XML API Interface Technical Document

This document is released as legacy documentation and is no longer updated.


Using the Outpost24 XML API will allow your company or third parties to integrate the OUTSCAN or HIAB solution into your own applications using an extensible XML interface. This guide is intended for those who are going to use the Outpost24 XML API. Read the Getting Started section before you start developing your application.

Getting Started

This manual provides the technical guidance required to integrate to the Outpost24 platform using a proprietary, XML-based interface. This interface is designed to provide clients with a straightforward way of how to create a connection to Outpost24. It is easy to integrate into applications and requires skills and knowledge that are familiar to most web developers.

The Outpost24 XML API features a rich set of functions, which will allow you to customize the output and request different types of information from within the system. As you can see in the illustration below, all the things that you can do from the graphical user interface can be performed from the XML API.

Processing API Requests:

The server will allow you to do either GET or POST request but if you have a request which might transfer a larger amount of data in the parameters then it's wise to use the POST request instead since that is capable of handling larger requests.

The default date and time format used by the system is yyyy-MM-dd HH:mm (Java formatting style). The time format is 24 hours so the following is an example, which refers to last day of the year right before midnight: 2012-12-31 23:59

The time zone used in the system is GMT. If you need it in another time zone you need to convert it by yourself.

The character encoding used by the system is UTF-8.

All URI parameters that are used when requesting information are case sensitive.

Basic Information

The request for the API is done against either the OUTSCAN system or the HIAB appliance/instance.

If done against the against the OUTSCAN system the URI is the following:

On the HIAB the XML API is located at the following URI:


When connecting to the API you should use something that is referred to as an application token called APPTOKEN. This makes it possible for you to perform a single request with a predefined users access right.

Note that the token generated should be carefully protected since it will allow direct access with out the requirement of authentication. Should you test the request in a browser, regenerate the token afterwards when the solution is put into production since the old version has been stored in the browser history.

The token can be generated under Main Menu > Settings > Account > Security Policy. In the bottom of that screen you will have a selection called Application Access Token and this is the one that will provide you access to the API without performing multiple requests.

Once the token is generated, add it to any request that you would like to perform using the parameter APPTOKEN.

For example:



Read the Appendix A to see how the responses are encapsulated in XML.

Country Codes

A complete and up to date list of supported country codes by system can be retrieved from the system. Whenever the country field is given to the system it will be validated against these values. See Appendix E.

Required Keys

Example request:

Example response:


Response Keys
TIMEZONEThe time  zone used by this country.
VCAREACODEThe area code used for this country.
VCNAMEThe name of the country.
XIDThe unique identifier of the given object.

Information In Session (License Information)

This Request will give you information regarding your license and other settings. The output below is a reflection of our test account and therefore some of these fields may not be present on your account.

Required Keys

Example request:

Example response:

         <NAME>Api Api</NAME>
         <LASTLOGONDATE>2014-02-18 08:53</LASTLOGONDATE>
         <SERVERTIME>2014-02-18 08:59</SERVERTIME>
         <USERROLE>Super User</USERROLE>

Response Keys
ACCEPT_RISKSIs the account allowed to accept risks.
ACCEPTEDLENGTHThe number of days the vulnerability has been accepted.
ACCEPTTARGETSBoolean value if the user is allowed to accept.
ALL_TARGETGROUPSSet to 1 if not all targets are available.
AUDITCHANGERISKLEVELBoolean flag if the user is required to supply an audit comment when changing a risk level for a report finding.
AUDITRISKACCEPTANCEBoolean flag if the user is required to supply an audit comment when accepting a risk.
AUDITSCANPOLICYMANAGEMENTBoolean flag if the user is required to supply an audit comment when doing a scan policy management.
AUDITSCHEDULEMANAGEMENTBoolean flag if the user is required to supply an audit comment when doing a schedule management.
AUDITTARGETMANAGEMENTBoolean flag if the user is required to supply an audit comment when doing a target  management.
COMPANYThe name of the company for this account.
COUNTRYThe country for this account, See Country Codes section.
COUNTRYCODEThe country code for this account, See Country Codes section.
CSRFVALIDATIONBoolean flag if the Cross Site Request Forgery function should be enabled.

Can this account view the dashboard.

DATEFORMATThe format that should be used when presenting dates.
EMAILEmail address for this account.
FORCEGROUPSCHEDULINGBoolean flag which will enforce only use of groups if set.
GMTOFFSETThe offset from GMT used when displaying time information in this account.
ISSERVICESBoolean flag whether this account can supply reports in the service.
IS_ADMINBoolean flag whether the account has administration rights.
IS_SALESBoolean flag if this account is a sales organization.
IS_SUBUSERBoolean flag whether account is a sub account.
LANGUAGEThe language for this account. See Country Codes section.
LASTLOGONDATEThe last date this account was logged on to.
LASTLOGONIPFrom which IP the login occurred.
MANAGEDSERVICESLIMITEDBoolean flag if the service reports access can bi limited per sub user.
MAXIPThe maximum number of targets the account is allowed to use in the OUTSCAN system.
MAXPCIIPThe maximum number of targets the account is allowed to add to the PCI system.
MAXWEBAPPSThe maximum number of WEB applications this account is allowed to use.
MOBILEMobile/Cellphone number associated with this account.
NAMEThe user name which was used during log in.

The number of log in that this account has done since it was created.

P3DAYSThe Number of days before a task of priority level 3 is escalated.
P4DAYSThe Number of days before a task of priority level 4 is escalated.
P5DAYSThe Number of days before a task of priority level 5 is escalated.
P3LABELText label for priority level 3.
P4LABELText label for priority level 4.
P5LABELText label for priority level 5.
PACTIVEBoolean flag whether this account is active or not.
PCIDISPUTINGCan this account dispute PCI findings.
PCIEMAILADDRESSThe primary email address used for contact when doing PCI disputes.
PCIREPORTINGCan this account access  PCI reports.
PCISCHEDULINGCan this account schedule PCI scans.
PCISCOPINGCan this account change PCI scope.
PCI_SUBUSERIs this account a sub user in the PCI solution.
PRODUCTA list of products which is associated with this account.
RECEIVE_EMAILCan this account receive report email.
RECEIVE_SMSCan this account receive SMS notifications.
REPORT_DELETECan this account delete reports.
REPORT_DISABLECan the user mark findings as false positives.
SCANPOLICYOWNERSHIPBoolean flag if newly created scan policies should be visible to all users.
SCAN_REPORTSCan the user see reports.
SCAN_SCHEDULINGCan this account modify scan schedulings.
SCAN_SETTINGSCan this account modify scan settings.
SCAN_VERIFYCan this account perform verify scans.
SERVERTIMEThe local time of the server.
SERVICESBoolean flag whether this account has the service product.
SESSIONTIMEOUTThe session timeout in minutes.
SHOWGUIDEBoolean value which tells if the guide should be showed upon login.
SHOWMONITORBoolean flag whether to display the monitor application in the menu.
SHOWPCIINFOBoolean flag whether the PCI information window should be displayed.
SHOWRELEASENOTESBoolean flag if release notes should be presented when you log in (Please note that this field may not be present).
SHOWVALIDATIONRECOMMENDATIONBoolean flag if the two factor tip should be displayed after log in.
STARTDAYOFWEEKFirst day of week.
STARTPAGEInternal value. Used by the GUI.
STATEThe state for this account.
STOPSCANCan this account stop running scans.
STRATEGYBoolean flag whether this account has the strategy product.
SUBUSERXIDThe unique id for this sub user.
SUPERUSERDoes this account have the same rights as the main account.
SYSTEMThe name of the system you have connected to.
TARGETGROUP_ADMINCan this account change target groups.
TARGET_ADDCan this account add target.
TARGET_DELETECan this account remove target.
TIMEFORMATThe format that should be used when presenting time.
TWOFACTORAUTHENTICATIONMETHODMethod used for two factor authentication.
USERNAMEThe user name which was used during login.
USERROLEThe roles the user is granted.
USERROLES_ADMINCan this account change the user roles.
VERSIONThe version of the system you are connected to.
WEBAPPADMINCan this account manage web application settings.
WEBAPPDELETEREPORTCan this account remove web application reports.
WEBAPPREPORTINGCan this account view application reports.
XIDThe unique identifier of the given object.
XIPARENTIDThe unique id for any parent object for this object within the system.

State Codes

A complete and up to date list of supported state codes by the system can be retrieved from the system. Whenever  the state field is given to the system it will be validated against these values. See Appendix F.

Required Keys

Example request:

Example response:


Response Keys
COUNTRXIDThe country id.
TIMEZONEThe time  zone used by this state.
VCNAMEThe name of the state.
XIDThe short form of the name for this state.


This section describes how to change user name, password, and any account details.

See the List Account section for information about the meaning of the different fields that can be changed.

It also reports any restraints that may be present on your account, for example if you do not have access to all targets.

Update Account

This section describes how you can change user name, password, and other account details.

Required Keys

Optional Keys

Along with the above required key you can also submit any of the additional keys in case you would like to update them.

Optional Keys
LANGUAGEThe language set on the user profile.
PASSWD1Change password, you are required to submit PASSWD1, PASSWD2, and VCOLDPASSWORD in order to update it.
PASSWD2Change password, you are required to submit PASSWD1, PASSWD2, and VCOLDPASSWORD in order to update it.
SESSIONTIMEOUTThe timeout value used when determine if the users session should be considered invalid.
VCCOUNTRYThe country the user is located in.
VCEMAILThe users email address within the system.
VCFIRSTNAMEThe first name (spoken name) of the user.
VCLASTNAMEThe last name (surname) of the user.
VCOLDPASSWORDChange password, you are required to submit PASSWD1, PASSWD2, and VCOLDPASSWORD in order to update it.
VCPHONEDAYThe phone number of the user.
VCPHONEMOBILEThe mobile phone number of the user.
VCUSERNAMEThe name of the user which we would like to log in to.

Example request:


The above given request generates a generic response.

More information about this response type is available in Appendix A.

List Account

This function allows you to see the settings on your account along with any restrictions that may be present.

Required Keys
XIDThe unique identifier of the given object.

Example request:

Example response:

         <PARENT>Top Level</PARENT>
         <DLASTLOGON>2014-02-18 08:59</DLASTLOGON>
         <DEMAIL>2012-10-30 12:58</DEMAIL>
         <COUNTRY>United Kingdom</COUNTRY>

Response Keys
ALLSCANNERSBoolean flag which determines if the account has access to all scanners (only valid in a distributed HIAB environment).
ALLWEBBoolean flag if the account has access to all web application scanning scopes.
AUTHENTICATIONMETHODFlag for determining if the user is authenticated via the internal system or a LDAP/AD solution.
AUTOMATICGMTBoolean flag which will automatically set the GMT offset if true (will use the country details for this).
BACCEPTRISKSet if the account is allowed to accept risks in the report section.
BACTIVESet if the account is enabled.
BADMINUSERGROUPSet if the account is able to administer user roles.
BDISCOVERYEMAILSet if the account is allowed to receive discovery results e-mails.
BHADMINSet if the account is allowed to perform HIAB administrative tasks.
BHMONITORSet if the account is allowed to use the monitor utility.
BOADMINGROUPSSet if the account is allowed to administer groups.
BOALLHOSTSSet if the account has access to all targets.
BODELETEIPSet if the account is able to delete targets from the system.
BODELETEREPORTSet if the account is able to remove report from the system.
BODISABLESet if the account is able to disable scripts.
BOEMAILSet if the account is allowed to receive email notifications.
BOREPORTSSet if the account is allowed to read reports.
BOSCHEDULESSet if the account is allowed to schedule scans.
BOSETTINGSSet if the account is allowed to change scan settings on schedules (scan policies).
BOSMSSet if the account is allowed to receive SMS notifications.
BOVULTEXTSet if the account is allowed to comment vulnerabilities.
BOWAIVERSet if the account has accepted the waiver.
BREMOVEREPORTSet if the report should be removed after it has been sent out via e-mail.
BREPORTTYPEThe report type that should be included in the e-mail.
BSECURITYEMAILSet if the report should be sent out in a e-mail.
BSMSREPORTSet if the account is allowed to receive SMS notifications on reports.
BSUBADMINSet if the account is allowed to administer sub users.
BSUBUSERSet if the account is a sub user.
CHANGEPASSWORDONLOGONSet if the password is required to be updated upon the initial log in.
COUNTRYThe country for this account.
CUSTOMCOMPANYNAMEThe defined custom company name for this account.
CUSTOMREPORTFOOTERCustom text which will be available in the footer of the exported PDF report.
CUSTOMREPORTHEADERCustom text which will be available in the header of the exported PDF report.
DASHBOARDBoolean flag if the user have access to the dashboard.
DATEFORMATThe date format which will be used when presenting date information within the system.
DEMAILThe date when the initial e-mail was sent out.
DLASTLOGONThe date when the account last logged on to the system.
EXTERNALWEBAPPSCANSLEFTThe number of external web applications scans that are left on this account.

