Skip to main content

Reports & Evidence

Every DSP run creates a dedicated directory under:
The run directory is the bridge between what DSP generated and what the XDR/NDR platform detected.

Start with these three files

For normal POC work, check these first: The operator menu’s Show latest report option gives the quickest view of the most recent run.

Full artifact set

Evidence flow

For webshell runs, the remote host produces an events.jsonl bundle. DSP retrieves it, imports the events into the local Event Store, and continues through the same validation/report/evidence pipeline.

What validation.json means

validation.json confirms DSP’s own execution and event expectations. It is not an XDR/NDR alert verdict.
A scenario can be generated successfully even if the security product does not alert. Treat DSP execution evidence and product-side detection evidence as separate layers.
Preserve this relationship for each important POC finding:
This makes the final report auditable and prevents generated activity from being confused with detection success.

Regenerate a report

If the run artifacts still exist: