:
{
"@timestamp": "2026-04-27T03:14:22Z",
"category": "cve",
"cve_id": "CVE-2024-3094",
"cvss_score": 10.0,
"description": "Malicious code in xz-utils 5.6.0/5.6.1",
"env": "prod",
"host": "edge-nuc",
"matched_cpe": "cpe:2.3:a:tukaani:xz:5.6.0:*:*:*:*:*:*:*",
"package_name": "xz-utils",
"package_version": "5.6.0",
"scan_started_at": "2026-04-27T03:14:22Z",
"severity": "critical",
"source": "noxen"
}
Every record is flat - there is no nested host or
finding object - and keys are emitted in sorted order,
so a diff between two exports is readable. category is
one of cve, open_port, tls,
http_header or admin_surface, and the
remaining keys vary by category: an open_port record
carries port and service, a
tls record carries detail, an
admin_surface record carries kind,
display_name and surface_url.
Global tags (env,
region, etc.) can be supplied when invoking the
SIEM export from the share sheet; each invocation emits one
consistent set of tags across every event in the batch, merged in
at the top level of each record, which simplifies downstream filtering (e.g. a Splunk query like
search noxen env=prod severity=critical).
A persistent Settings pane for per-tenant tag maps is planned
for a future release.
Scope picker
The export sheet asks "what do you want to export?" with three options:
- This host's latest scan - quickest, smallest export. Useful when you're focused on one box.
- All hosts, latest scan - fleet snapshot. The default for monthly reports.
- Date range - every scan between two dates, across every host. Useful for historical analysis or proving a finding was open for N days during an audit.
Where the file lands
Standard macOS save panel - pick anywhere you have write access. The default filename includes the scope and date:
noxen-edge-nuc-2026-04-27.pdfnoxen-fleet-2026-04-27.csvnoxen-fleet-2026-04-27.ndjson
Full keyboard flow: ⌘E → select format → ↵ to confirm scope → ↵ to confirm save panel. Three keystrokes from "I want a report" to "report saved".