Flag if you are forced to use the groups instead of free text target definition in the schedule section.

GMTOFFSETThe offset from GMT where this user is located (used to display the correct local time in the system).
GROUPLIST/Comma separated list of granted groups for this account.
HIABEXTERNALWEBAPPSThe total number of external web application scans for this account.
IEMAILTYPEThe type of to send out (HTML/text).
IEXTERNALSCANSLEFTThe number of external scan left on this account.
IFAILEDLOGONThe number of failed login on this account.
ILOGONThe total number of login on this account.
IPCISCANSLEFTThe number of PCI scans left on this account.
ISECURITYLEFTThe number of scans left on this account .
ITESTThe number of scans on this account.
LANGUAGEThe language for this account.
MANAGEDSERVICESBoolean flag if the user has managed service.
MANAGEDSERVICESCOMMENTComment on the manager service.
MAXIPThe maximum number of IPs allowed to be defined on this account.
MAXPCIIPThe maximum number of PCI IPs allowed to be defined on this account.
MAXPCISCANThe maximum number of PCI scans allowed to be defined on this account.
MAXSCANThe maximum number of scans allowed to be defined on this account.
MAXWEBAPPSThe maximum number of web application scans allowed to be defined on this account.
PACTIVESet if parent account is enabled.
PARENTThe parent id.
PASSWORDAGEThe maximum age of a password before you are required to change it.
PCIDISPUTINGSet if the account is allowed to dispute PCI findings.
PCIREPORTINGSet if the account is allowed to see PCI reports.
PCISCHEDULINGSet if the account is allowed to schedule PCI scans.
PCISCOPINGSet if the account is allowed to change PCI scoping.
RISKAGEThe maximum age of a risk before it violates the company policy.
SCANNERLISTList of granted scanners for this account.
SHOWGUIDESet if the initial guide will be displayed upon log in.
STARTDAYOFWEEKValue for determining which is the first date of the week.
STATEThe state which the user is located within.
STOPSCANBoolean flag if the user is allowed to stop scans.
SUPERUSERSet if the user has the same access rights as the main account holder.

Boolean flag if system notifications should be sent out to this user.

TARGETLISTThe target list as accepted by the graphical user interface.

The parent account which will receive any tickets assigned to this user if they haven't been resolved within the defined due date.

TIMEFORMATThe time format to use when displaying time throughout the system.
TWOFACTORAUTHENTICATIONBoolean value if two factor authentication is required.

List of assigned user roles for this account.

VCCOMPANYThe company name for this account.

The country for this account.

VCEMAILThe e-mail address associated with this account.

The first name of the user.

VCFULLNAMEThe full name (both first and last name) of the user.
VCLASTNAMEThe surname of the user.
VCPASSWORDThe password for the user which we try to log in with.

Current state of the scan.

VCUSERNAMEThe name of the user which we would like to log in to.
VERIFYSCANBoolean flag if the user can perform verify scan.
WASMAXIMUMLINKSThe maximum number of WAS links that this user can scan.
WEBAPPADMINSet if the account can administer the WAS module.
WEBAPPDELETEREPORTSet if the account is allowed to delete WAS reports.
WEBAPPREPORTINGSet if the account is allowed to see WAS reports.
WEBAPPSCANSNumber of WAS scans in total.
WEBAPPSCANSLEFTNumber of WAS scans left on this account.
WEBAPPTRIALSet if the accounthas a trial account for the WAS module.
XHIABCLOSEDSet if the accountHIAB has been disabled.
XHIABEXTERNALIPThe number of external IPsthat the HIAB can have defined.
XHIABIPThe number of IPs allowed on this HIAB.
XHIABSCHEDULEThe number of scans for this account.
XHIABSCHEDULEADDThe number of scans to add for this account.
XIDThe unique identifier of the given object.
XISUBPARENTIDThe unique id for any parent object for this object within the system.
XPATHUPInternal use only.
XPCIIPThe number of PCI targets that this account is allowed to have.
XPCISCANThe number of PCI scans that this account is allowed to perform.
XVCIPThe IP number which this account logged on from the last time.


In the system you can create additional attributes which can be made available in different sections.

You can for instance add a Business function field so that this information can be defined and visible in the exported reports if required. It is also possible to define these attributes on users so that you for instance can add his/her role within the company.

The combo type allows you to define a drop down menu which contains static values (this can be used to prevent input errors due to spelling errors).

Update Attribute

This request will allow you to redefine the attribute (and also disable it since it cannot be removed). Within the system you can have 10 attributes defined at the same time

Required Keys
ACCEPTABLEVALUESThis field allows you to define which values are accepted for this specific attribute.

Boolean flag if this attribute is active.

COLUMNIDThe unique column identifier for this attribute. Up to 10 are allowed to be defined.
EXPORTREPORTBoolean flag if this attribute is available in exported reports.

The field type defines what type this field has.
Available field types:
0 : Text
1 : Combo
2: Check box
3 : Number

NAMEThe name of the attribute.
ONUSERBoolean flag if this attribute is available on users.

Boolean flag if this attribute is available in reporting.

REQUIREDBoolean flag if this attribute is required to have a value.
TARGETThe target that this entry is about.

Example request:

The above given request will generate a generic response.

More information about this response type is available in Appendix A.

List Attributes

Additional attributes are possible to define in the system. These can for instance be defined as additional values which can be made availble in the target, user or report section.

Required Keys

Example request:

Example response:

         <NAME>Geographic location</NAME>

Required Keys
ACCEPTABLEVALUESThis field allows you to define which values are accepted for this specific attribute.

Boolean flag if this attribute is active.

COLUMNIDThe unique column identifier for this attribute. Up to 10 are allowed to be defined.
EXPORTREPORTBoolean flag if this attribute is available in exported reports.

The field type defines what type this field has.
Available field types:
0 : Text
1 : Combo
2 : Check box
3 : Number

NAMEThe name of the attribute.
ONUSERBoolean flag if this attribute is available on users.

Boolean flag if this attribute is available in reporting.

REQUIREDBoolean flag if this attribute is required to have a value.
SCHEDULINGShould this attribute be available in the schedule section.
TARGETThe target that this entry is about.
XIDThe unique identifier of the given object.
XUSERXIDThe unique user id.

Manage User Accounts

This section describes how to add sub users and define their access rights and roles. An unlimited amount of sub users can be added to the system and they can also be added in an hierarchy so that you can define users that will manage and maintain other users.

The user roles will give you the possibility to create roles within the system that will fit your organization. For example, if you have managers that only should be able to receive reports, they can simply be added and restricted to only perform such action within the system.

User Roles

The user roles are predefined roles which can be assigned to multiple users which will help you when managing the access to the different actions which can be performed within the system.

You can for example create user roles like the following:
   SOC - Team
   System owner
   Vulnerability Manager - User
   Vulnerability Manager - Manager
   Network administrator

It is of course also possible to make them user specific if you have a smaller organization:
   Jane Doe
John Smith

Update User Roles

In order to add or update an user role you need to supply the following parameter.

Required Keys
VCNAMEName of the user role.

Optional Keys

If you would like to create a new role you would enter "-1" (or not supply it at all) as the value for the XID parameter but if you would like to update an already present role you need to supply the unique identification number for that role in that field instead.

Optional Keys
XIDThe unique identifier of the given object.

Example request:

The above given request will generate a generic response.

More information about this response type is available in Appendix A.

List User Roles

The user roles are predefined roles which can be assigned to multiple users which will help you when managing the access to the different actions which can be performed within the system.

Required Keys

Example request:

Example response:

         <VCNAME>My User Role</VCNAME>

Response Keys
BACCEPTRISKCan the user mark a risk as accepted.
BADMINUSERGROUPCan the user administer user roles.
BHADMINCan the user restart the HIAB and setup the HIAB settings, such as backup and networking.
BHMONITORCan the user access the network monitor module.
BOADMINGROUPSCan the user administer targets and target groups.
BODELETEIPCan the user delete targets.
BODELETEREPORTCan the user delete scans.
BODISABLECan the user mark a vulnerability as false positive.
BOEMAILCan the user receive scan report e-mails.
BOREPORTSCan the user show scan reports.
BOSCHEDULESCan the user administer scan schedules.
BOSETTINGSCan the user administer scanning policies.
BOSMSIs the user allowed to receive SMS notifications.
BOVULTEXTCan the user change vulnerability comments.
BOWAIVERShould the waiver be displayed to the user.
BSUBADMINSet if the account is allowed to administer sub users.
DASHBOARDBoolean flag if the user have access to the dashboard.
FORCEGROUPSCHEDULINGIf enabled then no Target List section will be available in the Scheduling section.
MANAGEDSERVICESCan the user access the managed report section.
MANAGEDSERVICESCOMMENTCan the user add comments to managed reports.
PCIDISPUTINGCan the user dispute findings in the PCI reports.
PCIREPORTINGCan the user access the PCI reporting section.
PCISCHEDULINGCan the user change the PCI scheduling.
PCISCOPINGCan the user change the PCI scoping.
STOPSCANCan the user stop running scans.
VCNAMEName of the user role.
VERIFYSCANCan the user perform verify scans.
WEBAPPADMINCan the user administer the web application scanner.
WEBAPPDELETEREPORTCan the user remove the web application scans.
WEBAPPREPORTINGCan the user access the web application scan reports.
XIDThe unique identifier of the given object.

Remove User Role

In order to remove an already defined user role you need the unique identification number for that specific role. This is received from the list of already defined user roles ( See section: List User Roles).

Required Keys
XIDThe unique identifier of the given object.

Example request:

The above given request will generate a generic response.

More information about this response type is available in Appendix A.

Users Accounts

The user account section contains information regarding how your account or sub accounts are defined.

This is also the location where you can change the password on you account. The account details will also provide you with any limitations that may be present on the defined sub accounts within the system.

Update Account

In order to add or update an user account you need to supply the following parameters. If you would like to create a new account you would enter "-1" as the value for the XID parameter but if you would like to update an already present account you need to supply the unique identification number for that role in that field instead.

Required Keys
VCCOUNTRYThe country for this account.
VCEMAILThe e-mail address associated with this account.
VCFIRSTNAMEThe first name of the user.
VCLASTNAMEThe surname of the user.
VCUSERNAMEThe name of the user which we would like to log in to.
XIDThe unique identifier of the given object.

Example request:

The above given request will generate a generic response.

More information about this response type is available in Appendix A.

List Accounts

In order to see the available defined user roles which you can assign to your sub users you need to retrieve a list of them where you will get the unique identification number of it (XID).

The request has the following parameters:

Required Keys

Example Request:

Example Response:

         <PARENT>Top Level</PARENT>
         <DLASTLOGON>2012-05-25 12:54</DLASTLOGON>
         <DCREATED>2009-06-25 11:54</DCREATED>
Response Keys
ALLSCANNERSBoolean flag which determines if the account has access to all scanners (only valid in a distributed HIAB environment).
AUTHENTICATIONMETHODFlag for determining if the user is authenticated via the internal system or a LDAP/AD solution.
BACTIVESet if your account is enabled.
BOALLHOSTSBoolean value if the user has access to all OUTSCAN hosts.
BSUBADMINSet if the account is allowed to administer sub users. (Please note that this field may not be present).
COUNTRYThe country for this account.
CUSTOM1Custom attributed defined on either an user or a target. (Please note that this field may not be present).
DCREATEDThe date when this account was created.
DEMAILThe date when the initial eamil was sent out.
DLASTLOGONThe date when the account last logged on to the system.
GROUPLISTComma separated list of granted groups for this account.
IEMAILTYPEThe type of email to send out (HTML/text).
ILOGONThe total number of logins on this account.
PARENTThe parent account for this account.

List of granted scanners for this account.

SHOWGUIDESet if the initial guide will be displayed upon log in.

Value for determining which is the first date of the week.

SUPERUSERSet if the user has the same access rights as the main account holder.

Boolean flag if system notifications should be sent out to this user.

TARGETLISTThe target list as accepted by the graphical user interface.
TICKETPARENTThe parent account which will receive any tickets assigned to this user if they haven't been resolved within the defined due date.
TWOFACTORAUTHENTICATIONBoolean value if two factor authentication is required.
USERGROUPLISTList of assigned user roles for this account.
USERGROUPNAMESList of user roles that is assigned to this account (Please note that this field may not be present).

The e-mail address associated with this account.


The first name of the user.

VCFULLNAMEThe full name (both first and last name) of the user.
VCLASTNAMEThe surname of the user.
VCUSERNAMEThe name of the user which we would like to log in to.
WASMAXIMUMLINKSThe maximum number of WAS links that this user can scan.
XIDThe unique identifier of the given object.
XISUBPARENTIDThe parent id of this sub user.
XPATHUPInternal use only.

