# Product Documentation

PlexTrac helps cybersecurity teams improve and centralize workflow management processes across the entire lifecycle. The platform streamlines all aspects of the process, from staging offensive engagements and conducting assessments to analyzing data and reporting, prioritizing critical issues, collaborating between teams, and communicating with stakeholders.

<div align="left"><figure><picture><source srcset="/files/c6DlEa1XqcrZIDzAqks4" media="(prefers-color-scheme: dark)"><img src="/files/9kKFSX7pO2uJRGknWOtI" alt=""></picture><figcaption></figcaption></figure></div>

{% hint style="info" %}
Visit the [Using This Site](/plextrac-documentation/master/using-this-site) page for orientation and tips about using the site navigation, exporting pages to PDF, using search, and leaving page feedback.
{% endhint %}

## PlexTrac Modules&#x20;

When logging in to PlexTrac, users are greeted by the **Dashboard** page. Seven modules exist besides the Dashboard: **Clients**, **Assessments**, **Reports**, **Priorities, Content Library**, **Analytics**, and **Runbooks**.&#x20;

Click a box to learn about a module.

<table data-view="cards"><thead><tr><th align="center"></th><th></th><th data-hidden>topics covered<select multiple><option value="21679e92a702429cb3c27685f1dfd0cb" label="User Assignments" color="blue"></option><option value="4a2068e36ed548ecbd7e29b06ca6be42" label="Findings Older Than 30 days" color="blue"></option><option value="0ce7614e78d74ee88594b3e095da59be" label="User Reports" color="blue"></option><option value="8ec41f34a9ed47eba0d3cfde11510e42" label="User Assessments" color="blue"></option><option value="ef06ba96e6aa455397863f1a205050fb" label="Adding Clients" color="blue"></option><option value="495e8e9a533d4b4ea5eaed80b38613da" label="Adding Assets" color="blue"></option><option value="37c7917153964527b79884c78ec92cad" label="Using Short Codes" color="blue"></option><option value="4f746167cb1044059ebfbd011809e98c" label="Exporting Reports" color="blue"></option><option value="4e99ced6ea5741f5998c79ba74a018cf" label="Creating Assessments" color="blue"></option><option value="fc39d09a064b4a668983c0862c058275" label="Creating Questions" color="blue"></option><option value="7aaec1e7bf35462f95c3f0f32ad6a9a1" label="Completing Aessessments" color="blue"></option><option value="7989a1068a22463693f526bb4aebe0cf" label="Answer Types" color="blue"></option></select></th><th data-hidden data-card-cover data-type="files"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td align="center"><strong>Dashboard</strong></td><td>viewing assigned findings, reports, assessments, and priorities</td><td><span data-option="21679e92a702429cb3c27685f1dfd0cb">User Assignments, </span><span data-option="4a2068e36ed548ecbd7e29b06ca6be42">Findings Older Than 30 days, </span><span data-option="0ce7614e78d74ee88594b3e095da59be">User Reports, </span><span data-option="8ec41f34a9ed47eba0d3cfde11510e42">User Assessments</span></td><td><a href="/files/deqnX1HLCDTEWy8L3qUz">/files/deqnX1HLCDTEWy8L3qUz</a></td><td><a href="/pages/3E0sebUyADQcNKYfXUx4">/pages/3E0sebUyADQcNKYfXUx4</a></td></tr><tr><td align="center"><strong>Clients</strong></td><td>adding clients, adding assets, using short codes, exporting reports</td><td><span data-option="ef06ba96e6aa455397863f1a205050fb">Adding Clients, </span><span data-option="495e8e9a533d4b4ea5eaed80b38613da">Adding Assets, </span><span data-option="37c7917153964527b79884c78ec92cad">Using Short Codes, </span><span data-option="4f746167cb1044059ebfbd011809e98c">Exporting Reports</span></td><td><a href="/files/MXHH6pPBolFls8gvhzh5">/files/MXHH6pPBolFls8gvhzh5</a></td><td><a href="/pages/-Lk6zcW1CzXz9-C_4XH1">/pages/-Lk6zcW1CzXz9-C_4XH1</a></td></tr><tr><td align="center"><strong>Schedule</strong></td><td>set up and view engagements and manage resources for reports</td><td></td><td><a href="/files/5aLxQGnaJOTlZGqqfTz0">/files/5aLxQGnaJOTlZGqqfTz0</a></td><td><a href="/pages/5uhjdeNqOs54NjSg7xfx">/pages/5uhjdeNqOs54NjSg7xfx</a></td></tr></tbody></table>

<table data-view="cards"><thead><tr><th align="center"></th><th></th><th data-hidden>topics covered<select multiple><option value="5998bf8a7c694d25aca1c84064fc8ab9" label="Creating Reports" color="blue"></option><option value="6ed1b44e0c1941d3ba18d6a487831661" label="Creating Findings" color="blue"></option><option value="18beec97a2b4418f9f5a9e5ac34e8099" label="Importing Findings" color="blue"></option><option value="f234a9d064514a68bdcabec05e347039" label="Importing Reports" color="blue"></option><option value="a8ce54a85ec74e92848e06724cc1c0b7" label="Types of Repositories" color="blue"></option><option value="00d42c6d04be4c649d15581c5425ceda" label="NarrativesDB" color="blue"></option><option value="830a534b33144b6d96d25bbd4e24c1fa" label="WriteupsDB" color="blue"></option><option value="91a25289bee54f6ca481991ce8fa7d29" label="RunbooksDB" color="blue"></option><option value="0ed25773ab3543cb8dfcec21fda96973" label="Findings " color="blue"></option><option value="920fdc5bea2841a29753ccfd51b1ac94" label="Assets" color="blue"></option><option value="9113c7f24986494382bd0df39d28f596" label="Runbooks" color="blue"></option><option value="1cac7ff8fe0c4db19fc2716d3db0ad88" label="Trends &#x26; SLAs" color="blue"></option></select></th><th data-hidden data-card-cover data-type="files"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td align="center"><strong>Assessments</strong></td><td>managing assessments, creating questions, managing answer types</td><td></td><td><a href="/files/eNAkDnqSZLRuV8SrMhSG">/files/eNAkDnqSZLRuV8SrMhSG</a></td><td><a href="/pages/-Lk7-CX6pmH30MUlXCzk">/pages/-Lk7-CX6pmH30MUlXCzk</a></td></tr><tr><td align="center"><strong>Reports</strong></td><td>creating reports, importing findings, exporting reports, affected assets</td><td><span data-option="5998bf8a7c694d25aca1c84064fc8ab9">Creating Reports, </span><span data-option="6ed1b44e0c1941d3ba18d6a487831661">Creating Findings, </span><span data-option="18beec97a2b4418f9f5a9e5ac34e8099">Importing Findings, </span><span data-option="f234a9d064514a68bdcabec05e347039">Importing Reports</span></td><td><a href="/files/G38Rf9LoC0hxV76S6MXq">/files/G38Rf9LoC0hxV76S6MXq</a></td><td><a href="/pages/-Lk7-KyezQaRUGwC26RF">/pages/-Lk7-KyezQaRUGwC26RF</a></td></tr><tr><td align="center"><strong>Priorities</strong></td><td>create priorities, link findings, link assets, manage scores and status</td><td></td><td><a href="/files/iEEXPGsbfWcvpsM9pp2G">/files/iEEXPGsbfWcvpsM9pp2G</a></td><td><a href="/pages/W4sI7gUhpwwS7uCLEPbM">/pages/W4sI7gUhpwwS7uCLEPbM</a></td></tr><tr><td align="center"><strong>Content Library</strong></td><td>set up and manage NarrativesDB, WriteupsDB,  and RunbooksDB</td><td><span data-option="a8ce54a85ec74e92848e06724cc1c0b7">Types of Repositories, </span><span data-option="00d42c6d04be4c649d15581c5425ceda">NarrativesDB, </span><span data-option="830a534b33144b6d96d25bbd4e24c1fa">WriteupsDB, </span><span data-option="91a25289bee54f6ca481991ce8fa7d29">RunbooksDB</span></td><td><a href="/files/20E7qKn3RVNOM7Dqsa8U">/files/20E7qKn3RVNOM7Dqsa8U</a></td><td><a href="/pages/9xb5lElQyCbtKjwYgXCm">/pages/9xb5lElQyCbtKjwYgXCm</a></td></tr><tr><td align="center"><strong>Analytics</strong></td><td>findings metrics, filters, assets metrics, runbooks metrics, trends &#x26; SLAs</td><td><span data-option="0ed25773ab3543cb8dfcec21fda96973">Findings , </span><span data-option="920fdc5bea2841a29753ccfd51b1ac94">Assets, </span><span data-option="9113c7f24986494382bd0df39d28f596">Runbooks, </span><span data-option="1cac7ff8fe0c4db19fc2716d3db0ad88">Trends &#x26; SLAs</span></td><td><a href="/files/Il5Phf5qoVBZ3DCoMhOR">/files/Il5Phf5qoVBZ3DCoMhOR</a></td><td><a href="/pages/-Lk70bz68FmhgDuz9EMA">/pages/-Lk70bz68FmhgDuz9EMA</a></td></tr><tr><td align="center"><strong>Runbooks</strong></td><td>engagements, test plans, procedures, importing and exporting runbooks</td><td></td><td><a href="/files/xn1SlyoX5uqxrLsPvKUF">/files/xn1SlyoX5uqxrLsPvKUF</a></td><td><a href="/pages/MhtwLeeNjRSeDZOxsXXB">/pages/MhtwLeeNjRSeDZOxsXXB</a></td></tr></tbody></table>

## Tenant Management

PlexTrac provides many options for configuring a tenant. Below are links to documentation for administration tasks, configuring user-specific settings, configuring authentication (OATH and SAML), integrating with APIs and parsers, installing and maintaining PlexTrac locally, and much more.

Click a box to learn about a topic.

