Example reports

An appsec lead, a licensing owner and a SOC analyst need different parts of the same analysis.

Which sections a report shows is configurable. The three presets below are starting points rather than fixed views, and the control at the top of each report is real: it changes what is on the page, not what is highlighted on it.

lenssectionsfor
Minimal3 of 18Someone who needs an answer
Business11 of 18Someone making the decision
Technical18 of 18Someone checking the working
CustomanyDefine the sections you want. On the roadmap; the three above are the presets that ship.

A signed vendor installer

Everything checks out

Docker Desktop Installer.exe 4.38.0

The full eighteen sections and the lens toggle. Vendor intelligence at verified identity, and the four bundled executables that appear in an endpoint register with no catalog entry of their own.

An unsigned binary

Nothing to verify against

fabdeploy.exe, Fabrikam Deployment Utility 2.1.0

Attribution where there is no signature to lean on. This artifact is a row in the endpoint register at fineness 720, same value, same meaning, and here is the working behind it. Contractor-supplied, never published, in no catalog: the case a catalog cannot answer at all.

A macro-bearing document

The file contradicts itself

Remittance-Advice-2026-08.docm

A document whose stored macro source and compiled p-code describe different programs. Every tool that reads the source sees a date formatter. Extracted VBA, shown inert, with the divergence beside it: the case where reading the file is not merely better but is the only thing that works.

The data is fabricated and internally consistent: real vendors, real structures, written analysis. Sections marked in the margin are designed rather than shipped.