Remove Account

In order to remove an already defined account you need the unique identification number for that specific account. This is retrieved from the list of already defined user account (See section: List Accounts).

Required Keys
DELETENOTEAudit note which may be required.
XIDThe unique identifier of the given object.

Example request:

The above given request will generate a generic response.

More information about this response type is available in Appendix A.

Manage Targets

This section will describe how you can manage your assets within the system. The grouping system will allow you to store the same target in multiple groups which will allow you to define for example groups based on the following:

Geographical location:
   North America
   South America

Business function

Or even based on asset type:
   Web servers
   Mail servers
   DNS servers
   Database servers


The targets are either IP addresses or host names of system that you would like to perform vulnerability management against. The targets can be added automatically to the system by performing a discovery scan.

On the targets you can also define multiple attributes and also partial scan policies that should only apply to a single host.

Insert Targets

In order to add a target you need to supply the following parameters.

Required Keys
ADDNOTEAudit note that may be required.
GROUPThe group id to add this target into. Set the value to -1 for none.

The target list as accepted by the graphical user interface.

Example request:

The above given request will generate a generic response.

More information about this response type is available in Appendix A.

Update Targets

Inordet to update a target you need to supply the following parameters.

Required Keys
ADDNOTEAudit note that may be required.

Custom attributed defined on either an user or a target.


Custom attributed defined on either an user or a target.

CVSS_CDPCVSS Collateral Damage Potential.
CVSS_SR_AVAILCVSS Security Requirements - Availability.

CVSS Security Requirements - Confidentiality.


CVSS Security Requirements - Integrity.

CVSS_TDCVSS - Target Distribution.
HIDDENURLSHidden URI that are present on this target that you would like to include in the scan.
HOSTNAMEThe FQDN of the host.
MACADDRESSThe targets MAC address
VIRTUALHOSTSThe virtual hosts for this target.
XIDThe unique identifier of the given object.

Example request:

The above given request will generate a generic response.

More information about this response type is available in Appendix A.

List Targets

In order to see all targets which has been added to the system on your profile you need to supply the following details.

Required keys

Example request:

Example response:


Response keys

Authentication type used:
   0 : SMB
   1 : SSH.

CONFIRMEDBoolean flag if this target is confirmed within the PCI section.
CUSTOM0Custom attributed defined on either an user or a target.
CUSTOM1Custom attributed defined on either an user or a target.
CUSTOM2Custom attributed defined on either an user or a target.
CUSTOM3Custom attributed defined on either an user or a target.
CUSTOM4Custom attributed defined on either an user or a target.
CUSTOM5Custom attributed defined on either an user or a target.
CUSTOM6Custom attributed defined on either an user or a target.
CUSTOM7Custom attributed defined on either an user or a target.
CUSTOM8Custom attributed defined on either an user or a target.
CUSTOM9Custom attributed defined on either an user or a target.
CVSS_CDPCVSS Collateral Damage Potential.
CVSS_SR_AVAILCVSS Security Requirements - Availability.

CVSS Security Requirements - Confidentiality.

CVSS_SR_INTEGCVSS Security Requirements - Integrity.
CVSS_TDCVSS - Target Distribution.
HOSTNAMEThe FQDN of the host.

The IP address of the target.

LASTDISCOVERYDATEThe last date when the discovery scan was executed (Please note that this field may not be present).
LATESTSCANDATEThe latest scan date of this target (Please note that this field may not be present).
LATESTSCANSTATUSThe latest scan status of this target.
LATESTSUCCESSFULSCANDATEThe last date whena scan was successfully done against this target (Please note that this field may not be present).
LIMITEDThe presence of this field indicates that the response has been limited by the use of the "limit" parameter in the request.
MACADDRESSThe targets MAC address
PCIBoolean flag if this target is part of the PCI product.
PCICOMPLIANCEBoolean flag if this target is PCI compliant.
PLATFORMThe detected platform for this target.
SCANNERIDThe scanner id which this target will be tested from.
SCANNERNAMEThe scanner name of the above scanner id.
SYNCInternal use only.
USESLICENSEBoolean value if this target utilize any license.

The virtual hosts for this target.

XIDThe unique identifier of the given object.

Remove Targets

In order to remove a target you need the unique identification number for that specific target. This is retrieved from the list of already defined targets (See section: List Targets).

Required keys
DELETENOTEAudit note which may be required.
XIDThe unique identifier of the given object.

Example request:

The above given request will generate a generic response.

More information about this response type is available in Appendix A.


A couple of special target groups are in the system by default (these can not be removed or updated):

All Targets: This group contains all the targets that have been added to the system.

Ungrouped: contains all targets that are not present in another group defined within the system.

The group system will allow you to store the same target in multiple groups. This opens up for the possibility to create groups specifically for reporting, scheduling, target assignment and event notifications.

Update Group

In order to update a group you need to supply the following parameters.

Required keys
NAMEName of the group
XIDThe unique identifier of the object that you would like to update. Omit or set to -1 if you would like to add a new group to the system.

Optional Keys

This function is not only for adding a group which the example shows you. You can of course also add or remove targets with the use of that function. In order to do that you should supply either of the following parameters to the request. You would need to know the unique id values of the targets in order to add them but they can be extracted from the system, please see the List Target section.

Optional keys
ADDTARGETLISTComma separeted list of unique targets id which you would like to add to the group.
REMOVETARGETLISTComma separeted list of unique targets id which you would like to remove from the group.

Example Request:

The above given request will generate a generic response.

More information about this response type is available in Appendix A.

Target Group

In order to see all the groups which has been added to the system on your profile you need to supply the following details.

Required keys

Example Request:

Example Response:

         <NAME>All targets</NAME>

Response keys

Description of the object.


The number of targets within this scan scope.

LIMITEDThe presence of this field indicates that the response has been limited by the use of the limit parameter in the request.

The name of the attribute.

REPORTBASEDBoolean flag if this group is based on a report filter.
RULEBASEDBoolean flag if this group is based on a target filter.
XIDThe unique identifier of the given object.

The unique id for any parent object for this object within the system.

Remove Group

In order to remove a target you need the unique identification number for that specific group. This is retrieved from the list of already defined groups (See section: List Groups).

Required keys
XIDThe unique identifier of the given object.

Example Request:

The above given request will generate a generic response.

More information about this response type is available in Appendix A.

Manage Schedule

This is the section where you perform the scheduling of the target scans, creates scanning policies and see the status of the scans.

The scan history section will allow you to see when a scan started, ended, duration and any errors that might have occurred during the scan.

Scan policies will allow you to change the settings for the scan so that you can either go deeper into the targets (with the use of authenticated scan) or change the selection of test to be utilized during the scan. The system comes with a predefined set of scanning policies which will allow you to perform simplified, normal or extend scans.

There is an unsafe scanning policy defined. Please note that this is NOT supposed to be used against a live production environment. The intention with this scan policy is to use it prior to putting a server into production as a form of acceptance test. Please make sure that you have a working backup just in case when performing such a scan.

The scan schedules section will allow you to set up simple or complex scanning rules with scan windows and against already defined targets or groups as for dynamic network ranges.

In the running scans part you will be able to extract the currently running scans along with their status. These can then either be paused or stopped depending on your requirements.

Scan History

In order to see what has been executed in the past on your account you can retrive a scan log which will contain the history of your scanning.

Required keys

Optional Keys

The following parameters can be supplied in case you would like to exclude specific entries from being retrieved.

Required keys
EXCLUDEEMPTYBoolean value if empty scan logs should be included in the results.
ITYPEThe type of this entry, see Appendix C.

Example Request:

Example Response:

         <DSCANSTARTDATE>2006-05-31 06:57</DSCANSTARTDATE>
         <DSCANENDDATE>2006-05-31 06:59</DSCANENDDATE>
Response key
CANUPDATEBoolean flag if this entry can be updated using the SLS feature.
COMPLIANTBoolean flag which shows if the target where compliant according to the PCI guidelines in case the scan refers to such a target.
CONFIRMEDBoolean flag if this target is confirmed within the PCI section.
DISCOVERYTEMPLATEName of the discovery job if it's a discovery.
DSCANENDDATEThe date and time when the scan ended.
DSCANSTARTDATEThe date and time when the scan started.
FROMHIABBoolean flag which is set to 1 if the scan originated from a HIAB (only viable on OUTSCAN).
HASWASSTATSBoolean flag if the target has web application scanning statistics.
IIDInternal use only.
ITYPEThe type of this entry, see Appendix C.
LASTBoolean value if this is the latest entry for this target.

Date and time when this scan where last updated using the SLS thechnology.

LIMITEDThe presence of this field indicates that the response has been limited by the use of the limit parameter in the request.
SCANLESSBoolean value if this is an SLS update of the report.
SCANNERIDThe scanner id which this target will be tested from.
SCANNERNAMEThe name of the scanner where this action takes place.
SCANTIMEThe total amount of time the scan took.
SCHEDULEJOBThe name of the schedule job which is associated with this entry.
SUBMITTEDBoolean flag if this target is a PCI target and that the report has not been submitted yet in this quarter.
TARGETThe target that this entry is about.

The scan policy utilized by this object.

VCHOSTThe IP or host name of the target which where tested.
XIDThe unique identifier of the given object.
XIPXIDThe unique identifier of the target object.
XSCANJOBXIDThe unique identifier of the scan job log object which contain all individual targets (entry with scan type set in the 20 range).

The unique identifier of the schedule object which contain the schedule preferences.

XTEMPLATEThe unique identifier of the scan policy utilized by this object.

Scan Policy

The scan policy is used to define rules and settings for the scan to use when it is executed.

These scan policies allows you to specify what test to execute and also provide specific settings for different services.

Update Scan Policy

In order to add or uppdate scan policy you need to supply the following parameters. If you would like to create a scan policy you would enter "-1" as the value for the XID parameter but if you would like to update an already present role you need to supply the unique identification number for that scan policy in that field instead.

Required keys
NAMEThe name of the scan policy.
XIDThe unique identifier of the given object.

Example request:

The above given request will generate a generic response.

More information about this response type is available in Appendix A.

List Scan Policy

In order to see a list of available scanning policies you shall supply the following information. The scanning policies allows you to define credentials for different services that may be available. This may allow the scanner to log in and retrieve additional information like which patches are installed on the tested server and hence produce a more accurate report.

Required keys

Example request:

Example reponse:

         <NAME>Port scan</NAME>
         <DESCRIPTION>This scan policy will only perform a port scan on the defined TCP and UDP ports within the policy.</DESCRIPTION>

Response key
DESCRIPTIONShort description of the scan policy.
DISABLEFAMILYLISTA comma separated list of families that has been disabled in this scan policy.
DISABLESCRIPTLISTA comma separated list of script ids that has been disabled in this scan policy.

A comma separated list of families that has been enabled in this scan policy.

ENABLESCRIPTLISTA comma separated list of script ids that has been enabled in this scan policy
GLOBALBoolean flag if the template is avialable to other users within your company.
LIMITEDThe presence of this field indicates that the response has been limited by the use of the limit parameter in the request.
NAMEThe name of the template.
OWNERThe owner of the object.
XIDThe unique identifier of the given object.

Remove Scan Policy

In order to remove a scan policy job you need the unique identification number for that specific scan policy. This is retrieved from the list of already defined scanning policies (See section: List Scan Policies).

Required keys
XIDThe unique identifier of the given object.

Example request:

The above given request will generate a generic response.

More information about this response type is available in Appendix A.

Scan Schedule

The schedules are groups of targets on which you would like to execute scans against at specific times. A schedule can be set to repeat at a certain interval but also be set to only run once or started manually.

Update Scan Schedule

In order to add or update an user role you need to supply the following parameters. If you would like to create a new role you would enter "-1" as  the value for the XID parameter but if you would like to update an already present role you need to supply the unique identifier for that role in that field instead.

Required keys
NAMEThe name of the schedule job that you would like to add/update
XIDMUST be set to "-1" if you do not update an already existing schedule.
XUSERXIDMUST be supplied, this value can be retrieved from the LOGINDATA function.

Example request:

The above given request will generate a generic response.

More information about this response type is available in Appendix A.

List Scan Schedule

In order to see all the scheduled jobs which has been added to the system on your profile you need to supply the following details.

Required keys

Example request:

Example Response:

         <LATESTSCANDATE>2009-11-19 12:00</LATESTSCANDATE>
         <NAME>Application server</NAME>
         <OWNER>Daniel Fredriksson</OWNER>

Response key
ADDTOGROUPXIDAdd found targets to the following group (if schedule jod is a discovery scan)
AVERAGESCANDURATIONThe average scan time.
CONCURRENTSCANSNumber of concurrent scansallowed in this schedul job

CVSS Collateral Damage Potential.


CVSS Security Requirements - Availability.