<table data-view="cards"><thead><tr><th align="center"></th><th data-hidden></th><th data-hidden data-card-cover data-type="files"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td align="center"><strong>Tenant Administration</strong></td><td></td><td><a href="/files/aMKqS3ki0n7WoaeP7xAl">/files/aMKqS3ki0n7WoaeP7xAl</a></td><td><a href="/pages/es8f22GIGlpMEX8lfloa">/pages/es8f22GIGlpMEX8lfloa</a></td></tr><tr><td align="center"><strong>User Profile Settings</strong></td><td></td><td><a href="/files/WMy27A0dOIGShiaYfQ47">/files/WMy27A0dOIGShiaYfQ47</a></td><td><a href="/pages/MzKs6jH4YLaCVoWLA4XL">/pages/MzKs6jH4YLaCVoWLA4XL</a></td></tr><tr><td align="center"><strong>Authentication Methods</strong></td><td></td><td><a href="/files/s6Wfzy3GrExNuRz7TnP9">/files/s6Wfzy3GrExNuRz7TnP9</a></td><td><a href="/pages/-M3rMLhvhUwgA2J4ETkf">/pages/-M3rMLhvhUwgA2J4ETkf</a></td></tr><tr><td align="center"><strong>Integrations and Imports</strong></td><td></td><td><a href="/files/5MYfie0atyx0sgkh1HdN">/files/5MYfie0atyx0sgkh1HdN</a></td><td><a href="/pages/6iBwpvPTpulj6vdei2fO">/pages/6iBwpvPTpulj6vdei2fO</a></td></tr><tr><td align="center"><strong>Supported Applications</strong></td><td></td><td><a href="/files/waECU5pGFuMJy2xGF9j6">/files/waECU5pGFuMJy2xGF9j6</a></td><td><a href="/pages/M359bqvAcc1eDww4004O">/pages/M359bqvAcc1eDww4004O</a></td></tr><tr><td align="center"><strong>API Documentation</strong></td><td></td><td><a href="/files/hNCUAyJlRK3Kz2VAWe1Z">/files/hNCUAyJlRK3Kz2VAWe1Z</a></td><td><a href="/pages/2wuny8pVRdWqIckhK2Xk">/pages/2wuny8pVRdWqIckhK2Xk</a></td></tr></tbody></table>


# Dashboard

The **Dashboard** is a centralized hub where users can view relevant information in a single location. It is accessed by clicking **Dashboard** in the application's main menu.

<div align="left"><figure><img src="/files/eBGTyBTP0OvGlkbKSn2s" alt="" width="230"><figcaption></figcaption></figure></div>

## Overview

The Dashboard provides information regarding reports, assets, and findings based on a user's role, permission settings, and access to published reports.

<div align="left"><figure><img src="/files/OBtORidvpKq6tATqPq8h" alt="" width="563"><figcaption></figcaption></figure></div>

Information can be filtered by selecting the client from the pulldown menu.

<div align="left"><figure><img src="/files/bjAoFuqTrI2gajzsCT8p" alt="" width="311"><figcaption></figcaption></figure></div>

Clicking data points within the graphs and charts will open a side drawer with further information about the findings and assets referenced in the data.&#x20;

## My Work Page

This page displays assignments as users receive them and a list of recently accessed reports.&#x20;

<div align="left"><figure><img src="/files/UZZlT3HSjQ3HkDOx4Dag" alt=""><figcaption></figcaption></figure></div>

The My Work page is accessed by clicking the icon found at the top right of the page.

<div align="left"><figure><img src="/files/uh9fbAwPg2vO5aEAlDap" alt="" width="305"><figcaption></figcaption></figure></div>

### Recent Reports

Once a report is viewed, a box will appear at the top of the page. This box displays the report's title, status, client, and the number of findings and assets. Clicking the box opens the report.&#x20;

### Assignments

&#x20;Assignments are grouped by type.

* **My findings**
* **My reports**
* **My assessments**
* **My priorities**

Assignments result from associations made from multiple areas of PlexTrac, such as being identified as a report operator, an assignee of a finding, or a reviewer of an assessment.&#x20;

Click a tab for more information about each topic assignment, including the assigned role for the report or assessment.

## Customizing Table View

The columns displayed in the table view of each assignment tab can be added or removed by clicking the column icon on the right of the page.&#x20;

<div align="left"><figure><img src="/files/CuFegPWRzd0HGK6deJ0E" alt="" width="563"><figcaption></figcaption></figure></div>

Once clicked, a modal appears that lists all fields that exist for that box.&#x20;

<div align="left"><figure><img src="/files/gchYpYci618Qy7PwsXmL" alt="" width="563"><figcaption></figcaption></figure></div>

To remove a column, click **X** within the bar.&#x20;

<div align="left"><figure><img src="/files/PiHkt7sj2xryaCGu8mos" alt="" width="563"><figcaption></figcaption></figure></div>

{% hint style="info" %}
Fields that are required and cannot be eliminated do not have an **X** available.&#x20;
{% endhint %}

When fields are removed, an "Add Column" pulldown menu is added at the bottom left of the modal to store the field. Any removed fields can be added later by clicking **Add Column** and selecting the field to add. &#x20;

<div align="left"><figure><img src="/files/oyJ5rAujwZfR6GPFiYDY" alt="" width="563"><figcaption></figcaption></figure></div>

This modal represents the sequence of fields provided in the table, meaning the bar on top will be the column that appears on the far left of the relevant box.&#x20;

The order of columns can be adjusted within this modal by clicking the six dots on the left of the bar for a field and dragging the bar to the desired sequence place.&#x20;

<div align="left"><figure><img src="/files/R7Ub0yjCazg2Mxpv5jXu" alt="" width="563"><figcaption></figcaption></figure></div>

Each topic has its list of fields and must be customized separately.&#x20;

## Notifications

Messages received within PlexTrac are stored on the **Notifications** page.

<div align="left"><figure><img src="/files/IREbT4rNigl0B78ewh0l" alt=""><figcaption></figcaption></figure></div>

This page is accessed by clicking the bell icon at the top of any PlexTrac page next to the user name and then clicking **View All**.

<div align="left"><figure><img src="/files/roRUgTFZC1J845HPo9Yw" alt="" width="296"><figcaption></figcaption></figure></div>

When new notifications exist, the bell will have a red outline.

<div align="left"><figure><img src="/files/4VRciDWyGbWy2HYPCXNS" alt="" width="321"><figcaption></figcaption></figure></div>

Clicking the bell will provide a list of unread notifications. Clicking a notification directly will send the user to the page that prompted it, and the notification will be set to the "Read" status.


# Clients

In the **Clients** module, users can group and categorize data as needed. This helps manage confidentiality, integrity, and availability effectively while enhancing collaboration and catering to individual client needs.

Users access the module by clicking **Clients** in the application's main menu.

<div align="left"><figure><img src="/files/9NCkF0ZiVVAmBUe3nPtV" alt="" width="351"><figcaption></figcaption></figure></div>

## Overview

PlexTrac defines a client as a logical grouping utilized to segregate data. The term holds various meanings within different organizations, depending on the context in which it is used.

For teams external to the consulting organization, the term "client" typically refers to the individuals or entities that utilize their services. These clients may include businesses, government agencies, or other organizations that engage the consulting team to assess their cybersecurity posture, conduct vulnerability assessments, or provide related services. For these external teams, the client represents the entity they work for and to whom they deliver their expertise.

For teams operating within the boundaries of an organization or company, a client could refer to a specific project, a business unit, a regional office, or a program within the organization. Defining a client in this manner facilitates segregating data, findings, reports, and assets, ensuring that information is appropriately isolated within the relevant groupings.

By organizing data according to different clients, teams can manage and maintain confidentiality, integrity, and information availability. This approach allows for more collaboration and reporting within specific client-based units, prevents data overlap and ensures that each client's unique requirements and concerns are adequately addressed.

The **Clients** module home page displays all clients in a tenancy.&#x20;

<div align="left"><figure><img src="/files/DXbBv4WONf32Oo0O13nC" alt="" width="563"><figcaption></figcaption></figure></div>

The table view is highly customizable, allowing users to select which columns are displayed to suit their specific needs. For a deeper dive into individual client details, clicking "View" under the "Actions" column navigates directly to the "Details" tab of the Client Summary page.&#x20;

Similarly, clicking "Reports" provides a quick link to all reports related to a specific client. This directs users to the "Reports" tab of the Client Summary page. To review the assets linked to a client, select "View Assets," which takes users to the "Assets" tab. Finally, the interface also allows the deletion of a client.

### Configuring Table View

The table view on the **Clients** home page can be customized by clicking the column view icon to the right of the search bar.

Once clicked, a modal appears that lists all fields.

<div align="left"><figure><img src="/files/hqjrOTZrCJrcQ5Rrbsc7" alt="" width="563"><figcaption></figcaption></figure></div>

To remove a column, click **X** within the bar.&#x20;

{% hint style="info" %}
Fields that are required and cannot be eliminated do not have an **X** available.&#x20;
{% endhint %}

When fields are removed, an "Add Column" pulldown menu is added at the bottom left of the modal to store the field. Any removed fields can be added later by clicking **Add Column** and selecting the field to add. &#x20;

<div align="left"><figure><img src="/files/ZKtegHKcKKgpLSeGcske" alt="" width="563"><figcaption></figcaption></figure></div>

This modal also represents the sequence of fields provided in the table, meaning the bar at the top is the column that appears on the far left of the relevant box.&#x20;

The order of columns can be adjusted within this modal by clicking the six dots on the left of the bar for a field and dragging the bar to the desired sequence place.&#x20;

<div align="left"><figure><img src="/files/PdZ2uNiRYbmgkBAX3a8Y" alt="" width="563"><figcaption></figcaption></figure></div>

Click **Save** when finished.&#x20;


# Clients Components

PlexTrac offers easy access to detailed client information. By clicking on a client's row from the **Clients** module home page, the user is directed to a summary page, which includes tabs for **Reports**, **Findings**, **Assets**, **Procedures**, **Details**, **Statistics,** and **Priorities**.&#x20;

These tabs offer insights into the client's reports, findings, asset inventory, client-specific details, and finding metrics. PlexTrac ensures a cohesive and organized approach to client management by centralizing all client data in one place.

## Reports Tab

This tab lists all the reports associated with a client. It can also be reached by clicking **Reports** under the "Actions" column from the **Client** home page. &#x20;

{% hint style="info" %}
Visit the [Reports section](/plextrac-documentation/product-documentation/reports) of this site for documentation on creating, editing, importing, and exporting reports.&#x20;
{% endhint %}

This tab displays the report title, status, classification, creation date, and finding count. It allows direct access to the Report Readout page and associated findings. Click one of the rows for more information about a specific report.

<div align="left"><figure><img src="/files/z7j0h8dGhdIFzH3pdpmn" alt="" width="563"><figcaption></figcaption></figure></div>

### Bulk Actions

When editing multiple reports, PlexTrac offers bulk action capabilities. Bulk actions provide several advantages, including time-saving and increased efficiency by processing numerous items simultaneously.

