Reports & Evidence
Every DSP run creates a dedicated directory under:Start with these three files
For normal POC work, check these first:
The operator menu’s Show latest report option gives the quickest view of the most recent run.
Full artifact set
Evidence flow
For webshell runs, the remote host produces anevents.jsonl bundle. DSP retrieves it, imports the events into the local Event Store, and continues through the same validation/report/evidence pipeline.
What validation.json means
validation.json confirms DSP’s own execution and event expectations. It is not an XDR/NDR alert verdict.
A scenario can be generated successfully even if the security product does not alert. Treat DSP execution evidence and product-side detection evidence as separate layers.