CVSS_SR_CONFCVSS Security Requirements - Confidentiality.
CVSS_SR_INTEGCVSS Security Requirements - Integrity.
CVSS_TDCVSS - Target Distribution.
DAYWEEKMONTHFlag if specific day of week or month should be used (available on monthly scanning).
DELETEDBoolean value if this entry is marked as removed and should not be displayed.
DISABLEPROTOCOLFlag regarding which process should be disabled during discovery.
DNSLOOKUPBoolean flag if a DNS lookup should be performed on all targets that are added in case this schedule is in discovery mode.
EMPTYTARGETGROUPBoolean value if the groupwhich we add targets t oshould be emptired prior to adding newly discovered targets.
FREQUENCYThe frequency of the scheduled time for this job.

Boolean flag if targets has been/shall be retrieved from a LDAP/AD server.

GROUPLISTComma separated list of granted groups for this account.

The number of targets which will be scanned by this schedule.

LASTSCANDATEWhen this schedule will no longer be re-schedule.
LATESTSCANDATEWhen this schedule was scanned the latest time.
LATESTSCANDURATIONThe duration of the latest scan.
LATESTSCANSTATUSThe latest scan status of this schedule.
MAXSCANTIMEThe maximum amount of time allowed to scan this schedule.
NAMEThe name of the schedule job.
NETBIOSLOOKUPBoolean flag if a NetBIOS lookup should be performed on all targets that are added in case this schedule is in discovery mode.
NEXTSCANDATEThe next time this schedule will be executed.

The owner of this schedule job (used when sending out notification).

SCANLESSBoolean flag if this schedule job should update daily.
SCANMODEThe mode of this schedule job (discovery, discovery/scan, scan).
SCANNERIDThe scanner id which this target will be tested from.
SCANWINDOWDELAYThe delay between scan windows (in days).
SCANWINDOWSThe number of allowed scan windows for this schedule.

The target list as accepted by the graphical user interface.

TEMPLATEIDThe scanning policy used by this schedule.
WAKEONLANDELAYThe delay before starting a scan against a target which has been woken up for testing.
XIDThe unique identifier of the given object.
XSUBUSERXIDThe unique identifier of sub account that has created this schedule (Please note that this field may not be present).

Remove Schedule

In order to remove a schedule job you need the unique identification number for that specific schedule job. This is retrived from the list of already defined schedule jobs ( See section: List Schedule).

Required keys
XIDThe unique identifier of the given object.

Example request:

The above given request will generate a generic response.

More information about this response type is available in Appendix A.

Running Scan

In this section you can view the currently running scans and if required you can either pause ( and resume ) or stop any running scans.

List Running Scans

In order to see a list of currently running scans you shall supply the following information.

Required keys

Example request:

Example response:

         <DSCANSTARTED>2012-11-16 10:45</DSCANSTARTED>
         <DSCANSTART>2012-11-16 10:45</DSCANSTART>
         <DSCANEND>2012-11-16 22:45</DSCANEND>
Response key
BPAUSEBoolean flag if the scan is marked as paused.
BSTOPBoolean flag if the scan is marked as stopped.
COMPANYThe name of the company for this account
DBSCHEMAInternal use only.

Date and time information when the scan will terminate if not already finished.

DSCANSTARTDate and time information when the scan shall start.
DSCANSTARTEDDate and time information when the scan started.
FROMLDAPRetrieve targets from the configured LDAP/AD server.
HOSTNAMEThe FQDN of the host.
IATTACKERIDThe internal attacker id which this scan is running from.
ICOUNTThe number of targets within this scan scope.
IPERCENTVThe percentage value of the progress of the scan.
ISPAUSEDBoolean flag if the scan is paused.

Boolean flag if the scan is stopped.

ITHREADIDThe thread identification number within the system. Used for performing actions upon specific scans.
IVERIFYBoolean flag if the running scan is a verification scan.
LOOKUPBoolean flag if any discovered targets will perform a lookup upon adding them to the system.

The scan policy which will be used on scan started by a discovery/scan type of scan (Please note that this field may not be present).

PROBEIDThe unique probe identification number.
REASONThe comment that will be used when adding targets to the system if the are detected (Please note that this field may not be present). 
REMOTEXIDInternal use.
RESUMINGBoolean flag if this scan is resumed from a previously paused scan.

The unique identifier of the report which is updated using the SLS feature.

SCANNERIDThe scanner id which this target will be tested from.

The name of the scanner where this action takes place.

SCANSCHEMAInternal use.
SCANSENTBoolean flag if the scan has been sent to the designated scanner.
SCANWINDOWDELAYThe delay between scan windows (in days).
SCANWINDOWSThe number of allowed scan windows for this schedule.

Boolean flag if the results will utilize smart filtering.


The available types of targets:
0 : IP
1 : Host name
2 : NetBIOS name.

TEMPLATEThe scan policy utilized by this object (Please note that this field may not be present).
TXREPORTDeprecated (Please note that this field may not be present).
TXSETTINGSText settings for this scan.
VCGNAMEInternal use.
VCJOBNAMEThe name of the schedule job.
VCPERCENTText representation of the percentage value.

Should be set to W in order to only see Web Applications scan status.

VCSTATECurrent state of the scan.
VCSTATUSCurrent status of the scan.
VCTARGETText representation of the target.
WAKEONLANBoolean flag if targets should woken up by the WOL feature.
WAKEONLANDELAYThe delay before targets will be scanned since the WOL request is sent.
XIDThe unique identifier of the given object.
XIPXIDThe unique identifier of the target object.
XSCANJOBXIDThe unique identifier of the scan job log object which contain all individual targets (entry with scan type set in the 20 range).
XSOXIDThe unique identifier of the schedule object which contain the schedule preferences.
XSUBUSERXIDThe unique identifier of sub user which this object is connected to.
XTEMPLATEThe unique identifier of the scan policy used by this object.

The unique user id.

Start a Scan

In order to start a scan you need to supply the unique identification number for a specific schedule. This can retrived from the schedule list (See section: List schedule).

Required keys
ONLYSCANNOWShould be set to 1.
XIDThe unique identiefier of the given object.


The above given request will generate a generic response.

More information about this response type is available in Appendix A.

Pause a Scan

In order to pause a currently running scan you need to supply the unique identification number for that specific scan. This can be retrived from the scan list (See section: List running scans).

Required keys
XIDThe unique identifier orf the given object.

Example request:,13&ACTION=PAUSESCAN

The above given request will generate a generic response.

More information about this response type is available in Appendix A.

Resume a Scan

In order to resume a currently paused scan you need to supply the unique identification number for that specific scan. This can be retrived from the scan list (See section: List running scans).

Required keys
XIDThe unique identifier orf the given object.

Example request:,13&ACTION=RESUMESCAN

The above given request will generate a generic response.

More information about this response type is available in Appendix A.

Stop  a Scan

In order to stop a currently running scan you need to supply the unique identification number for that specific scan. This can be retrived from the scan list (See section: List running scans).

If you would like to stop all running scans then you should supply -1 as the XID value.

Required keys
XIDThe unique identifier orf the given object.

Example request:,13&ACTION=STOPSCAN

The above given request will generate a generic response.

More information about this response type is available in Appendix A.

Manage Reports

Here you can see the result of a scan and also export the results to different formats (PDF, Excel and XML). This section will also provide information regarding additional tasks that can be performed on single entries, like for instance how to accept a reported risk in a report.

There are several actions that can be performed upon a single report entry, such as assign task, accept risk, perform verify scan and comment vulnerability.

The different report types that you can export are the following:

Delta report - Shows that has changed between the latest and the selected previous report. The information will contain added and removed findings a long with any newly opened or closed ports. This is very useful when you need to determine what has changed between two scanning occurrences.

Overview report - Shows in which vulnerability families you currently have you reported vulnerabilities.

Solution report - This will give you information regarding how many issues will be resolved by applying the unique solutions for the selected report. With this information it's really easy to determine where you have your quick wins that you can apply and drastically reduce your risk level with minimal workload.

Trend report - This will provide statistics for the number of high, medium and low risks over time for the selected target.

Report Selection

This section will guide you through the different requests that you are required to perform in order to retrieve a report. This will contain requests like how to retrieve the schedules, templates or plain lists or targets which are available in the report.

There are two different ways to retrieve the reports. These are:

  1. From a group (list) - All targets currently defined in that group(s) will be used to present a report.
  2. From a host (list) - Only the individual selected target(s) will be used to generate a report.

The above ways of retrieving the reports will be explain in the following section.

Report Target

This is the sectioin where you receive information about the actual finding for a specific target. With the use of the filtering and addional parameters that can be defined you have a very powerful way of extracting information from the system based on your requirements.

Required keys
GROUPSComma separated list of groups which you would like to retrive the targets for.
TARGETSComma separated list of targets which you would like to retrive the target report target information for.


Example reponse:

         <SCHEDULEJOB>Application server</SCHEDULEJOB>
         <DFIRSTSEEN>2009-11-05 12:00</DFIRSTSEEN>
         <DLASTSEEN>2009-11-05 12:00</DLASTSEEN>
         <DATE>2009-11-05 12:00</DATE>
         <VCNAME>Port scanner</VCNAME>
         <FINDINGDATE>2009-11-05 12:00</FINDINGDATE>

Response keys
ACCEPTCOMMENTWritten comment that shall describe why the finding has been marked as an accepted risk (Please note that this field may not be present).
ACCEPTEDBoolean value if the report entry has been marked as an accepted risk.

For how many days was the entry accepted.

ACCEPTEXPIRESThe end date when the finding is no longer accepted automatically.
AGEThe number of days since the first occurrence of this specific finding.
ASSIGNEEThe user who is assigned to this specific entry.

Boolean value if this entry is marked as a potential false positive.

BNEWBoolean value if this finding wasn't reported on the previous report for this target.
BPCIBoolean value if this finding is related to PCI.
CUSTOM0Custom attributed defined on either an user or a target (Please note that this field may not be present).
CUSTOM1Custom attributed defined on either an user or a target (Please note that this field may not be present).
CUSTOM2Custom attributed defined on either an user or a target (Please note that this field may not be present).
CUSTOM3Custom attributed defined on either an user or a target (Please note that this field may not be present).
CUSTOM4Custom attributed defined on either an user or a target (Please note that this field may not be present).
CUSTOM5Custom attributed defined on either an user or a target (Please note that this field may not be present).
CUSTOM6Custom attributed defined on either an user or a target (Please note that this field may not be present).
CUSTOM7Custom attributed defined on either an user or a target (Please note that this field may not be present).
CUSTOM8Custom attributed defined on either an user or a target (Please note that this field may not be present).
CUSTOM9Custom attributed defined on either an user or a target (Please note that this field may not be present).
CVSSSCOREThe calculated CVSS score for this finding.
DATEReport date and time.
DFIRSTSEENDate and time when this finding where first reported for this target and service.

The date and time when this finding where seen the last time for this target and service.


The date and time when this finding where either verified or updated from the SLS scanning.


Name of the global template usedwhen performing the scan if any.

HASEXPLOITSBoolean flag if the vulnerability has a known exploit.

The FQDN of the host.


The calculated number of the target (if IPv4) (Please note that this field may not be present).


The port where this issue has been detected.

IPROTOCOLThe protocol where this issue has been detected (See

The risk value for this finding
0 : Information
1 : Low
2 : Medium.
4 : High


Boolean flag if this finding has been added since the last scan.

LIMITEDThe presence of this field indicates that the response has been limited by the use of the "limit" parameter in the request.
ORIGINALRISKLEVELThe original risk level if it has been changed.

The calculated PCI CVSS score.


The platform that has been detected upon this target.

POTENTIALFALSEBoolean flag if this finding is a potential false positive.

The name of the scanner where this action takes place.

SCHEDULEJOBThe name of the schedule job which where used when performing this scan.
SERVICENAMEThe name of the service which where used when performing this scan.

The available types of targets:
0 : IP
1 : Host name
2 : NetBIOS name


What type of entry this is:
0 : Port
1 : Information
2 : Vulnerability

VCBUGBugtraq ID for this finding.
VCCVECVE ID for this finding.
VCFAMILYThe vulnerability family which this entry falls under.
VCNAMEThe name of the vulnerability.
VCTARGETText representation of the target.
VCVHOSTThe virtual host where this vulnerability has been detected.
VCVULNIDThe unique vulnerability id for this entry.
VERIFIEDBoolean flag if this finding has been verified scanned.
XIDThe unique identifier of the given object.
XIPXIDThe unique identifier of the target object.
XTEMPLATEThe unique identifier of the scan policy utilized by this object.

Report Template

Using predefined templates when retrieving reports allows you to use saved filters when selecting what should be present in the report.

How to define a template will not be covered by this documentation. This document will rather function as a guide to what the different values represent for your knowledge. It is only includded here in so that you can use it when selecting what the content should be in the report. When using a template you will only submit the filtering section to the backend.