<div align="left"><figure><img src="/files/M05P2oH7YXs4d8cpjRrZ" alt="" width="563"><figcaption></figcaption></figure></div>

Click **Actions** to see the list of options for reports.

<div align="left"><figure><img src="/files/DXKto2jvckinWBYapvwO" alt="" width="473"><figcaption></figcaption></figure></div>

### Configuring Table View

The table view can be customized by clicking the column view icon to the right of the search bar.

Once clicked, a modal appears that lists all fields. To remove a column, click **X** within the bar.

<div align="left"><figure><img src="/files/DHzRkMd0gXZL2RjjNepS" alt="" width="563"><figcaption></figcaption></figure></div>

{% hint style="info" %}
Fields that are required do not have an **X** available.
{% endhint %}

When fields are removed, an "Add Column" pulldown menu is added at the bottom left of the modal to store the field. Any removed fields can be added later by clicking **Add Column** and selecting the field to add. &#x20;

<div align="left"><figure><img src="/files/p7ol6iM79X7S3OIw39eH" alt="" width="563"><figcaption></figcaption></figure></div>

This modal represents the sequence of fields provided in the table, meaning the bar on top will be the column on the table's far left.&#x20;

The order of columns can be adjusted within this modal by clicking the six dots on the left of the bar for a field and dragging the bar to the desired sequence place.

<div align="left"><figure><img src="/files/9NG7kZ9cgeVwnqCEX8gZ" alt="" width="563"><figcaption></figcaption></figure></div>

Click **Save** when finished.&#x20;

## Findings Tab

This tab lists all the findings associated with a client via a report.

{% hint style="info" %}
Visit the [Findings section](/plextrac-documentation/product-documentation/reports/findings) of this site for documentation on creating, editing, and importing findings.&#x20;
{% endhint %}

<div align="left"><figure><img src="/files/Hzu8Zz9Eki8f1Qd3nNKi" alt="" width="563"><figcaption></figcaption></figure></div>

Clicking a finding row opens a side drawer and the findings detail view. From this view, a finding status can be edited by clicking the status value, and affected assets can be viewed and edited directly.

{% hint style="info" %}
If a client has multiple reports with the same finding, the highest severity value among all occurrences will be displayed at the client level. However, at the report level, the finding will only have the severity value assigned for that specific report.
{% endhint %}

### Bulk Actions

Bulk action options appear after one or more findings are selected by clicking the checkbox to the far left of the Finding Title field or by clicking the box next to the column header.&#x20;

Click **Actions** to see the list of options available.

<div align="left"><figure><img src="/files/t6Cvoib7H8vRlZyADTul" alt="" width="491"><figcaption></figcaption></figure></div>

### Configuring Views

The table view can be customized by clicking the column view icon to the right of the search bar.

## Assets Tab

This tab lists all the assets associated with a client and the ability to view the asset, edit the asset properties, add any notes, or delete the asset.

<div align="left"><figure><img src="/files/RkiO8CL8k2AR739OxSGK" alt="" width="563"><figcaption></figcaption></figure></div>

{% hint style="info" %}
[Visit adding assets to a client](/plextrac-documentation/product-documentation/clients/adding-assets-to-a-client) for more information on adding an asset to a report.
{% endhint %}

### Bulk Actions

Bulk action options appear after selecting one or more assets by clicking the checkbox to the far left of the Assets field or by clicking the box next to the column header.&#x20;

Click **Actions** to see the options available, such as linking to a priority or adding tags.

### Configuring Table View

The table view can be customized by clicking the column view icon to the right of the search bar.

## Procedures Tab

This tab streamlines the creation and management of procedures within reports, offering a view of all procedures and tactics associated with a client.

<div align="left"><figure><img src="/files/d2p52XrfLn0VPvqk8jFi" alt="" width="563"><figcaption></figcaption></figure></div>

### Configuring Table View

The table view can be customized by clicking the column view icon to the right of the search bar.

## Details Tab

This tab provides an overview of the client for all *published* reports. Its primary purpose is to provide a snapshot of the client's security posture and progress in addressing the identified issues. It is a centralized dashboard where users can quickly assess the client's status at a glance, enabling efficient monitoring and decision-making.

<div align="left"><figure><img src="/files/NGjx5wrVUQTrfqTvYlAz" alt="" width="563"><figcaption></figcaption></figure></div>

Clicking on **Edit Client Information** offers options for managing the client's logo, name, point of contact, description, tags, and the ability to add custom fields. It is also where [authorized users](/plextrac-documentation/product-documentation/clients/managing-clients), roles, and classification levels are managed.

## Statistics Tab

This tab offers a snapshot of a client's findings based on severity and status for all *published* reports.&#x20;

By organizing findings by severity and status, users can quickly identify the number of open or unresolved findings that require attention and follow-up actions.

<div align="left"><figure><img src="/files/vrTU2urxdWD6N7c9r16K" alt="" width="563"><figcaption></figcaption></figure></div>

## Priorities Tab

This tab summarizes all client priorities. The list displayed depends on whether the [tenancy enables client-specific or tenant-level priorities](/plextrac-documentation/product-documentation-1/account-management/account-admin/tenant-settings/general-settings#priorities).&#x20;

It can be determined whether a priority applies to all clients or a specific one based on the "Client" column value. If a priority applies to all clients, an "All clients" value is displayed. If it is client-specific, the client's name will appear instead.&#x20;

<div align="left"><figure><img src="/files/uZYSQNlQb9XrFgob4vqO" alt=""><figcaption></figcaption></figure></div>

The priority can be accessed directly by clicking on its title or row.

### Bulk Actions

Bulk action options appear after one or more priorities are selected by clicking the checkbox to the far left of the Priority field or by clicking the box next to the column header.&#x20;

Once available, click on **Actions** to see the list of options.

### Configuring Table View

The table view can be customized by clicking the column view icon to the right of the search bar.


# Creating a Client

The "Create New Client" modal allows users to input essential information, such as the client's name, logo, point of contact, client notes, tags, and custom fields.&#x20;

Users can create a comprehensive profile for each client, enabling efficient data collection, organization, and management within PlexTrac.

<mark style="background-color:yellow;">Step 1:</mark> From the **Clients** module home page, click **New client**.

<div align="left"><figure><img src="/files/Xo7lW7rpV1isShiAoljv" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> A modal appears with the following fields:

<div align="left"><figure><img src="/files/Pf0PNmzgPG9eSnWBFIS5" alt="" width="563"><figcaption></figcaption></figure></div>

1. **Client Logo**: To represent the client visually, drag an image or click the designated box to navigate to a picture on the computer.
2. **Client Name (required)**: Enter the client or project name that will identify this data collection throughout PlexTrac.&#x20;
3. **Point of Contact**: Enter the resource's name to contact about the data collection.
4. **Point of Contact Email**: Enter the resource's email address. If the email of a current PlexTrac user is entered, this person is added as a client user with the analyst role. If the person creating the client adds themselves as the point of contact, their default tenancy role (i.e., admin) is assigned. All roles [can be adjusted](/plextrac-documentation/product-documentation/clients/manage-client-users#changing-user-roles).
5. **Client Description/Details**: Enter any pertinent information to help provide users context.
6. **Tags**: Enter any tags associated with the client (new or existing). Any special characters will be removed, and any spaces will be replaced with an underscore (\_).
7. **Add Custom Field**: Enter additional fields and values needed to enhance the client's management.

<mark style="background-color:yellow;">Step 3:</mark> Click **Submit**.

<div align="left"><figure><img src="/files/2ANvMoUdECmZZidYXJ4r" alt="" width="375"><figcaption></figcaption></figure></div>

The new client now appears on the Clients module home page.


# Managing Clients

Once clients have been added, PlexTrac offers a range of features that facilitate editing and managing information, including contact details, custom fields, logos, and additional notes and details. Users can ensure client information remains accurate and relevant with just a few clicks.

## Editing Client Information

<mark style="background-color:yellow;">Step 1:</mark> From the **Clients** module home page, click **View** under the "Actions" menu for the impacted client.

<figure><img src="/files/T2rgI8qVzv05AZApI5tL" alt=""><figcaption></figcaption></figure>

<mark style="background-color:yellow;">Step 2:</mark> Click **Edit Client Information**.

<div align="left"><figure><img src="/files/ZONHzYs9huLakvcHYIVy" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4:</mark> The "Edit Client Information" modal appears and can be modified as desired. Click **Submit** when finished.&#x20;

<div align="left"><figure><img src="/files/jXHAP5vo3526NzVV2nFl" alt="" width="563"><figcaption></figcaption></figure></div>

## Deleting a Client

<mark style="background-color:yellow;">Step 1:</mark> From the **Clients** module home page, click the three dots under the "Actions" column corresponding to the client and click **Delete Client**.&#x20;

<div align="left"><figure><img src="/files/nkWdjt0STC7GXwhagpfn" alt="" width="467"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> A modal will appear, confirming the action. Type in the client name and click **Delete**.&#x20;

<div align="left"><figure><img src="/files/EsTNDYMlwvT2qpXW5R5f" alt="" width="358"><figcaption></figcaption></figure></div>


# Managing Client Users

PlexTrac offers role-based access controls (RBAC) at the client level. RBAC allows teams to efficiently manage user privileges and permissions based on specific client requirements, enabling effective collaboration and task accomplishment.

Within PlexTrac, three default levels of access exist that can be assigned to users based on their responsibilities:

1. **Administrator**: An Administrator has the highest access level within PlexTrac. They possess extensive privileges and can perform various tasks, including creating reports, adding findings, tracking status, managing users, configuring settings, and accessing all areas of the platform related to the client.&#x20;
2. **Standard User**: A Standard User plays a crucial role in managing and documenting client activities. They can create reports, add findings, and track the status of ongoing projects. This level of access allows Standard Users to contribute actively, collaborate with other team members, and provide valuable insights throughout the process.
3. **Analyst**: An Analyst is a user with a more limited role. Their primary responsibility is to track and update the status of identified vulnerabilities. While they may not have the authority to create reports or add findings, their role is essential in ensuring the accurate documentation and timely resolution of identified issues. Analysts can provide real-time updates on the progress of vulnerability mitigation efforts, making it easier for the broader team to stay informed and take necessary actions.

These default access levels ensure each team member has the appropriate privileges and responsibilities aligned with their role and contribution to the client's initiatives. By assigning specific access levels, teams can streamline workflows, maintain data integrity, and improve overall efficiency in managing and securing client environments.

