Reports
Waratek has created a reporting tool that will ingest vulnerability data in various formats and correlate them with any enabled Waratek patches that are in place.
As Waratek’s Agents work at runtime in memory, Static Application Security Testing (SAST) tools cannot test for Waratek protections. If an application being scanned has a vulnerability, a SAST vulnerability scanner will flag the vulnerability and show that in a report.
Organizations that use Waratek could very well have Waratek protection in place for the flagged vulnerabilities, and SAST tools will not reflect this in their reports. As a result, Waratek has created a reporting tool that generates two basic report formats:
Tenable Integrations
This produces a correlation report based upon a user's Tenable scan results. This requires a Tenable account, and that the hosts to be correlated have been previously scanned.
Customer Vulnerability Reports
This allows the user to upload a file containing CVEs. Here the user can produce a report and correlate that information with the enabled patches and policies in place on an Agent.
For further information on each report type, please refer to their specific page nested under this page in the side menu.