Required keys

The type of scan which you would like to recieve the templates for.

Valid values:
2 : WAS

Example request:

Example reponse:

         <NAME>High risks - All targets</NAME>
         <OWNER>John Doe</OWNER>

Response keys
ISPUBLICBoolean flag if this template is publicly available to all your sub users.
NAMENema of the report template.
OWNERThe creator of this template.

The type of scan which you would like to receive the templates for.

Valid values:
2 : WAS

SERVERFILTERThe filter for this template.
STATEThe filter used by the GUI to display this template.
TARGETGROUPSThe selected groups for this template.
TARGETSThe selected targets for this template.
XIDThe unique identifier of the given object.
XUSERXIDThe unique user id.


In order to retrieve scanning results you need to supply the which targets and/or groups that you would like to receive them for. The targets and group cat either be single or multiple ones with the use of a comma separated list of their unique identification key. How to retrieve these identification keys are described in the Report selection section.

Retrive Report Entries

In order to retrieve scanning resultyou need to supply the following information.

Required keys
GROUPSComma separated list of unique group identifiers to be included in the report.
TARGETSComma separated list of unique target identifiers to be included in the report.

Optional Keys

If based on a schedule object you should provide it's unique identification number in the following paramater.

Optional keys
SCANLOGXIDThe unique scan log entry id for the schedule job which you would like to retrieve reports for.


Example response:

         <SCHEDULEJOB>Application server</SCHEDULEJOB>
         <DFIRSTSEEN>2009-11-05 12:00</DFIRSTSEEN>
         <DLASTSEEN>2009-11-05 12:00</DLASTSEEN>
         <DATE>2009-11-05 12:00</DATE>
         <VCNAME>Port scanner</VCNAME>
         <FINDINGDATE>2009-11-05 12:00</FINDINGDATE>

Response keys
ACCEPTCOMMENTThe comment given when this vulnerability was accepted (Please note that this field may not be present).
ACCEPTEDBoolean value if the vulnerability has been accepted.
ACCEPTEDLENGTHThe number of days the vulnerability has been accepted.
ACCEPTEXPIRESThe date when the vulnerability no longer is accepted.
AGEThe number of days since the first occurrence of this specific finding.
ASSIGNEEThe user who has a ticket assigned to him/her for this entry.
BFALSEPOSBoolean value if this vulnerability is marked as a false positive or not.
BNEWBoolean value if this finding wasn't reported on the previous report for this target.
BPCIBoolean value if this report is a PCI report.
CUSTOM0Custom attributed defined on either an user or a target.

Custom attributed defined on either an user or a target.

CUSTOM2Custom attributed defined on either an user or a target.
CUSTOM3Custom attributed defined on either an user or a target.
CUSTOM4Custom attributed defined on either an user or a target.
CVSSSCOREThe CVSS score for this vulnerability.
DATEThe date and time when this scan was performed.
DFIRSTSEENThe date and time when this finding was first detected on this host.
FINDINGDATEThe date and time when this finding was updated.

The global template that was used if any.

HASEXPLOITSBoolean flag if the vulnerability has a known exploit.
HASFPCOMMENTBoolean flag if the target has false positive comments.
HOSTNAMEThe FQDN of the host.
IPORTThe port where this vulnerability was detected upon.
IPROTOCOLThe protocol used when detecting this vulnerability.
IRISKThe risk level that this vulnerability is graded to. See appendix G.
ISADDEDBoolean value if this vulnerability has been added after the initial scan.
LIMITEDThe presence of this field indicates that the response has been limited by the use of the limit parameter in the request.
ORIGINALRISKLEVELThe original risk level for this vulnerability.
PCICVSSSCOREThe PCI CVSS score for this vulnerability ( Does not reflect DOS ).
PLATFORMThe detected platform for this vulnerability.
POTENTIALFALSEBoolean value if this vulnerability are a potential false positive.
SCANNERNAMEThe name of the scanner where this action takes place.
SCHEDULEJOBThe name of the schedule job which is associated with this entry.
SERVICENAMEThe name of the service listening on this port and protocol.
TARGETTYPEThe available types of targets:
0 : IP
1 : Host name
2 : NetBIOS name.
TYPEThe entry report type.
VCBUGThe Bugtraq ID for this vulnerability.
VCCVEThe CVE reference for this vulnerability.
VCFAMILYThe family name of this vulnerability.
VCNAMEThe name of this vulnerability.
VCTARGETText representation of the target.
VCVHOSTThe virtual host name where this vulnerability was detected.

The unique script identification number given to this vulnerability.

VERIFIEDBoolean value if this finding has been verified or not.
XIDThe unique identifier of the given object.
XIPXIDThe unique identifier of the target object.
XTEMPLATEThe unique identifier of the scan policy utilized by this object.

Export Report

You can also export the report in a predefined format like PDF, Excel spreadsheet or into XML. In order to export a report you need to supply the selection criteria which where used to retrieve the report in the first place along with the next request.

Required keys
FORMATShould be set to either PDF, XLS or XML.
LASTQUERYThe parameters used to retrive the report. This parameter should be URL encoded.


The length of the selected period.


The period that you would like to have the report for:
1 : Week
2 : Month
3 : Year

REPORTTYPEThe report type that you would like to extract. See Appendix I.

Example request:

The response will be in a binary format. This format is dependent on the given parameters in the request.

Report Actions

This section will describe additional actions that can be taken upon the reports. Accepted risk will allow you to add information on a specific finding where it clearly states that the finding is an accepted risk within your organization and when and for how long the finding is to be considered accepted. The accepted risk functionality can be set up to automatically accept new finding of the same type, so if the specific finding appears in another location it can be automatically accepted. During the accepted period that has been defined (or forever) the finding will automatically be marked as an accepted risk and contain the original comment.

Mark false positive should be used to send back feedback to the support team. It should not be used instead of the accepted risk feature since a false positive is something that has reported upon the wrong circumstances and not something that you don't think apply to your organization. If you think that it doesn't affect your organization or if you added compensating controls, then you should use the accepted risk and provide the reasoning within that comment. This will provide the report readers with the information that compensating controls are put into place and which person that supplied those details when.

Using the Verify functionality allows you to perform a scan against the target just using that single test. The verify function doesn't deduct any scans from your license so you are free to re-test if the remediation has resolved the reported issues.

The Comment vulnerability feature allow you to add information on a specific vulnerability that will also be present in the report.

Each finding can also be assigned to a specific user within the system. There is a built in ticketing system that should be used to track the remediation process.

Accept Risk

You can choose to accept a reported vulnerability by accepting the risk it will expose the company for.

Required keys

The comment to be included in the report regarding why it has been accepted.

ACCEPTFORALLTARGETSBoolean value if the risk should be accept on all targets which currently have this risk.
ACCEPTFOREEVERBoolean value if the risk is accepted forever.
ACCEPTRISKADDThe number of days you accept the risk.
XIDThe unique identifier of the given object

Example request: 

The above given request will generate a generic response.

More information about this response type is available in Appendix A.

Mark False Positives

In order to mark a finding as a false positive you need the unique identifiction number for that specific report entry.

Required keys
INFORMATIONText comment which will be available in conjunction with the false positive.
SENDINFOShould be set to 1 if you would like to notify Outpost24 support department regarding this entry.
XIDThe unique identifier of the given object.


The above given request will generate a generic response.

More information about this response type is available in Appendix A.


You can perform a verification scan of a specific finding. This will just perform the check for the specific vulnerability and the result will be present in the report afterwards. This can be done on all types of findings except the following : Port scanning entires and those that are of the family Web Application Scanner (WAS).

Required keys
XIDThe uniq identifier of the given object.

Example request:

The above given request will generate a generic response.

More information about this response type is available in Appendix A.

Comment Vulnerability

You can add comments to vulerabilities in the report. This is done by suplying the following information.

Required keys
COMMENTThe comment which should be associated with this vulnerability.
ISCOMMENTMust be set to 1 or true in order to add a comment.
XIDThe unique identifier of the given object.

Example request:

The above given request will generate a generic response.

More information about this response type is available in Appendix A.

Removed Marked False Positive

In order to remove the reported false positive you can perform an update on that specific report entry and reset the Boolean value to zero.

Required keys
BFALSEPOSBoolean value which should be set to 0 in order to remove the false positive flag from this entry.
XIDThe unique identifier of the given object.

Example request:

The above given request will generate a generic response.

More information about this response type is available in Appendix A.

Assign Report Entry as Ticket

You can mark findings as a task for any of you sub user s to take action upon. In order to do that you need to supply the following information.

Required keys
DUEDATEThe due date for this task.
IDThe task identification number. Should be set to NEW if you would like to create a new entry.
MESSAGEThe message which will be connected to this task.
MULTIPLEBoolean value if the is regarding multiple entries or not.
NAMEThe name of the task.
PRIORITYThe priority of this task. Value 1-5.
STATUSThe current status of the task.
TASKIDThe task identification number. Should be set to -1 if you would like to created a new entry.

Example request:

The above given request will generate a generic response.

More information about this response type is available in Appendix A.

Report Types

This section will describe the other report types that can be extracted from the system.

Delta report:

This report will show you the differences between two selected reports (or previous). This is handy when you would like to see what has changed since the last time of scanning. It will display your changes both on the specific vulnerabilities and also any changes in the number of open ports. The changes are reported on the added or removed basis so it really easy to see what has been resolved (removed) and what needs to be prioritized (added).

Overview report:

The overview report will show you how the findings are distributed over vulnerability family and also upon which port you have the most reported issues.

Solution report:

This report will provide you with the "QUICK WINS", that is the "make me look good" list. It will provide the information where you gain the most risk reduction with least amount of work required. Instead of report based on the vulnerability it will display the findings based on their solution, so if updating to the latest version of a version would resolve multiple issues they will only have one entry in the solution report with the number of vulnerabilities that will be resolved by applying the required solution.

Trend report:

This report will give you a historical representation of how the number of high, medium and low risk has evolved during the selected trend period.

Delta Report

You can get a delta view over how the vunerabilities are changed during different periods.

Required keys
GROUPSThe unique group identification number which you would like to get the delta for.

The number of periods.


1 = week
2 = month
3 = year

PORTBoolean value if you would like to include delta information on the open/closed port with the response.
SCANLOGXIDThe unique scan log identifier that you would like to get the delta view for.
STARTSCANXIDA scan log id wich you would like to compare the the selected report with.
TARGETSThe unique target identification number which you would like to get the delta for.


Example response:

         <FIRSTREPORTDATE>2009-10-09 12:57</FIRSTREPORTDATE>
         <LASTREPORTDATE>2009-11-06 09:38</LASTREPORTDATE>

Response keys
ADDEDThe number of vulnerabilities which where added between the two dates.
FIRSTREPORTDATEThe first report date which is used in the comparison.
HIGHNumber of high risk.
IPADDRESSThe IP address which this delta is for.
LASTREPORTDATEThe last report date which is used in the comparison.
LOWNumber of low risks.
MEDIUMNumber of medium risks.
REMOVEDThe number of vulnerabilities which where removed between the two dates.
SCANNERNAMEThe name of the scanner where this action takes place.
UNCHANGEDThe number of vulnerability which where unchanged between the two dates.

Text representation of the target.

XIDThe unique identifier of the given object.
XIPXIDThe unique identifier of the target object.

Overview Report

You can get an overview over how the vulnerabilities are distributed based on different criteria.

Required keys
GROUPBYWhich overview you would like to have. Currently the following are available: VCFAMILY | IRISK | IPORT | ACCEPTED
GROUPSThe unique group identification number which you would like to get the oveview for.
TARGETSThe unique target identification number which you would like to get the overview for.

Example request:

Example response:


Response keys
COUNTThe amount of vulnerabilities found for the selected overview.
VCFAMILYThe family name of the vulnerability.

Solution Report

You can get a solution view of your reported vulnerabilities.

Required keys
GROUPSThe unique group identification number which you would like to get the solutions for.
SCANLOGXIDThe unique scan log identifier that you would like to get the solution view for.
TARGETSThe unique target identification number which you would like to get the solutions for.


Example response:

         <SOLUTIONTITLE>Restrict access to the SMB service</SOLUTIONTITLE>
         <SOLUTION>Restrict access to the SMB service</SOLUTION>

Response keys
COUNTThe total number of vulnerabilities that has this solution.
HIGHRISKSThe number of high risks that this solution will resolve

The number of low risks that this solution will resolve.

MEDIUMRISKSThe number of medium risks that this solution will resolve
ORDERINGInternal use.
SOLUTIONThe solution text that explaines that action needs to be taken to resolve the issue.
SOLUTIONPRODUCTThe product that the solution affects.
SOLUTIONTITLEShort title regarding the solution.
SOLUTIONTYPEThe type of the solution. See Appendix_M
TARGETCOUNTThe number of targets that has this solution.