{% hint style="info" %}
The [RBAC page](/plextrac-documentation/product-documentation-1/account-management/account-admin/security-and-user-management/security/rbac) provides more information on default roles, permissions throughout the platform, and user licensing.
{% endhint %}

## Licensing

An icon will appear at the end of the role title when adding a user to a licensed role, regardless of the number of licenses available.

<div align="left"><figure><img src="/files/ajauYgpP6yZxvrmT92gN" alt=""><figcaption></figcaption></figure></div>

Any messaging regarding user licenses will appear as a banner on the "Authorize Client Users" modal.

<div align="left"><figure><img src="/files/d80Qw1WF61q2ekvekTZb" alt=""><figcaption></figcaption></figure></div>

{% hint style="info" %}
Visit the [RBAC page](https://docs.plextrac.com/plextrac-documentation/product-documentation-1/account-management/account-admin/security-and-user-management/rbac#licensed-permissions) for information on the various messaging related to licensed users and their relationship to permissions.
{% endhint %}

## Adding Users to a Client

<mark style="background-color:yellow;">Step 1:</mark> From the **Clients** module home page, click **View** under the "Actions" menu for the impacted client.

<div align="left"><figure><img src="/files/6KZ0vN7vlHnbwPQNq5To" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Scroll to the "User access" section and click **Add/Authorize User**.&#x20;

<div align="left"><figure><img src="/files/OeyQ7Yh4R6QxpC8KoQnM" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Select the user to add from the "User" field pulldown menu.&#x20;

<div align="left"><figure><img src="/files/4n1ecZk51AT9MGJwxrUn" alt=""><figcaption></figcaption></figure></div>

Only *existing* users in the tenancy who are *not* authorized for the client appear in the pulldown menu.

After adding a user, the "Role" and "Classification" fields will be automatically filled in but can be changed.&#x20;

<mark style="background-color:yellow;">Step 4:</mark> Click **Add User** to add additional users (if applicable). Click **Save** when finished.&#x20;

<div align="left"><figure><img src="/files/SPvQ8ll3xeliNnDt24IN" alt=""><figcaption></figcaption></figure></div>

## Deleting a User

<mark style="background-color:yellow;">Step 1:</mark> From the **Clients** module home page, click **View** under the "Actions" menu for the impacted client.

<div align="left"><figure><img src="/files/B6kUce0BbVPF1ePKSKD9" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Scroll down to the "User Access" section and click **Revoke** under the "Actions" column in the user's row to remove access permissions.

<div align="left"><figure><img src="/files/v2Xr6OXUoIocZF6gVUpg" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> A dialog box will appear confirming the action. Click **Revoke**.

## Changing User Roles

<mark style="background-color:yellow;">Step 1:</mark> From the **Clients** module home page, click **View** under the "Actions" menu for the impacted client.

<div align="left"><figure><img src="/files/2l8czPjjV2CDJogcEmYC" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Under the "User Access" section, select the new role from the pulldown menu in the "Role" column for the user.

<div align="left"><figure><img src="/files/p2oH6dxqCXGdad2U3EcI" alt=""><figcaption></figcaption></figure></div>

The change is immediate. A dialog box will appear at the bottom left of the screen confirming the change.

## Changing User Classification Level

<mark style="background-color:yellow;">Step 1:</mark> From the **Clients** module home page, click **View** under the "Actions" menu for the impacted client.

<div align="left"><figure><img src="/files/KB0fPKvDstsW0EWRLZnK" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Scroll down to the "User Access" section and click the pulldown menu under the "Classification Level" column of the user impacted.&#x20;

<div align="left"><figure><img src="/files/Ldsh1sC7WDhyBMciFK7l" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Select the new classification level.

The change is immediate. A dialog box confirming the change will appear at the bottom left of the screen.


# Adding Assets to a Client

Assets within PlexTrac are stored outside of reports at the client level within the platform. An asset can exist as a standalone file in the Clients module or associated with a finding, referred to as an affected asset. &#x20;

Organizations can efficiently manage and track their cybersecurity resources by organizing and storing assets in PlexTrac. This centralized approach ensures that important files and information are readily accessible when necessary, facilitating collaboration, efficient vulnerability management, and streamlined remediation efforts.&#x20;

## Creating an Asset

<mark style="background-color:yellow;">Step 1:</mark> From the **Clients** module home page, click the client's row or **View** under the "Actions" column.

<figure><img src="/files/JXe9vvQSOmrDYhjNar7G" alt=""><figcaption></figcaption></figure>

<mark style="background-color:yellow;">Step 2:</mark> Click the **Assets** tab.

<mark style="background-color:yellow;">Step 3:</mark> Click the **Add assets** pulldown menu and select **Create asset**.

<div align="left"><figure><img src="/files/MR9wsbLKdmLsAeQl0zJj" alt="" width="403"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4:</mark> The "New Asset" modal appears. Enter the desired information into the appropriate fields.

{% hint style="info" %}
Asset Name is the only required field.
{% endhint %}

<div align="left"><figure><img src="/files/Dx2yc9pccEQGWZPqmgSw" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 5:</mark> Click **Save** at the bottom of the modal.&#x20;

<div align="left"><figure><img src="/files/INBls41jcZ9qGMtSrYRp" alt=""><figcaption></figcaption></figure></div>

The asset now appears in the **Assets** tab.

## Adding Assets via Bulk Paste

<mark style="background-color:yellow;">Step 1:</mark> From the **Clients** module home page, click the client's row or **View** under the "Actions" column.

<div align="left"><figure><img src="/files/MPmDZtegkmqRRZmFlRcc" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Click the **Assets** tab.

<mark style="background-color:yellow;">Step 3:</mark> Click **Add assets**, then select **Bulk paste assets** from the pulldown menu.

<div align="left"><figure><img src="/files/nN0CQEq8mfiF0ZxS07Dm" alt="" width="403"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4:</mark> Paste asset information into the provided box as a return- or comma-separated list. PlexTrac will parse the assets and add them to the finding. URLs with paths (i.e., [www.plextrac.com/test/](http://www.plextrac.com/test/)) will be separated into parent and child assets.

<div align="left"><figure><img src="/files/crQQuPCwX69ZQqguQqrQ" alt="" width="563"><figcaption></figcaption></figure></div>

{% hint style="info" %}
Check "Preserve pasted assets" to treat the pasted content as a monolithic asset. The parser will **not** attempt to break down the asset into its constituent parts (child assets) or identify potentially vulnerable parameters.\
\
![](/files/bQCrhoAkPzcXpWjQELDu)
{% endhint %}

<mark style="background-color:yellow;">Step 5:</mark> Click **Next**.

<mark style="background-color:yellow;">Step 6:</mark> PlexTrac will search for assets in the bulk paste that match existing assets and identify them separately from new assets on the **Review** tab. This provides the option to deselect any assets before import.

<div align="left"><figure><img src="/files/BE1nDPdiTbZfBTQx9p4i" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 7:</mark> Click **Next**.

<mark style="background-color:yellow;">Step 8:</mark> Add any tags (optional). Click **Add X assets**.

<div align="left"><figure><img src="/files/0Vj06RgEcmbok55pLBc0" alt="" width="563"><figcaption></figcaption></figure></div>

A message confirming the import and assets are viewable from the **Assets** tab will appear.

## Importing Assets to Clients

PlexTrac supports asset imports using an NMAP file or a CSV template:

* **NMAP files**: Network Mapper is a [free, open-source ](https://nmap.org/)network discovery and security auditing utility. More information on NMAP can be found on PlexTrac's [Integrations](/plextrac-documentation/product-documentation-1/integrations-and-file-imports) section of this site.
* **CSV**: PlexTrac provides a template for uploading assets to a client. Click the file below to download the template:

{% file src="/files/fyFq6f012j9gylfefx39" %}
updated 4-20-2023
{% endfile %}

### CSV Asset Template Rules

The template is prepopulated with all permitted fields and sample values.&#x20;

{% hint style="danger" %}
Do not add additional columns or some data may not be imported.&#x20;
{% endhint %}

| Column Header     | Description                                          | Sample Value                                  | Comments                                                                                                                                                                                                                                                                                                                                                |
| ----------------- | ---------------------------------------------------- | --------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| name              | Asset Name                                           | temp-asset-1                                  |                                                                                                                                                                                                                                                                                                                                                         |
| ip addresses      | IP address of the asset                              | 10.0.0.10                                     |                                                                                                                                                                                                                                                                                                                                                         |
| criticality       | Importance level of the asset                        | High                                          |                                                                                                                                                                                                                                                                                                                                                         |
| data owner        | Person responsible for the data                      | Jane Pentester                                |                                                                                                                                                                                                                                                                                                                                                         |
| physical location | Geographic location of the asset                     | Boise                                         |                                                                                                                                                                                                                                                                                                                                                         |
| system owner      | Person responsible for the system                    | John                                          |                                                                                                                                                                                                                                                                                                                                                         |
| ports             | Open/closed ports and associated services            | 22/open/tcp//ssh//OpenSSH 4.3 (protocol 2.0)/ | Each port can have up to eight values, separated by a slash. See the Ports section below after the table for more information.                                                                                                                                                                                                                          |
| tags              | Categorization tags                                  | Karbo                                         |                                                                                                                                                                                                                                                                                                                                                         |
| description       | Brief description of the asset                       | csv-desc1                                     |                                                                                                                                                                                                                                                                                                                                                         |
| parent            | Hierarchical relationship                            | Child 1                                       |                                                                                                                                                                                                                                                                                                                                                         |
| type              | Asset type                                           | Workstation                                   | <p>The value for this field must be one of the following: <code>Workstation</code>, <code>Server</code>, <code>Network Device</code>, <code>Application</code>, or <code>General</code>. If another value is used, it will be ignored, and the Asset Type value will display in PlexTrac as "Not Set."<br></p><p>This field is not case-sensitive. </p> |
| host fqdn         | Fully Qualified Domain Name                          | [www.plextrac.com](http://www.plextrac.com/)  |                                                                                                                                                                                                                                                                                                                                                         |
| hostname          | Name of the host                                     | temp-asset-1                                  |                                                                                                                                                                                                                                                                                                                                                         |
| host rdns         | Reverse DNS lookup                                   | 4.3.2.1.in-addr.arpa                          |                                                                                                                                                                                                                                                                                                                                                         |
| dns name          | DNS name associated with the asset                   | 192.0.2.44                                    |                                                                                                                                                                                                                                                                                                                                                         |
| mac address       | Media Access Control address                         | 00-B0-D0-63-C2-26                             |                                                                                                                                                                                                                                                                                                                                                         |
| netbios name      | NetBIOS name of the asset                            | temp-asset-1                                  |                                                                                                                                                                                                                                                                                                                                                         |
| total cves        | Total number of Common Vulnerabilities and Exposures | 8                                             |                                                                                                                                                                                                                                                                                                                                                         |
| pci status        | Payment Card Industry compliance status              | Fail                                          | <p>The value for this field must be blank, <code>Pass</code>or <code>Fail</code>. If another value is used, it will be ignored, and the Asset Type value will display in PlexTrac as "Not Set."<br></p><p>This field is not case-sensitive. </p>                                                                                                        |
| operating system  | OS running on the asset                              | Windows 11                                    |                                                                                                                                                                                                                                                                                                                                                         |

#### Ports

Column G ingests port information imported and found in the asset's **Notes/Description** tab.