Trend Report

You can get a trend overview over how the vulnerabilities are distributed based on differentperiods.

Required keys
GROUPSThe unique group identification number which you would like to get the trend for.
LENGTHThe number of the periods
PERIOD1 = Week
2 = Month
3 = Year
TARGETSThe unique target identification number which you would like to get the trend for.

Example request:

Example response:

         <DATE>2013-07-17 00:00</DATE>

Response keys
ADDEDThe number of added findings.
CLOSEDThe number of closed findings.
DATEThe date when this information was gathered.
HIGHThe number of high findings.
HIGHACCEPTEDThe number of high findings which are accepted.
ISCVSSThe sum of all calculated CVSS scores added together.
LOWThe number of low findings.
LOWACCEPTEDThe number of low findings which are accepted.
MEDIUMThe number of medium findings.
MEDIUMACCEPTEDThe number of medium findings which are accepted.
OPENEDThe number of opened ports.
REMOVEDThe number of removed findings.

Report schedule

This section will describe how you can schedule reports to be automatically sent out to a defined recipient.

Multiple entries can be defined so different types of reports can be sent to the same recipient. The reports can also be defined to only contain specific host, groups or even using a report template (target selection and filtering combined).

On a HIAB it is also possible to transfer the file out to an external server using either FTP or SCP. Those options will be available once such servers have been defined in the maintenance section.

List Schedule Report

In order to see all the scheduled reports which has been added to the system on your profile you need to supply the details.

Required keys
SCANTYPEThe available scan types:
1 : PCI
2 : WAS

Example request:

Example response:

         <LASTDATE>2011-04-30 00:00</LASTDATE>
         <LATESTDATE>2011-10-03 10:00</LATESTDATE>
         <OWNER>Daniel Fredriksson</OWNER>
Reponse keys
DAYWEEKMONTHFlag if specific day of week or month should be used (available on monthly scanning).
ENCRYPTIONKEYName of the encryption key which shall be used to encode the report.
FORMATBinary encoding of the format to be include.
FREQUENCYThe frequency of the scheduled time for this job.
INCLUDEHOSTINFOBoolean flag if target information should be included in the exported report.
LASTDATEThe last date and time when the report was generated.
LATESTDATERun schedule until this given date.
LENGTHThe lenght of the given period.
NAMEThe name of the report schedule.
OWNERThe owner of the object.
PERIODThe period of the scheduled report. See Appendix B.
RECIPIENTThe unique idenfication number of the user who should receive the report. Set to -1 if custom email address are used.
RECIPIENTEMAILThe custom email address if no recipient identification number is specified.

The type of reciepient:
0 : Email
1 : FTP - HIAB only
2 : SCP - HIAB only


The number of sub levels of the groups that will be included in the group report.

REPORTTEMPLATEThe report template to use when generating the report.
REPORTTYPEThe type of report to export. See Appendix I.
SCANTYPEThe available scan types:
1 : PCI
2 : WAS
TARGETGROUPSComma separated list of target groups to be included in the report.
XIDThe unique identifier of the given object.

The unique user id.

Update Scheduled Report

You can schedule reports to be generated at a specific time.

Required keys
NAMEName of the schedule report.
RECIPIENTThe recipient of the report.
REPORTTYPEThe type of report to receive. See Appendix I.
SCANTYPEThe available scan types:
1 : PCI
2 : WAS

Example request:

The above given request will generate a generic response.

More information about this response type is available in Appendix A.

Remove Schedule Report

In order to remove a scheduled report you need the unique identification number for that specific report schedule. This is retrieved from the list of already defined report schedules ( See section : List Schedule Report).

Required keys
XIDThe unique identifier of the given object.

Example request:

The above given request will generate a generic response.

More information about this response type is available in Appendix A.

Manage Tickets

In the system you can create custom and report specific tickets to be assigned to any of your defined users. The tickets can be defined to automatically become generated and assigned from within the event system. There is also an option to define an escalation rule for each individual user in case a due date has been exceeded.

List Tickets

You can retrieve  a list of tickets by supplying the following information.

Required keys

Example request:

Example response:

         <DUEDATE>2009-07-01 00:00</DUEDATE>
         <NAME>My First Ticket</NAME>
         <ASSIGNEE>Daniel Fredriksson</ASSIGNEE>

Response key
ASSIGNEEThe assigned user of this task.
DREPORTDATEThe report date and time which this task is regarding.
DUEDATEThe due date of this task.
IPADDRESSThe IP address of the target which this task is concerning.
IPORTThe port of the finding of which this task is concerning.

The protocol of the finding.

NAMEThe name of the task.
PCIFINDINGBoolean value if this is regarding a PCI finding.
PORTA text description of the port of which this task is concerning.
PRIORITYThe task priority (1-5)
PROTOCOLA text decription of the protocol.
REPORTXIDInternal use.
SCHEDULEOBJECTNAMEThe schedule name conerning this task
SCHEDULEOBJECTXIDThe unique schedule id conerning this task
SCRIPTIDThe vulnerability script id which this task is conerning.
SCRIPTNAMEThe vulnerability name.
STATUSCurrent status of this task.
TARGETTYPEThe available types of targets:
0 : IP
1 : Host name
2 : NetBIOS name.
TASKIDThe unique identificatioin number of this task.
TYPEThe type of task:
0 : Single entry
1 : Whole report
VCVULNIDThe vulnerability script id which this task is conerning.
VERIFIEDBoolean value if this finding has been verified or not.
VIRTUALHOSTThe virtual hosts for this target.
WASFINDINGBoolean flag if this task concerns a Web Application Scan.
XIDThe unique identifier of the given object.

The unique identifier of the target object.

XSUBUSERXIDThe unique identifier of sub user which this object is connected to.

Update Ticket

In order to create a ticket you have to supply the following information.

Required keys
DUEDATEThe due date for this task.
IDThe task idenfication number. Should be set to NEW if you would like to create a new entry.
MESSAGEThe message which will be connected to this task.
MULTIPLEBoolean value if the task is regarding multiple entries or not.
NAMEThe name of the task.
PRIORITYThe priotity of this task. Value 1-5
STATUSThe current status of this task.
TASKIDThe taskidentification number. Shoiuld be set to -1 if you would like to create a new entry.

Example request:

The above given request will generate a generic response.

More information about this response type is available in Appendix A.

Remove Ticket

If you are the main account holder the you can actually remove a ticket from the system. Please note that this isn't possible by any other user. In order to remove a ticket you need to supply the following information.

Required keys
XIDThe unique identifier of the given object.

Example request:

The above given request will generate a generic response.

More information about this response type is available in Appendix A.

Manage Audit

Here you can retrieve a list of some actions which has been taken place in the system by the defined users so that you can see who did what and when.

This might be a requirement from your auditor but can come in handy when it comes to tracking changes within the system.

Please note that this information is only retained for 1 year. If longer storage is required, you are required to manually download and store this information in a remote system on an annual basis.

View Audit History

You can retrive a list of some actions which has been taken place in the system by the defined users so that you can see how did what and when.

Required keys

Example request:

Example response:

         <NAME>Api Api</NAME>
         <XTIME>2014-02-18 08:59</XTIME>

Response keys

0 = Added
1 = Updated
2 = Deleted
3 = Login
4 = Log out

LIMITEDThe presence of this field indicates that the response has been limited by the use of the "limit" parameter in the request.

The full name on the account that performed the action.

TXCUSTOMAdditional details of the modification.
VCFIRSTNAMEThe first name of the user.
VCLASTNAMEThe surmane of the user.
XIDThe unique identifier of the given object.
XTIMEThe data and time when the action was performed.
XVCAPPThe application which the audit log entry is concerning. See Appendix N.
XXIDThe unique identification number for the entry which this log is about.

Export Audit History

The audit log can also be exported from the system. This request will result in a binary file being provided of the XLS format.

Required keys

Example request:

The response will be in a binary format. This format is dependent on the given parameters in the request.

Manage Events

The event notifications area allows for actions to be performed upon certain events. These actions can be sent out over SNMP, syslog or email.

Please see Appendix N for a complete list of all possible actions.

List Event Notifications

In order to list the defined event notifications which are present in the system you need to supply the following information.

Required keys

Example request:

Example response:


Response keys
ASSIGNEEThe user which is assigned the ticket (Please note that this field may not be present).
ATTACHREPORTBoolean value if the report should be attached to the email if selected.
ENCRYPTIONKEYThe encryption key that will be used to encrypt any attached report (Please note that this field may not be present).
EVENTNAMEThe name of the notification event (Please note that this field may not be present).
ITYPEThe event type:
1 : Syslog
2 : SNMP
3 : Email
4 : SMS
5 : Ticket
MYSCANSBoolean value if this should only be for scans which the user has scheduled.
NEWFINDINGSBoolean value if this event is only for new findings.
RECIPIENTEmail address where the event will be sent to (Please note that this field may not be present).
REPORTTYPEThe report type that will be attached to the event notfication. See Appendix I.
SCANFORMATThe additional information format that should be included in the event.
SCANTYPEThe available scan types:
1 : PCI
2 : WAS
TARGETGROUPLISTFor which target groups that this notification will take place.
TARGETINFORMATIONBoolean value if additional target information should be included in the notification.
TARGETLISTThe target list as accepted by the graphical user interface.
TICKETPRIORITYThe priority that will be set for the assigned task if defined (Please note that this field may not be present). 
XASSIGNEEThe full name of the user which is assigned task if defined (Please note that this field may not be present). 
XIDThe unique identifier of the given object.
XREFIDSee Appendix N.
XUSERXIDThe unique user id.

Update Event Notification

In order to add an event notification you need to supply the following information.

Required keys

1 : Syslog
2 : SNMP
3 : Email
4 : SMS
5 : Ticket

RECIPIENTThe recipient of the event
XREFIDSee Appendix N.

Example request:

The above given request will generate a generic response.

More information about this response type is available in Appendix A.

Remove Event Notification

In order to remove any event notification you need to supply the unique identification number for that specific event.

Required keys
XIDThe unique identifier of the given object.

Example request:

The above given request will generate a generic response.

More information about this response type is available in Appendix A.

Manage Dashboard.

The dash board gives a quick overview of the status of your network. It holds modules that gives information about various aspects of the targets and their risks.

Top Groups

Shows the groups with the most vulnerabilities.

Required keys

Example request:

Example response:

         <PATH>Report Groups / Risk</PATH>
Response keys
COUNTThe number of vulnerabilities present in this group.
HASCHILDNODESBoolean value if this group has any child nodes.
NAMEThe name of the group.
PATHThe group path.
POSITIONThe position in the path.
REPORTBASEDBoolean value if the group is based on a Reporting group.
RULEBASEDBoolean value if the group is based on a Dynamic group.
XIDThe unique identifier of the given object.
XIPARENTIDThe unique id for anyparent object for this object within the system.
XPATHUPInternal use only.

Top Ports

Shows the ports with most vulnerabilities.

Required keys

Example request:

Example response:

Response keys
COUNTThe number of open ports
PORTThe port number

Top Applications

Shows the applications found that has most vulnerabilities in the specified target group.

Required keys

Example request:

Example response:

Response keys

Risk Summary

Display how many targets that have high, medium, and low risk.

Required keys

Optional Keys

The risk summary can also be extracted for a specific group.

Optional keys

GROUPXIDThe group that you would like to receive the risk summary for. If omitted it will report all based on all targets.

Example request:

Example response:

Response keys
HIGHThe number of high risks.
HIGHTRENDThe trend of high risks.
LOWThe number of low risks.
LOWTRENDThe trend of low risks.
MEDIUMThe number of medium risks.
MEDIUMTRENDThe trend of medium risks.
TOTALThe total number of vulnerabilities on the selected group (or all targets it omitted).

Remediation Statistics

Shows how long it takes on average to re-mediate risks on the targets in the specified target.

Required keys
GROUPXIDThe group that you would like to receive the risk summary for. If omitted it will report all based on all target.

Example request:

Example response:

         <DAY>2013-11-19 00:00</DAY>
Response keys
DAYThe date for this statistics.
DAYSHIGHThe number of days it takes to resolve a high risk vulnerability.
DAYSLOWThe number of days it takes to resolve a low risk vulnerability.
DAYSMEDIUMThe number of days it takes to resolve a medium risk vulnerability.

Top Platforms

Shows the platform distribution found that has most vulnerabilities in the specified target group.

Required keys

Example request:

Example response:

Response keys

Top Targets

Shows the targets with most vulnerabilities in the specified target group.

Required keys

Example request:

Example response:

Response keys
COUNTThe number of vulnerabilities present on the specific target.
NAMEThe target name or IP.
XIDThe unique identifier of the given object.

Top Vulnerabilities

Shows the platform distribution found that has most vulnerabilities in the specified target group.