<div align="left"><figure><img src="/files/LVUqf9JDXkTy4XVhwjll" alt=""><figcaption></figcaption></figure></div>

Multiple values for the ports cell are separated by commas, such as:&#x20;

`22/open/tcp//ssh//OpenSSH 4.3 (protocol 2.0)/, 25/open/tcp//smtp///, 53/closed/tcp//domain///, 70/open/tcp//gopher///, 80/open/tcp//http//Apache http 2.2.3 ((CentOS))/, 113/open/tcp//auth///, 31337/open/tcp//Elite///`

Each port can have up to eight values, separated by a slash. This means there must be seven slash characters (/) for each port ingested, even if no data exists within the slashes. If the correct number of slashes is not used, an import error will appear, and the file will not be accepted.

Examples of valid data values for the ports field:&#x20;

* 80///////
* 80/open//////
* 80/open/tcp/////
* 80/closed/tcp/auth////
* 80/open/tcp/auth/ssh///
* 80/open/tcp/auth/ssh/test 6//
* 80/open/tcp/auth/ssh/test 6/Apache http 2.2.3 (CentOS)/

The first value captures the port number. The second value captures the port status (any ports with a status of `Closed` will not be imported). The third value captures the protocol. The fifth value captures the service, and the seventh value captures the version.

{% hint style="info" %}
If the port has a defined closed status, the cell is left blank entirely (the field is optional), or just one value is entered (such as `15.22.161.22`), then it is not necessary to include all seven slashes.&#x20;
{% endhint %}

### Importing Assets

<mark style="background-color:yellow;">Step 1:</mark> From the **Clients** module home page, click the report row or **View** under the "Actions" column.

<div align="left"><figure><img src="/files/yVXLE27NrHjbl9TxgCtW" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Click the **Assets** tab.

<mark style="background-color:yellow;">Step 3:</mark> Click **Add assets**, then select **Bulk paste assets** from the pulldown menu.

<div align="left"><figure><img src="/files/JWYliFB5bzdnbtCKloIu" alt="" width="403"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4:</mark> Drag a file into the modal or click the box to navigate to the file on the computer.&#x20;

<div align="left"><figure><img src="/files/IroKljIuuVnUA5CXk197" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 5:</mark> Click **Import**.&#x20;

<div align="left"><figure><img src="/files/lv3ydpsBPcSbNILhfsWS" alt="" width="563"><figcaption></figcaption></figure></div>

A message will appear confirming import.

The new assets are displayed on the **Assets** tab. To view imported values, click **View** of the imported asset.&#x20;

<div align="left"><figure><img src="/files/s1X2IzZBuQzro5WKDC22" alt="" width="563"><figcaption></figcaption></figure></div>

To view imported port information, click **Notes/Descriptions**.


# Managing Assets

Existing assets in PlexTrac are managed from the **Clients** module. Assets may be found either from the **Assets** tab of a client, the **Assets** tab of a report, or via the **Findings>Affected Assets** tab when creating or modifying a finding.

## Modifying an Asset for a Client

<mark style="background-color:yellow;">Step 1:</mark> Within a client, click the **Assets** tab.

<mark style="background-color:yellow;">Step 2:</mark> Click **Edit** under the "Actions" column of the asset to modify.

<div align="left"><figure><img src="/files/KJLYNf9czSmwXkE0tetz" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Update desired fields on the "Edit Asset" page.

<div align="left"><figure><img src="/files/MDEyqsFfbB46xA8MQFZt" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4:</mark> Click **Asset Detail**.

<div align="left"><figure><img src="/files/TCqyoBzHNyZiNn5qbskZ" alt="" width="428"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 5:</mark> A list of asset metadata and the **Associated findings** tab are presented. Click **Notes/Description**.

<div align="left"><figure><img src="/files/jxXH2MXtApFqu9OQ2NQI" alt="" width="563"><figcaption></figcaption></figure></div>

{% hint style="info" %}
The **Associated findings** tab table view can be customized by clicking the column icon to the right of the search bar.

![](/files/XwoBzmkDy0C4ntziXC7c)
{% endhint %}

<mark style="background-color:yellow;">Step 5:</mark> Existing ports, notes, and descriptions are presented. Add information by clicking **Add Note**.

<div align="left"><figure><img src="/files/DeNmy2kjOTvAGp4Ce3qC" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 6:</mark> Click the **Child assets** tab to view any child assets that may exist. The **Child assets** tab table view can be customized by clicking the column icon to the right of the search bar.

<div align="left"><figure><img src="/files/odoMI9Glyin21R7cY3Mz" alt="" width="563"><figcaption></figcaption></figure></div>

## Bulk Actions

Bulk action options appear after selecting one or more assets by clicking the checkbox or the box next to the column header.&#x20;

<div align="left"><figure><img src="/files/F1yb9lLdvHDxCw0FBJhf" alt="" width="464"><figcaption></figcaption></figure></div>

Click **Actions** to see the options available, such as linking to a priority or adding a tag.


# Using Short Codes for Clients

Short codes are small snippets that perform search-and-replace operations throughout the platform. They are designed to streamline report creation and promote data reuse, saving time and ensuring consistency across reports. Short codes can be utilized within report narratives and finding's rich-text fields to automate specific tasks and provide standardized content.

Short codes can simplify report creation by eliminating the need to modify repetitive or common content sections manually. Users can define code snippets once and reuse them across multiple reports, saving time and ensuring consistency by applying the same language, formatting, or information throughout different reports.

{% hint style="warning" %}
Administrators handle [creating and managing short codes](/plextrac-documentation/product-documentation-1/account-management/account-admin/tenant-settings/short-codes). Short codes must have been previously set up by an admin.
{% endhint %}

Short codes can be applied at the client level to all reports related to that client. However, they can also be inserted at the [report level](/plextrac-documentation/product-documentation/reports/short-codes) if they are relevant only to a specific report.

## Adding Short Codes

<mark style="background-color:yellow;">Step 1:</mark> From the **Clients** module home page, click **View** under the "Actions" menu for the impacted client to reach the **Details** tab.

<div align="left"><figure><img src="/files/nqFLNo6kDTO4djf3L6pq" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Click **Edit Client Information**.

<div align="left"><figure><img src="/files/uhIsL2N1Wr6zjEwOtzC0" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> At the bottom of the modal, click **Add Custom Field**.

<div align="left"><figure><img src="/files/uk5pfigoHpdwvUVZWqQI" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4:</mark> In the first box on the left, enter the label value corresponding to the appropriate short code and insert the text value that will replace the short code in the second box on the right.

<div align="left"><figure><img src="/files/zZhrER14yRWst5mb1qGm" alt=""><figcaption></figcaption></figure></div>

The "Value" box value will replace the short code (i.e., `%%LOCATION%%`) whenever found in the report's narratives or finding's rich-text fields.

{% hint style="warning" %}
The "Label" box value must be in the list of tenant short codes and set to "Client Field" for **Source**. \ <img src="/files/4ZzXrxRoijaZTo1n93Pt" alt="" data-size="original"><br>
{% endhint %}

The **Custom Field** label links the short code to the value (text data) to replace it. For example:

* **Label:** Location
* **Value:** Boise
* **Short Code:** %%Location%%

{% hint style="info" %}
Short Codes used in a report always begin and end with %% and have underscores rather than spaces.
{% endhint %}

<mark style="background-color:yellow;">Step 5:</mark> Click **Submit** when finished.

<div align="left"><figure><img src="/files/BUjfFLRKOMyGzAjEN7TC" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 6:</mark> Use the short code in any report narrative or findings rich-text field for the client.&#x20;

<div align="left"><figure><img src="/files/xY9H54FboBaPkFED5Gzt" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 7:</mark> From the **Narrative** tab of the report, click **Search & Replace** at the top right of the page.

<div align="left"><figure><img src="/files/JKfz9SzgmkbwjFJCNn9E" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 8:</mark> A modal appears. Click **Replace Short Codes** to replace all short codes in the report with their corresponding text data.

<div align="left"><figure><img src="/files/M5etV9bZtv7kxLLhOL7D" alt="" width="437"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 9:</mark> Click **Confirm**.

<div align="left"><figure><img src="/files/6Mg888XSIz4mnUqHn44R" alt="" width="439"><figcaption></figcaption></figure></div>

After a few minutes, a confirmation message will appear.

<div align="left"><img src="/files/wEhzcx14r8X5x3mirECm" alt=""></div>

<mark style="background-color:yellow;">Step 10:</mark> Validate that the change(s) occurred as desired.&#x20;

If unsuccessful, ask an admin to verify the short code was set up correctly in the **Admin Dashboard**.


# Schedule

In the **Schedule** module, users can request and view engagements while others can create, approve and allocate resources to work on reports.

Users access the module by clicking **Schedule** in the application's main menu.

<div align="left"><figure><img src="/files/SkXzE3KmLczwKnAY7DTA" alt=""><figcaption></figcaption></figure></div>

## Overview

The Schedule module streamlines scheduling, resource management, and team visibility to enhance pentesting and report efficiency.

For Managed Security Service Providers (MSSPs), the scheduler oversees ongoing projects and facilitates efficient handling of incoming requests. On the client side, the portal experience consolidates all relevant information and provides intuitive tools for requesting new engagements within PlexTrac instead of email. Users can easily document and communicate engagement details to the team, while resource managers receive a holistic view to optimize scheduling.&#x20;

Any report managed by an engagement will display this information on the **Details** tab of a report, with a link directly to the engagement.

<div align="left"><figure><img src="/files/tuG8UHqzbWHzbRqXuIG9" alt=""><figcaption></figcaption></figure></div>


# Schedule Components

Users can view and access engagements from the **Schedule** home page for clients they can access. The view defaults to a calendar. Additional tabs include a list of all engagements and resource availability (depending on permissions).

## Calendar Tab <a href="#details-tab" id="details-tab"></a>

This tab lists all client engagements a user can access, depending on the filtered view chosen (All, Pending, Schedule, In progress, In review, and Complete). The engagements are color-coded to identify their status quickly.

<div align="left"><figure><img src="/files/Gns4rTrkAbsafbl9f2va" alt="" width="563"><figcaption></figcaption></figure></div>

## List Tab <a href="#findings-tab" id="findings-tab"></a>

This tab displays a list view of all client engagements a user can access, depending on the filtered view chosen (All, Pending, Schedule, In progress, In review, and Complete). Engagements can be viewed or edited from this tab by clicking the task under the "Actions" column of the engagement.

<div align="left"><figure><img src="/files/VW35bPG1MWKrbQYQstlW" alt="" width="563"><figcaption></figcaption></figure></div>

## Availability Tab <a href="#bulk-actions" id="bulk-actions"></a>

This tab displays a list view of all users in the tenancy who have permission to view and edit reports. Visible engagements can be filtered by clicking a status value above (i.e., "Pending").

<div align="left"><figure><img src="/files/jde3KGeUlwZ7n7ZNhEYc" alt="" width="563"><figcaption></figcaption></figure></div>

## User Permissions

What permissions have been assigned to the user dictate the user experience (what tabs can be viewed and what tasks can be completed) in the Schedule module. In addition, users will only see engagements associated with clients they can access.

This module's permissions list can be viewed and customized for enabled roles on the Role-Based Access page of the **Admin Dashboard** under "Engagement Scheduler Permissions."

<div align="left"><figure><img src="/files/4jFkyExxwcnCtz1WDmbw" alt="" width="563"><figcaption></figcaption></figure></div>


# Creating an Engagement

Users with permission to approve an engagement will have a "New engagement" button available in the Schedule module.

<mark style="background-color:yellow;">Step 1:</mark> Click **New engagement** from the **Calendar** tab of the **Schedule** module.

<div align="left"><figure><img src="/files/eWT33P0isyBYbSkHNKIc" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Enter information about the engagement. Required fields are identified with a red asterisk. Click **Continue**.

<div align="left"><figure><img src="/files/0hnL7vocACgMa1ThaMAv" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Add any relevant files for context. Click **Continue**.

<div align="left"><figure><img src="/files/otjUhpwooflUvDW617tp" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4:</mark> Enter report details. Click **Continue**.

<div align="left"><figure><img src="/files/pjDmsRDHow8Gi16iPdXF" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 5:</mark> Select the dates to begin and end work on the engagement by inserting the cursor into the "Engagement dates" box and clicking the desired dates.&#x20;

<div align="left"><figure><img src="/files/kcRo4whFYDdpAxqwfaAt" alt="" width="513"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 6:</mark> Assign resources to work on the engagement by clicking the checkbox next to the desired resource under the "Operators" column. After selecting an operator, the engagement will appear next to that resource. Any existing resources that the operator is working on will also be displayed. Click **Save**.

{% hint style="info" %}
Report operators will receive an email with an attached .ics file. Most calendar applications, such as Microsoft Outlook, Google Calendar, and Apple Calendar, support ICS files.
{% endhint %}

<div align="left"><figure><img src="/files/EREjhe5lPMAE2rtbq3yb" alt=""><figcaption></figcaption></figure></div>

The engagement now appears on the **Calendar** and **List** tabs for viewing and modification.


# Requesting an Engagement

Users who do not have permission to approve an engagement can still request one.

<mark style="background-color:yellow;">Step 1:</mark> From the **Calendar** tab of the Schedule module, click **Request engagement**.

<div align="left"><figure><img src="/files/XHeG7MaNNVZ9gPRYsms7" alt="" width="563"><figcaption></figcaption></figure></div>

&#x20;<mark style="background-color:yellow;">Step 2:</mark> Enter the engagement details in the provided side drawer. Click **Continue**.

<div align="left"><figure><img src="/files/w8TUAhfiTTgAtL3CtCNu" alt="" width="548"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Add any relevant files for context. Click **Submit**.

<div align="left"><figure><img src="/files/9L4Vuw5uUmr638sfOMjh" alt="" width="549"><figcaption></figcaption></figure></div>

A dialog box will appear explaining the next steps. Click **Ok**.

<div align="left"><figure><img src="/files/9BrBWeKcK2feZf8PWitK" alt="" width="512"><figcaption></figcaption></figure></div>

The engagement is now listed as pending on the **Calendar** and **List** tabs.&#x20;


# Managing Engagements

Existing engagements are managed from the **List** tab of the **Schedule** module.&#x20;

<div align="left"><figure><img src="/files/rhDUs0HHJasWB3QUBjel" alt="" width="563"><figcaption></figcaption></figure></div>

Multiple tasks can be performed on existing engagements depending on the user's permissions. If a user has view access but nothing else, a message will appear in the engagement-side drawer when accessed.

<div align="left"><figure><img src="/files/NNydgQC0lXza8oqS40Al" alt="" width="563"><figcaption></figcaption></figure></div>

## Viewing an Engagement

Users with the appropriate permissions can view engagements.

<mark style="background-color:yellow;">Step 1:</mark> From the **List** tab of the Schedule module, click the row or **View** under the "Actions" column of the desired engagement.

<div align="left"><figure><img src="/files/5P29MexGTn8YoeqoFRBT" alt="" width="563"><figcaption></figcaption></figure></div>

On the **Files** tab, a side drawer will appear describing the engagement details and any provided support files. For easy access, a link directly to the report is provided.

<div align="left"><figure><img src="/files/TDZIqKVEydHoShd73ss7" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Click **X** at the top right of the drawer to exit.&#x20;

If permissions allow, the user can edit or cancel the engagement from this screen.

## Approving an Engagement

Users with the appropriate permissions can approve engagements.

<mark style="background-color:yellow;">Step 1:</mark>  From the **List** tab of the Schedule module, click the row or **View** under the "Actions" column of the desired engagement.

<div align="left"><figure><img src="/files/0TwdfHFGXGwRXleZi5XO" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> A side drawer describing the engagement details and any provided support files will appear. Click **Schedule & create report**.&#x20;

<div align="left"><figure><img src="/files/GehQ94yBIM0fGp9qrr75" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Review the first three tabs of the submitted engagement for accuracy and add any additional information. When finished, click **Continue** to move on to the next tab.

<div align="left"><figure><img src="/files/pdk5t6ZkISzDpxPHx6eG" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4:</mark> On the fourth tab, **Select & assign operators** and assign resources to work on the engagement by clicking the checkbox next to the desired resource under the "Operators" column. After selecting an operator, the engagement will appear next to that resource. Any existing resources that the operator is working on will also be displayed. Click **Save**.

<div align="left"><figure><img src="/files/Q0vjA3Ib62TDcodSrAxm" alt=""><figcaption></figcaption></figure></div>

## Canceling an Engagement

Users with the appropriate permissions can cancel engagements.

{% hint style="danger" %}
This action can not be undone. If canceled, the engagement will need to be created again manually.&#x20;
{% endhint %}

<mark style="background-color:yellow;">Step 1:</mark>  From the **List** tab of the Schedule module, click the row or **View** under the "Actions" column of the desired engagement.

<div align="left"><figure><img src="/files/KYZx6hdbNw7p0QUZzTLS" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> A side drawer describing the engagement details and any provided support files will appear. Click **Cancel request**.&#x20;

<div align="left"><figure><img src="/files/n6nj0vQz3a6gh7ffnC0p" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> A modal will appear, asking for confirmation. Click **Cancel Request**.&#x20;

<div align="left"><figure><img src="/files/DBCkvF3mWb2RRbxOojwO" alt="" width="393"><figcaption></figcaption></figure></div>

## Editing an Engagement

Users with the appropriate permissions can edit engagements.

<mark style="background-color:yellow;">Step 1:</mark>  From the **List** tab of the Schedule module, click the row or **View** under the "Actions" column of the desired engagement.

<div align="left"><figure><img src="/files/NzOWraGQftIj79Pxcwbl" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> A side drawer describing the engagement details and any provided support files will appear. Click **Edit**.&#x20;

<div align="left"><figure><img src="/files/6eCgxaO84vQCZ4gcSHvA" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Edit the engagement as desired by changing content until the end and clicking **Save**.

{% hint style="info" %}
See the [Creating an Engagement](/plextrac-documentation/product-documentation/schedule/creating-an-engagement) page for more details on the various parts of an engagement.&#x20;
{% endhint %}

## Downloading Support Files

<mark style="background-color:yellow;">Step 1:</mark>  From the **List** tab of the Schedule module, click the row or **View** under the "Actions" column of the desired engagement.

<div align="left"><figure><img src="/files/4VLq2yGFYuBCZ0nsoWg4" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> A side drawer describing the engagement details and any provided support files will appear. Click the **Files** tab.&#x20;

<div align="left"><figure><img src="/files/M3h8P6Ro4HX8tjwk24YO" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Click the download icon of the file to access it.

<div align="left"><figure><img src="/files/gH4rw9bxKwNSprA5pAMd" alt="" width="563"><figcaption></figcaption></figure></div>


# Engagement Status

The engagement status reflects the lifecycle stage and comprises six values labeled with color coding throughout the module.&#x20;

<div align="left"><figure><img src="/files/ZfZw5fruRPX0g7FwNpz7" alt=""><figcaption></figcaption></figure></div>

## Status Mappings

Below are the different status states for a report and engagement, the relationship mapping, and any additional notes. Some of the engagement status values are tied to the status of the associated report.

<table><thead><tr><th width="190">Report Status</th><th width="258">Resulting Engagement Status</th><th>Notes</th></tr></thead><tbody><tr><td><em>(not applicable)</em></td><td>Pending</td><td>This status indicates the engagement has been requested but not approved.</td></tr><tr><td>Draft</td><td>Scheduled</td><td>This status indicates that the engagement has been approved and is slated to begin later.</td></tr><tr><td>Draft</td><td>In Progress</td><td>This status reveals that an approved engagement start date has been reached. <br><br>The status will move automatically to <code>In Progress</code> on the start date based on queries that run every hour.</td></tr><tr><td>Ready for Review</td><td>In Review</td><td>This status reveals that the report associated with the engagement is in one of the three view stages.</td></tr><tr><td>In Review</td><td>In Review</td><td>This status reveals that the report associated with the engagement is in one of the three view stages.</td></tr><tr><td>Approved</td><td>In Review</td><td>This status reveals that the report associated with the engagement is in one of the three view stages.</td></tr><tr><td>Published</td><td>Complete</td><td>This status reveals that the report associated with the engagement has been published.</td></tr><tr><td><em>(not applicable)</em></td><td>Canceled</td><td>This status indicates the engagement was terminated.</td></tr></tbody></table>


# Assessments

The **Assessments** module offers security consultancies and pentesters a streamlined approach to developing and managing framework-based governance risk and compliance assessments and scoping questionnaires. This functionality promotes consistency across assessments and reduces the time and effort required for their creation and management. An additional benefit of managing assessment questionnaires in PlexTrac is the ability to utilize PlexTrac's **Reports** and **Analytics** modules to track and report on the status of the assessment findings.