Required keys

Example request:

Example response:

         <VCNAME>Mozilla Firefox file:// Directory Listing XSS Vulnerability</VCNAME>
Response keys
COUNTThe number of occurences of this vulnerability.
VCNAMEName of the vulnerability.
VCVULNIDThe script id for the vulnerability.

Vulnerability Database

The vulnerability database lets you look at the vulnerability checks, and also see their descriptions and suggested solutions.

It is also possible to get the number of times a specific vulnerability has been detected within your network..

List Vulnerabilities

In order to list the vulnerabilities you need to supply the following information.

Required keys

Example request:

Example response:

         <VCNAME>RPC Portmapper</VCNAME>
         <VCBUG>No bugtraq</VCBUG>
         <SCRIPTCREATED>2007-04-04 00:00</SCRIPTCREATED>
Response keys
CVSS_SCOREThe CVSS score for this vulnerability.
HASEXPLOITSBoolean flag if the vulnerability has a known exploit.
ICVSSThe calculated CVSS number for this vulnerability. Divide it by 10 to get the correct number.

The risk level that this vulnerability is graded to. See Appendix J.

LIMITEDThe presence of this field indicates that the response has been limited by the use of the limit. parameter in the request.

The date when this script was created.

VCBUGThe Bugtraq ID for this vulnerability.
VCCVEThe CVE reference for this vulnerability.
VCCVSSVECTORThe CVE vector for this vulnerability.
VCFAMThe family that this vulnerability belongs to.
VCNAMEThe name of this vulnerability.
XIDThe unique identifier of the given object.

Extended Script Information

If you supply the script identification you can get additional information like description and solutions for a specific vulnerability.

Required keys
XIDThe unique identifier of the given object.

Example request:

Example response:

         <VCNAME>Sun JRE: TLS / DTLS Protocol CBC-mode Ciphersuite Timing Analysis Plaintext Recovery Cryptanalysis Attack</VCNAME>
         <VCBUG>No bugtraq</VCBUG>
         <CDESC>The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJRE, PolarSSL, and other products, do not properly consider timing sidechannel attacks on a MAC check requirement during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, aka the "Lucky Thirteen"
         <CSOL>Upgrade to version 1.7.0_45 or later of Sun JRE.</CSOL>
         <SOLUTIONTITLE>Upgrade to version 1.7.0_45 or later of Sun JRE</SOLUTIONTITLE>
Response keys
CDESCThe description for this vulnerability.
CSOLThe solution for this vulnerability.
CVSS_SCOREThe CVSS score for this vulnerability.
FINDINGCOUNTThe number of occurences of this vulnerability in your system.
HASEXPLOITSBoolean flag if the vulnerability has a known exploit.
ICVSSThe calculated CVSS number for this vulnerability. Divide it by 10 to get the correct number.

The risk level that this vulnerability is graded to. See Appendix J.

SOLUTIONPRODUCTThe solution product.

Short title regarding the solution .

SOLUTIONTYPEThe solution type. See Appendix_M
VCBUGThe Bugtraq ID for this vulnerability.
VCCVEThe CVE reference for this vulnerability.
VCCVSSVECTORThe CVE vector for this vulnerability.
VCFAMThe family that this vulnerability belongs to.
VCNAMEThe name of this vulnerability.
XIDThe unique identifier of the given object.

Web Application Scanner

The web application scanner is used to detect vulnerabilities on the web server such as cross site scripting and SQL injection.

If you have the full version you can also detect the following vulnerability types:

  • XSS Element
  • XSS Attribute
  • XSS Header
  • SQL Injection
  • Remote File Include
  • Local File Include
  • Code Injection
  • Command Injection
  • Format String
  • CRLF Injection
  • Cross Site Request Forgery


The web application scanning is defined as a scope which includes the information about which links to follow and which IP:s we are allowed to follow during the crawling phase.

In the scope you can also define white-list, black-list and IP range which are used by the host name (if it's load balanced). There are also possible to define different authentication procedures, required cookies, fixed parameter values, user agent and HTTP refer.

Update Scheduled Scope

In order to add a web application scope you need to supply the following information.

Required keys
MAXIMUMLINKSThe maximum number of links that the crawler will follow during the detect phase.
NAMEThe name of the Web Application Scanning schedule scope.

Example request:

The above given request will generate a generic response.

More information about this response type is available in Appendix A.

List Scheduled Scopes

In order to alist the vulnerabilities you need to supply the following information.

Required keys

Example request:

Example response:

         <LATESTSCANDATE>2012-05-04 08:51</LATESTSCANDATE>
         <OWNER>Daniel Fredriksson</OWNER>
Response keys

The average scan time.

CODEINJECTIONBoolean value if the test shall include code injection checks.
COMMANDINJECTIONBoolean value if the test shall include command injection checks.
CONTENTANALYSISBoolean value if the test shall include content analysis checks.
CRLFINJECTIONBoolean value if the test shall include CRLF injection checks.

Flag if specific day of week or month should be used (available on monthly scanning).

DELETEDBoolean value if this entry is marked as removed and should not be displayed.
DISCOVERYMODEBoolean value if the scan only shall include the crawler part and not send any spikes to the target host.
ENABLEAJAXBoolean value if the scan shall parse JavaScript and try to enumerate additional links.
EVENTTIMEOUTThe timeout in seconds before the web application scanner no longer waits for an event to be processed.
FORMATSTRINGBoolean value if the scan shall include format string injection checks.
FREQUENCYThe frequency of the scheduled time for this job.
ISWASBoolean flag which specifies that this schedule is a Web Application Scan instead of a normal one.
LATESTSCANDATEWhen this schedule was scanned the latest time.
LATESTSCANDURATIONThe duration of the latest scan.

The latest scan status of this schedule.

LOCALFILEINCLUDEBoolean value if the test shall include local file include injection chacks.
MAXIMUMLINKSThe maximum number of links that the scanner will follow (please note that on these links it may detect more URI's than the maximum number specified).
MAXSCANTIMEThe maximum amount of time allowed to scan this schedule.
NAMEThe name of the Web Application Scan scope schedule/definition.

The owner of the object.

REMOTEFILEINCLUDEBoolean value if the test shall include remote file include injection checks.
REQUESTDELAYThe delay in seconds between each request.
SCANNERIDThe scanner id which this target will be tested from.
SCANNERNAMEThe name of the scanner where this action takes place.
SCANWINDOWDELAYThe delay between scan windows (in days).

The number of allowed scan windows for this schedule.

SQLINJECTIONBoolean value if the test shall include SQL injection checks.
TIMESQLINJECTIONBoolean value if the test shall include timed SQL injection checks.
TRANSFERTIMEOUTThe transfer timeout before we continue to the next URI.
UNVALIDATEDREDIRECTBoolean value if the test shall include checks for unvalidated URL redirects.
URIBLACKLISTNew line separated list of URI or sections of an URI of locations which the scanning isn't allowed to scan.
URILISTNew line separated list of URI's that the scanner will cover.
URIWHITELISTNew line separated list of the ONLY URI's that the scanner is allowed to cover.
WASCERTIFICATECertificate to use when performing web application scans.
XIDThe unique identifier of the given object.
XSSPERSISTENTBoolean value if the test shall include persistant XSS injection checks.
XSSREFLECTEDBoolean value if the test shall include reflected XSS injection checks.
XSUBUSERXIDThe unique identifier of sub user which this object is connected to.
XUSERXIDThe unique user id.

Delete Scheduled Scope

In order to remove a scope you need to supply the unique identification number for that specific scope.

Required keys
XIDThe unique identifier of the given object.

Example request:

The above given request will generate a generic response.

More information about this response type is available in Appendix A.

List Running Scans

It is possible to see the current status of the currently running scans. These can also be paused, resumed or stopped. When a scan is stopped, please allow some time for it to finish gracefully. The scanner will try to terminate it as quickly as possible.

List Running Scans

In order to see a list of currently running scans you shall supply the following information.

Required keys
VCSERVICEShould be set to W in order to only see Web Applications scan status.

Example request:

Example response:

         <DSCANSTARTED>2012-11-16 10:45</DSCANSTARTED>
         <DSCANSTART>2012-11-16 10:45</DSCANSTART>
         <DSCANEND>2012-11-16 22:45</DSCANEND>
Response keys
BPAUSEBoolean flag if the scan is marked as paused.
BSTOPBoolean flag if the scan is marked as stopped.
COMPANYThe name of the comapny for this account.
DBSCHEMAInternal use only.
DSCANENDDate and time information when the scan will terminate if not already finished.
DSCANSTARTDate and time information when the scan shall start.
DSCANSTARTEDDate and time information when the scan started.
HOSTNAMEThe FQDN of the host.
IATTACKERIDThe internal attacker id which this scan is running from .
ICOUNTThe number of targets within this scan scope.
IPERCENTVThe percentage value of the progress of the scan.
ISPAUSEDBoolean flag if the scan is paused.
ISSTOPPEDBoolean flag if the scan is stopped.
ITHREADIDThe thread identification number within the system. Used for performing actions upon specific scans.
IVERIFYBoolean flag if the running scan is a verification scan.
LOOKUPBoolean flag if any discovered targets will perform a lookup upon adding them to the system.
PDETECTTEMPLATEThe scan policy which will be used on scan started by a discovery/scan type of scan.
PROBEIDThe unique probe identification number (Please note that this field may not be present).

The comment that will be used when adding targets to the system if the are detected (Please note that this field may not be present).

REMOTEXIDInternal use.
RESUMINGBoolean flag if this scan is resumed from a previosly paused scan.
SCANLESSREPORTXIDThe unique identifier of the report which is updated using the SLS feature.
SCANNERIDThe scanner id which this target will be tested from.
SCANNERNAMEThe name of the scanner where this action takes place.
SCANSCHEMAInternal use.
SCANSENTBoolean flag if the scan has been sent to the designated scanner.
SCANWINDOWDELAYThe delay between scan windows (in days).
SCANWINDOWSThe number of allowed scan windows for this schedule.
SMARTFILTERINGBoolean flag if the results will utilize smart filtering.
TARGETTYPEThe available types of targets:
0 : IP
1 : Host name
2 : NetBIOS name.
TEMPLATEThe scan policy utilized by this object (Please note that this field may not be present).
TXREPORTDeprecated (Please note that this field may not be present).
TXSETTINGSText settings for this scan.
VCGNAMEInternal use.
VCJOBNAMEThe name of the schedule job.
VCPERCENTText representation of the percentage value.
VCSERVICEShould be set to W in order to only see Web Applications scan status.
VCSTATECurrent state of the scan.
VCSTATUSCurrent status of the scan.
VCTARGETText representation of the target.
WAKEONLANBoolean flag if targets should woken up by the WOL feature.
WAKEONLANDELAYThe delay before targets will be scanned since the WOL request is sent.
XIDThe unique identifier of the given object.
XIPXIDThe unique identifier of the target object.
XSCANJOBXIDThe unique identifier of the scan job log object which contain all individual targets (entry with scan type set in the 20 range).
XSOXIDThe unique identifier of the schedule object which contain the schedule preferences.
XSUBUSERXIDThe unique identifier of sub user which this object is connected to.

The unique identifier of the scan policy utilized by this object.

XUSERXIDThe unique user id.

Start a Scan

In order to start a scan you need to supply the unique identification number for a specific schedule. This can be retrieved from the schedule list ( See section : List Schedule ).

Required keys
ONLYSCANNOWShould be set to 1
XIDThe unique identifier of the given object.


The above given request will generate a generic response.

More information about this response type is available in Appendix A.

Pause a Scan

In order to pause a currently running scan you need to supply the unique identification number for that specific scan This can be retrived from the scan list ( See section : List Running Scans ).

Required keys
XIDThe unique identifier of the given object.

Example request:,13&ACTION=PAUSESCAN

The above given request will generate a generic response.

More information about this response type is available in Appendix A.

Resume Scan

In order to resume a currently paused scan you need to supply the unique identification number for that specific scan This can be retrived from the scan list ( See section : List Running Scans ).

Required keys
XIDThe unique identifier of the given object.

Example request:,13&ACTION=RESUMESCAN

The above given request will generate a generic response.

More information about this response type is available in Appendix A.

Stop Scan

In order to stop a currently running scan you need to supply the unique identification number for that specific scan This can be retrived from the scan list ( See section : List Running Scans ).

Required keys
XIDThe unique identifier of the given object.

Example request:,13&ACTION=STOPSCAN

The above given request will generate a generic response.

More information about this response type is available in Appendix A.

Report Findings

Here you can see the result of a web application scan and also export the results to different formats. .

Retrieve Report Entries

In order to retrieve scanning results you need to supply the the following information.

Required keys
GROUPSComma separated list of unique group identifiers to be included in the report.
TARGETSComma separated list of unique target identifiers to be included in the report.

Optional Keys

If based on a schedule object you should provide it's unique identification number in the following parameter.