Users access by clicking **Assessments** in the application's main menu.

<div align="left"><figure><img src="/files/g6PO5AIlLEvGpfTTo5OU" alt=""><figcaption></figcaption></figure></div>

## Overview

Assessments are crucial for identifying, evaluating, and prioritizing security weaknesses in systems, networks, or applications. They aim to uncover vulnerabilities that malicious actors could exploit. Organizations can strengthen their security defenses and reduce the likelihood of successful attacks and data breaches by systematically reviewing and analyzing areas prone to risks, such as software bugs, misconfigurations, and other security weaknesses.

Various paradigms concentrate on evaluating security in vulnerability assessments. Network vulnerability assessments focus on scrutinizing network infrastructure, devices, and protocols to identify potential weak points that attackers could exploit. Web application vulnerability assessments specialize in detecting and remedying security flaws specific to web-based applications. Host-based vulnerability assessments concentrate on individual systems or hosts, including servers and workstations, to identify potential vulnerabilities and implement necessary safeguards.

Some of the most commonly used assessment frameworks in PlexTrac include CMMC (Cybersecurity Maturity Model Certification), NIST (National Institute of Standards and Technology), CIS (Center for Internet Security), ISO (International Organization for Standardization), FFIEC (Federal Financial Institutions Examination Council), and NYDFS (New York Department of Financial Services).

Assessment questionnaires are valuable for gathering relevant information and evaluating security practices. They serve many purposes, such as identifying vendor risk management, conducting internal and external audits, or obtaining SOC2 certification. By utilizing well-crafted questionnaires, organizations can systematically gather data regarding their security practices, policies, and procedures, which are then used to assess their effectiveness and compliance with established standards. These questionnaires facilitate a structured approach to evaluating security measures, streamlining the process and ensuring consistent evaluation across different projects and organizations.

The **Assessments** module has two tabs:

* **In Progress/Completed**: This option shows all assessments the user can view, including completed and in-progress assessments. Client and status can filter assessments.
* **Manage Questionnaires**: This displays the list of questionnaires available for assessment purposes in the tenancy. It also allows users to create and manage questionnaires and import questions from a JSON file.

<div align="left"><img src="/files/fxWD4SiIJBTVsgUI9QhR" alt=""></div>


# Assessment Components

PlexTrac's assessment module offers a user-friendly interface that enables effective assessment management, progress tracking, data collection, and collaboration. It ultimately facilitates the submission and presentation of comprehensive assessment findings.

<div align="left"><figure><img src="/files/7hepYRfOJU2XkrGkE4wO" alt="" width="563"><figcaption></figcaption></figure></div>

1. **Questionnaire progress bar**: Visually displays the progress made on the assessment and provides a percentage representation. Users can track their progress as they complete questions, with the bar gradually filling up as the questionnaire is completed.\
   ![](/files/NAeKIoHAbp7y1F9nWfgd)
2. **Question navigator box:** This box allows searching for the title of any question within the assessment. The key icon explains the circle expressions appearing for a question.\
   ![](/files/ROHZLCvHbrbxrI4XRVPR)
3. **Filter by status box:** Further filters the results list by question status. \
   ![](/files/zW4U5b4Q52SbYnq6IBWB)
4. **Results count:** This displays the number of questions in the assessment and dynamically updates based on filter and search queries.<br>

   <div align="left"><figure><img src="/files/NLcwUJDDKmP9WQGYSDig" alt=""><figcaption></figcaption></figure></div>
5. **Questions column:** Lists all questions that exist in an assessment. The view will change dynamically based on filter and search queries. Select a question from this list to view or complete. \
   ![](/files/WX47GYoSEEDtcU0f92FO)
6. **Questions column navigation**: Provides access to questions that appear on different pages, when applicable.\
   ![](/files/hGgtJRV1nRMVxMV6kSiD)
7. **Question details box**: Presents the question selected for viewing and completion. \
   ![](/files/tiPm3W2LOcCD5jxyotdl)
8. **Reviewers button:** Used to assign assessment reviewers (this option disappears for completed assessments).
9. **Submit assessment button:** Used to submit the assessment and move it to "Completed" status.


# Managing Questionnaires

The **Questionnaire templates** tab is a directory of assessment questionnaires available for a tenant. This tab provides a centralized location where users can perform various actions, such as creating new questionnaires, modifying existing ones, importing questionnaires from external sources, or deleting no longer-needed questionnaires.

The primary objectives of assessment questions are twofold. First, they aim to bolster the effectiveness and thoroughness of the assessment process by providing additional context and relevant information. By including well-crafted questions, the assessment becomes more comprehensive and capable of capturing a broader range of data.&#x20;

Second, the information collected through these assessment questions is crucial in generating meaningful findings when the assessment is completed and submitted as a report. These findings, derived from the accumulated data, serve as valuable insights and recommendations.

Furthermore, the Questionnaire templates tab also provides the functionality to initiate client assessments. This feature streamlines the assessment workflow by seamlessly integrating the questionnaire creation and initiation steps within the same interface.

## Creating a Questionnaire

<mark style="background-color:yellow;">Step 1:</mark> Click **New Questionnaire** from the **Questionnaire templates** tab of the **Assessments** module.

<div align="left"><figure><img src="/files/Mi8WXNfpNuJerX9fkOyE" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Enter a unique title and select the reference framework from the pulldown menu.

The reference framework value tags assessments and questions for future categorization and management.

<div align="left"><figure><img src="/files/XCBCgH9BpyOONmdpuIzc" alt="" width="397"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Click **Create Questionnaire**.

<div align="left"><figure><img src="/files/FIOvonIbitInUmzVck2W" alt="" width="397"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4:</mark> Edit this section as needed.&#x20;

<div align="left"><figure><img src="/files/FtawlpK3TvNns9Ub45cz" alt="" width="563"><figcaption></figcaption></figure></div>

* **Questionnaire Title** (required): This value entered in Step 3 can be edited here. This value will appear in the expanded section of the questionnaire (reference number one in the question example below).
* **Reference Framework:** This value was selected in Step 3 and cannot be edited. The reference framework value tags assessments and questions for future categorization and management.
* **Require Completion of All Questions:** If all questions must be answered before completing the assessment, check the box.

<mark style="background-color:yellow;">Step 5:</mark> Click **Save Basic Info**.

<div align="left"><figure><img src="/files/AjpQUDNid56jjhhajT3e" alt=""><figcaption></figcaption></figure></div>

### Create a New Question Section

<div align="left"><figure><img src="/files/JAAXpdGbhmyGVE2y0b3I" alt="" width="563"><figcaption></figcaption></figure></div>

* **Title** (required): Question title and value that will appear in the expanded section of the questionnaire *(see number 1 in the example below)*.
* **Description** (required): Description of the question that will appear as additional context for the user when answering the question *(see number 2 in the example below)*.
* **Answer Types** (required): Header value for multiple-choice questions *(see number 3 in the example below)*. \
  \
  Additional multiple-choice questions can be added by clicking **Add Answer Type**, which is helpful for assessments that score off multiple categories, such as Process and Practice maturity in CMMC.\
  \
  Check the box under "Require?" to make answering the question mandatory when completing the assessment.\
  \
  The list of values available for each multiple-choice question can be previewed by hovering over the informational icon to the right of the **"**&#x41;nswer Types" label (but only [admins can edit answer type labels and answer type values](/plextrac-documentation/product-documentation-1/account-management/account-admin/tenant-settings/general-settings#answer-types)).
* **Add Input Field**: An additional label can be provided and made mandatory if necessary *(see number 4 in the example below)*. The label will be presented to the user with a box for data entry. Enter as many Input Fields as required.
* **Add Custom Field**: Provides additional RTF fields with a label, if needed. Repeat as often as needed.

<div align="left"><img src="/files/LygHzMkcZGEJnGup9riq" alt=""></div>

#### Custom Button Fields

<div align="left"><figure><img src="/files/aq7C4bYag0RRUn6YBwrL" alt="" width="563"><figcaption></figcaption></figure></div>

* **Default Severity:** Pulldown menu list of values to define the default severity of the question. If a question is based on a Framework Control, it may have a predefined severity. This will be the severity of the report finding that this question will become upon submission.
* **Default Score:** Optional method for providing a default score.
* **Default Score Calculation:** If required, enter as a plain text string.
* **Tags:** Additional information to improve search and reporting.
* **Recommendations:** Recommendations relevant to the question, such as a remediation technique or policy suggestion.
* **References:** References to questions to assist with implementing or verifying the assertion, such as website links.

#### Writeups DB Button

Information from a writeup can be linked to a question. This metadata and content from the writeup will not appear in the assessment. Still, after the assessment is submitted and the question becomes a finding, the writeup information is included on the finding detail page.

<div align="left"><figure><img src="/files/bOnzjgV0BxuyKnbBFJQV" alt=""><figcaption></figcaption></figure></div>

* **Writeup:** Pulldown menu list of available writeups to link to the question.
* **Tags:** Additional information to improve search and reporting. This is the same field found under the "Custom" button.

{% hint style="info" %}
Not every field edited for a question will be displayed during the assessment. Still, it will be passed to a finding in the report generated upon submission, as each question in the assessment will become a finding.\
\
The screenshot below illustrates this: Every field greyed out and below the yellow line will not appear in the assessment but will be passed on to the finding details page after an assessment is submitted. \
\
![](/files/luxE0oUiGgjHSW8j6kQs)
{% endhint %}

<mark style="background-color:yellow;">Step 6:</mark> Click **Create**.

<div align="left"><figure><img src="/files/TVcoYxB1gN25oiYjqeE5" alt=""><figcaption></figcaption></figure></div>

The created question now appears in the "All Questions" column on the left.