Optional keys
SCANLOGXIDThe unique scan log entry id for the schedule job which you would like to retrive reports for.


Example response:

         <SCHEDULEJOB>Application server</SCHEDULEJOB>
         <DFIRSTSEEN>2009-11-05 12:00</DFIRSTSEEN>
         <DLASTSEEN>2009-11-05 12:00</DLASTSEEN>
         <DATE>2009-11-05 12:00</DATE>
         <VCNAME>Port scanner</VCNAME>
         <FINDINGDATE>2009-11-05 12:00</FINDINGDATE>
Response keys

The comment given when this vulnerability was accepted (Please note that this field may not be present).

ACCEPTEDBoolean value if the vulnerability has been accepted.
ACCEPTEDLENGTHThe number of days the vulnerability has been accepted.
AGEThe number of days since the first occurrence of this specific finding.
ASSIGNEEThe user who has a ticket assigned to him/her for this entry.
BFALSEPOSBoolean value if this vulnerability is marked as a false positive or not.

Boolean value if this finding wasn't reported on the previous report for this target.

BPCIBoolean value if this report is a PCI report.
CUSTOM0Custom attributed defined on either an user or a target.
CUSTOM1Custom attributed defined on either an user or a target.
CUSTOM2Custom attributed defined on either an user or a target.
CUSTOM3Custom attributed defined on either an user or a target.
CUSTOM4Custom attributed defined on either an user or a target.
CVSSSCOREThe CVSS score for this vulnerability.
DATEThe date and time when this scan was performed.
DFIRSTSEENThe date and time when this finding was first detected on this host.
DLASTSEENThe date and time when this finding was last seen on this host.
FINDINGDATEThe date and time when this finding was updated.

The global template that was used if any.

HASEXPLOITSBoolean flag if the vulnerability has a known exploit.
HASFPCOMMENTBoolean flag if the target has false positive comments.
HOSTNAMEThe FQDN of the host.
IPORTThe port where this vulnerability was detected upon.
IPROTOCOLThe protocol used when detecting this vulnerability.
IRISKThe risk level that this vulnerability is graded to. See appendix G.

Boolean value if this vulnerability has been added after the initial scan.

LIMITEDThe presence of this field indicates that the response has been limited by the use of the "limit" parameter in the request.
ORIGINALRISKLEVELThe original risk level for this vulnerability.
PCICVSSSCOREThe PCI CVSS score for this vulnerability ( Doesn't reflect DOS ).
PLATFORMThe detected platform for this vulnerability.
POTENTIALFALSEBoolean value if this vulnerability are a potential false positive.
SCANNERNAMEThe name of the scanner where this action takes place.
SCHEDULEJOBThe name of the schedule job which is associated with this entry.

The name of the service listening on this port and protocol.

TARGETTYPEThe available types of targets:
0 : IP
1 : Host name
2 : NetBIOS name.
TYPEThe entry report type.
VCNAMEThe Bugtraq ID for this vulnerability.
VCTARGETText representation of the target.
VCVHOSTThe virtual host name where this vulnerability was detected.
VCVULNIDThe unique script identification number given to this vulnerability.
VERIFIEDBoolean value if this finding has been verified or not.
XIDThe unique identifier of the given object.

The unique identifier of the target object.

XTEMPLATEThe unique identifier of the scan policy utilized by this object.

Scan History

The scan history functions are the same as when you are viewing normal OUTSCAN or HIAB history. Please see earlier reference under Manage Schedule.

In order to see what has been executed in the past on your account you can retrieve a scan log which will contain the history of your scannings.

Required keys
WASShould be set to 1 in order to only see Web Application Scan log history

Optional Keys

The following parameters can be supplied in case of you would like to exclude specific entries from being retrieved.

Required keys
EXCLUDEEMPTYBoolean value if empty scan logs should be included in the results.
ITYPEThe type of this entry, see Appendix C.
TEMPLATEThe scan policy utilized by this object.

Example request:

Example response:

         <DSCANSTARTDATE>2011-01-26 14:16</DSCANSTARTDATE>
         <DSCANENDDATE>2011-01-26 14:47</DSCANENDDATE>
Response keys

Boolean flag if this entry can be updated using the SLS feature.

COMPLIANTBoolean flag which shows if the target where compliant according to the PCI guidelines in case the scan refers to such a target.
CONFIRMEDBoolean flag if this target is confirmed within the PCI section.
DISCOVERYTEMPLATEName of the discovery job if it's a discovery
DSCANENDDATEThe date and time when the scan ended.

The date and time when the scan started.

FROMHIABBoolean flag which is set to 1 if the scan originated from a HIAB (only viable on OUTSCAN).
HASWASSTATSBoolean flag if the target has web application scanning statistics.
IIDInternal use only.
ITYPEThe type of this entry, see Appendix C.
LASTBoolean value if this is the latest entry for this target.
LATESTSCANUPDATEDate and time when this scan where last updated using the SLS technology.
LIMITEDThe presence of this field indicates that the response has been limited by the use of the "limit" parameter in the request.
SCANLESSBoolean value if this is an SLS update of the report.
SCANNERIDThe scanner id which this target will be tested from.

The name of the scanner where this action takes place.

SCANTIMEThe total amount of time the scan took.
SCHEDULEJOBThe name of the schedule job which is associated with this entry.
SUBMITTEDBoolean flag if this target is a PCI target and that the report hasn't been submitted yet in this quarter.
TARGETThe target that this entry is about.
TEMPLATEThe scan policy utilized by this object (Please note that this field may not be present).
VCHOSTThe IP or host name of the target which where tested.
XIDThe unique identifier of the given object.
XIPXIDThe unique identifier of the target object.
XSCANJOBXIDThe unique identifier of the scan job log object which contain all individual targets (entry with scan type set in the 20 range).
XSOXIDThe unique identifier of the schedule object which contain the schedule preferences.
XTEMPLATEThe unique identifier of the scan policy utilized by this object.


In the following appendix we will provide information about additional features that are available through the use of the API. We will also provide look up thables of the meaning of the different field which are ised within the systemon different reqeusts.

Appendix A - Generic Request Response

When you are performing requests you will be presented with a generic status message when you are updating or removing an object. This looks like the following:


The above response will also contain a reference to a DTD. The supplied DTD is NOT valid for the response and should be disregarded when parsing the response. Please set the code to avoid DTD validation.


All responses from the XML API are wrapped in a RESPONSE tag

Appendix B - Schedule Frequency Table

The frequency table is used when you define different scheduled task like for instance scheduled report, scans, or back up tasks. 

Schedule  codeFrequency

Appendix C - Scan Status Table

The scan status which is represented by a number is mapped to a type and action. Below you can see what the different codes stands for.

Scan status codeDescription
-1Not scanned
0Completed (Scheduled)
1Completed (Forced)
4Stopped (By user)
5Large report
6Stopped (Large report)
8Scan window paused
9Scan window resume

11Discovery - Scan running
12Discovery - Done
13Discovery -Time out
14Discovery -Stopped

18Schedule job not started
19Schedule job currently running
20Schedule job done
22Schedule job failed

30HIAB update
31HIAB script update
32HIAB backup
33HIAB import
34HIAB synchronize

Appendix D - Error Codes

If a request fails or if you have not performed a correct request any of the following errors may be given in response.

Error #MessageExtended explanation
100You are not logged in.The action you have requested require that you are logged into the system.
101Access is denied.You don't have access to perform the requested function.
102Incorrect login.You have supplied the wrong credentials.
103No records where removed.You tried to remove something from the system but no records where removed during the request.
104All required fields are not present.All fields which are required in order to perform the request has not been supplied correctly.
105The account you are trying to update does not exist.The account you tried to update does not exist.
106No targets found to be updated.The target you tried to update does not exist.
107The country code is invalid.The supplied country code is not valid.
108The mobile number is invalid.The format of the mobile number is incorrect.
109Username must be greater then four characters.The minimum length of the user name id four characters.
110The username is taken by another user.The selected user name is not available.
111Password must be greater then five characters.Password must contain at least six characters.
112Too many login attempts. The account is locked.You have given the wrong password credentials to many times and the account has been locked. In order to gain access again you need to perform a Forgot login.
113Old password is incorrect.When you tried to change passwords you supplied the wrong old password.
114<Not used>
115To many entries defined. The maximum is:You are trying to add more than allowed. The error message will state how many entries that are allowed.
116Unsupported value in field.The mentioned field contains unsupported values.
117No test was sent. Failed to find receiver.This occurs if the user tries to send a test message and we are unable to determine the receiver.
118Vaildation of input failed.Something in the request isn't vaild.
119<Not used>
120Invalid email address.The email address isn't valid.
121Parameter to low:The mentioned parameter is to low.
122Parameter to high:The mentioned parameter is to high.
123Importing data. Please try again later.An import is being done, system will be disabled during that period.
124Logged out due to inactivity.The account has been logged out due to inactivity.
500Internal server error.When handling the request somethin unexpected occured which terminated the request.
998Database not in UTF-8. Localization disabled. Contact support.The database is missing a significant patch, please contact support for further assistance.
999Server is not registered.The HIAB appliance is not registered to an account on Outpost24, please contact support for further instructions.

Appendix E - Country Codes

A complete and up to date list of supported country codes by the system can be retrieved from the system by performing the following request:

Example response:

   <COUNTRY rowid="1">

Appendix F - State Codes

A complete and up to date list of supported state codes by the system can be retrieved from the system by performing the following request:

Example response:

   <STATE rowid="1">

Appendix G - Scanning Policies

A complete and up to date list of supported scanning policies by the system can be retrieved from the system by performing the following request:

Example response :

   <TEMPLATE rowid="1">

Appendix H - Audit Applications

The audit application will use the following string representations of different parts in the system.

tHiabHIAB changes
tMonitorHostSMonitor log
tOutscanFileSUploaded files
tPdetectSDiscovery scans
tReportSReport generation
tReportTextSReport text modifications
tReport_DisputeSPCI Disputes
tSavedscanprefSScan policies
tScannerSDistributed scan changes
tSubUserSSub account

Appendix I - Report Types

When exporting reports you need to specify which type of report you would like to receive.

2Executed scripts
4Trend summary
5Trend detailed
7Group summary
8Delta report
9Solution report
10PCI summary
11PCI detailed

Appendix J - Risk Table

In the reporting section the risk value is mapped to the following risk level.

1Low risk
2Medium risk
4High risk

Appendix K - Additional Features

In all requests which will produce some sort of list you can supply additional parameters in order to filter out and sort the results in different manners.


If no limit is defined it will use a default limit which is set by the system ( often 50 ) but it depends on which request you are doing. If you would like to disable the limit you should set it to -1.

Example :

You can define a field that you would like to sort upon from the response. You can also select which direction with the use of the dir parameter.

Example :


You can also group the findings based on a field from the results with the use of the groupBy parameter.

Example :


You can create multiple filters if that is required but you need to number then with the start from 0.

First you need to define which field this is about and you do that with the use of the following parameter : filter[counter][field].

Then you need to define which comparison you would like it to perform in the filter, the supported ones are eq, lt, gt, and not. The parameter is called filter[counter][comparison].

Once that is done you need to give it a comparison value which is done with the parameter : filter[counter][value].

Now at last you need to define which type this value is in order to perform the correct comparison and this is done with the parameter : filter[counter][data][type]and the supported types are : date, boolean, list, numeric and string.

Example :[0][data][type]=date&filter[0][field]=NAME&filter[0][comparison]=eq&filter[0][value]=Test

Appendix N - Event Type

Whan defining events you need to supply which event you would like to set up. This is a list of the available event types currently present.

0Finding - Information
1Finding - Low risk
2Finding - Medium risk
4Finding - High risk
5Scan results ready
6Large report detected
7Scan started
8Scan timeout
9Scan stopped
10Scan failed
11Network monitor - Open port
12Network monitor - Closed port
13Network monitor - Answer on ping
14Network monitor - No answer on ping
15HIAB update
16HIAB boot
18HIAB backup
19System restarted
20Discovery - Notification
21Discovery - Alive host
22Discovery - Dead host
23Discovery - Host added to system
24Target added to system
25Target removed from system
26Scan notification
30User login notification
31Scanner missing
32Maintenance plan completed
33Update failed
34Verify done
35Scan - Not reachable
36Scan - Updated
37Backup failed
38Release notes
39Scan: Could not start SLS
40Scan: Schedule started

Appendix M - Solutiontype

When fetching data from reporting tools, more precisely the solution category, the UI has a string as the category title while the XMLAPI uses a number for the attribute SOLUTIONTYPE.

Reconfigure (software)
InProgress (solution is being investigated)
Contact vendor
Update (software)
Patch (software)
Unack (Unacknowledged solution by vendor)
NoSol (No known solution)
Account (change account settings)
Disable (the service)
Filter (access)