<div align="left"><figure><img src="/files/LqnLW4FjZa7vxm5oB9vF" alt="" width="563"><figcaption></figcaption></figure></div>

This section contains a record of all questions in an assessment and provides the sequence in which they will appear.&#x20;

<mark style="background-color:yellow;">Step 7:</mark> Create more questions to complete the assessment. This can be done in two ways:

1. Clicking **Add Question** brings up a new blank list of fields.\
   ![](/files/r5jmCEoxO9vOPTSy6eKy)<br>
2. Clicking the copy icon of the question to clone.\
   ![](/files/8Wyv9ybKd3GqiwfxbEEP)

<mark style="background-color:yellow;">Step 8:</mark> Click **Create** after completing the second question. Create as many questions as needed to complete the assessment.

<div align="left"><figure><img src="/files/IEYadgRBm36hVJbikExh" alt=""><figcaption></figcaption></figure></div>

After multiple questions exist, the ability to sequence each question is provided should the creation of steps be outside the desired final sequence.&#x20;

Questions can be moved by clicking the "All Questions" question box and dragging it to the desired arrangement on the list. The numbering will dynamically change so that they are ordered as shown on the page (i.e., the question on top is always Question #1).

<div align="left"><figure><img src="/files/1DAPT9c4TcEqLVhYKkT7" alt=""><figcaption></figcaption></figure></div>

## Importing a Questionnaire

PlexTrac allows imported questionnaires in JSON file format.

<mark style="background-color:yellow;">Step 1:</mark> From the **Assessments** module, click the **Questionnaire templates** tab.

<div align="left"><figure><img src="/files/x1nPpT9Wxdj6fxGW76Db" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Click **Import**.

<div align="left"><figure><img src="/files/RMXxU7fzZTk2BscdeZFf" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Drag the JSON file to the modal or click to browse the file on the computer. Repeat if necessary. When finished, click **Upload**.

{% hint style="warning" %}
Importing a questionnaire removes all linked writeups.
{% endhint %}

<div align="left"><figure><img src="/files/5yGolYeoLEYDn9c889Kh" alt="" width="426"><figcaption></figcaption></figure></div>

If the wrong JSON file is used, an error message will appear. If the import is successful, the new file will appear in the list of questionnaires.

## Exporting a Questionnaire

A questionnaire can be exported as a JSON file for backup or imported to another instance. Questionnaires can be exported during editing,  directly from the Manage Questionnaires page, or when viewing a questionnaire.&#x20;

<mark style="background-color:yellow;">Step 1:</mark> From the **Assessments** module, click the **Questionnaire templates** tab.

<div align="left"><figure><img src="/files/d5QZoGuvCK4mX8d4g2p1" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Click the three dots under the "Actions" menu of the questionnaire and then click **Export**.

<div align="left"><figure><img src="/files/UtphS6zcfKbRDMGnRQ62" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Click **Export**.

The questionnaire is downloaded locally as a JSON file.

## Viewing a Questionnaire&#x20;

Clicking the row of the questionnaire on the **Manage Questionnaire** tab displays all question titles, descriptions, and tags on one page for easy viewing. The questions are listed in sequence.

<div align="left"><figure><img src="/files/HvqAsGY3ZsNtXNxVuQEm" alt="" width="563"><figcaption></figcaption></figure></div>


# Starting an Assessment

Users have two options for beginning an assessment. First, they can navigate to the **Questionnaire templates** tab. Second, users can start a new assessment from the **In progress/completed** tab.

{% hint style="info" %}
Assessments can be sent by copying the URL. If the recipients have an account in the PlexTrac instance, they can access the question and provide the necessary answers. This feature enhances collaboration and ensures that assessments progress smoothly, even with remote participants.
{% endhint %}

## Option A: From the Assessments Home Page

\ <mark style="background-color:yellow;">Step 1:</mark> Click the **Start New Assessment** tab from the **Assessments** default home page.

<div align="left"><figure><img src="/files/qAGuLNapcp6LZDi8AtAj" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Select the client the assessment applies to from the pulldown menu, then select the questionnaire. Click **Next**.&#x20;

<div align="left"><figure><img src="/files/VmvYxHGQ2mGcue8rZeeQ" alt="" width="400"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> A new page appears, presenting the assessment for modification.

<div align="left"><figure><img src="/files/oULWeTHNvGB95JS51Xqy" alt="" width="563"><figcaption></figcaption></figure></div>

## Option B: From a Questionnaire

<mark style="background-color:yellow;">Step 1:</mark> Click the **Questionnaire templates** tab from the **Assessments** default home page.

<div align="left"><figure><img src="/files/d0R6L0jA0OKgzblaGUJa" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Click **Begin Assessment** under the "Actions" column for the desired questionnaire.&#x20;

<figure><img src="/files/UlzOhQjzxauxglNPG8po" alt=""><figcaption></figcaption></figure>

<mark style="background-color:yellow;">Step 3:</mark> Select the associated *c*lient/project value from the pulldown menu and click **Begin Assessment**.

<div align="left"><figure><img src="/files/FD0rAQYIthRavt47uQ04" alt="" width="403"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4:</mark> A new page appears, presenting the assessment for modification.

## Next Steps

If no action is taken after an assessment is created or is not finished, the assessment will receive an "In Progress" status and be accessible from the **In progress/completed** tab.

<div align="left"><figure><img src="/files/5Dj9vHV3a4PNMQyLaf7R" alt="" width="563"><figcaption></figcaption></figure></div>

[An assessment can be completed](/plextrac-documentation/product-documentation/assessments/take-assessment) by clicking **Edit** under the "Actions" column.


# Taking an Assessment

Assessments can be started immediately after creation or worked on later by opening one to complete from the **In progress/completed** tab. If no action is taken after an assessment is created or the assessment is not finished, the assessment will have an "In Progress" status.

{% hint style="info" %}
To save progress on an assessment, click the **Save** button within the question box as questions are answered.\
![](/files/IQQrfjlKT4JEgjZznyJn)
{% endhint %}

To open and complete an "In Progress" assessment, go to the **In Progress/Completed** tab, select the desired assessment, and click **Edit**.

## Monitoring Progress

The assessment module provides progress tracking for questionnaires. A visual bar indicates the questionnaire's completion status, gradually filling up as more questions are answered until it reaches 100%.&#x20;

<div align="left"><figure><img src="/files/U98EU6ZmW8LrocNkerhL" alt=""><figcaption></figcaption></figure></div>

Users can provide answers, observations, notes, and attachments as questions are completed, such as policy documents, screenshots, code samples, and videos. Attachments are facilitated through a modal where files can be dragged, dropped, pasted, or browsed from the computer.&#x20;

<div align="left"><figure><img src="/files/jqbV6ENG4GLO6sPhvpQp" alt="" width="525"><figcaption></figcaption></figure></div>

Questions can be marked as complete, and users can continue to another question by clicking the question in the left column, entering the question number in the provided box, clicking the navigation arrow to reach the previous or next question in sequence, or using search/filtering to find a specific question.&#x20;

<div align="left"><figure><img src="/files/lZXIN66bgmzEBxbqqAR5" alt="" width="563"><figcaption></figcaption></figure></div>

The progress bar will update as data is entered, questions are completed, and the user moves to the next question. Completed questions will have a checkmark in the circle next to the question.

<div align="left"><figure><img src="/files/WAF3ljsnEKcUic6D4VZS" alt="" width="273"><figcaption></figcaption></figure></div>

Questions that are optional for the assessment will have a circle with a dotted outline next to the question's title, while questions that are required will have a circle with a solid outline. Questions touched but not marked as completed are identified with a shaded purple within the circle. Questions that have not been touched retain a white background until modified.

<div align="left"><figure><img src="/files/RQ5Gyvut19LWhXTiObAH" alt="" width="259"><figcaption></figcaption></figure></div>

When an assessment has all questions completed, all questions will have a checkmark, and the questionnaire progress bar will be full and display a green checkmark.

<div align="left"><figure><img src="/files/PHNQE1xkhSB7fdNOWBIB" alt="" width="270"><figcaption></figcaption></figure></div>

## Answering a Question

Questions are answered by selecting the question title in the Questions column, which inserts the question in the main window. The edited question is highlighted with a shaded background in the left column.&#x20;

A question defaults to the status of "Not Started." When a question receives input in any available field, it updates to "In Progress."

<div align="left"><figure><img src="/files/j1o1utSrlK3IOmO4Q5jE" alt="" width="563"><figcaption></figcaption></figure></div>

After a question has been answered, click the circle next to "Mark question complete," which will update its status to "Completed" and impact the questionnaire progress bar.

<div align="left"><figure><img src="/files/Utktf4hmgNxgy1B2m96o" alt="" width="563"><figcaption></figcaption></figure></div>

## Adding Attachments

Users can gather evidence directly and securely on the platform, eliminating the need to email sensitive documents while completing assessments.

<mark style="background-color:yellow;">Step 1:</mark> Click **Add attachment(s)**.

<div align="left"><figure><img src="/files/fGPIJkHARtLHeRczr7Ew" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Drag a file onto the modal or browse it from a local computer.

<div align="left"><figure><img src="/files/D8Pq9oT5LLbQatxD1GaP" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Add any additional notes as needed. Repeat the process if more than one file is loaded. Click **Save.**&#x20;

<div align="left"><figure><img src="/files/HwAL1pTvRz3cOOizcvZj" alt="" width="563"><figcaption></figcaption></figure></div>

The attachment is listed on the question after the "Notes" box. Hover over the attachment filename for icons to download or delete the file.

<div align="left"><figure><img src="/files/xqvGyPrgccH8biPCPEPd" alt="" width="563"><figcaption></figcaption></figure></div>


# Reviewing an Assessment

After finishing an assessment, users can easily choose reviewers from a dropdown menu. This feature simplifies the procedure of sharing findings and removes the necessity of sending confidential documents through email.

The assessment is changed to a draft format with an "In Review" status when a reviewer is added. This prevents premature submission and ensures that the assessment cannot be completed or submitted until the review is complete.

The number of current reviewers and remaining approvals needed for an assessment are listed on the **In progress/completed** tab.

<div align="left"><figure><img src="/files/kU21ipIuGjm7a57RdjXm" alt="" width="563"><figcaption></figcaption></figure></div>

After the reviewers finish evaluating the assessment and find it suitable, they mark it as approved. If all the reviewers approve the assessment but it is not yet submitted, the assessment will be labeled "Approved," and the overall status will be "In Progress."

In the case of a single reviewer, the user can either submit the assessment or continue working on it. However, if there are other pending reviews, the assessment will be marked as "In Review" and cannot be approved until all reviews have been completed.

{% hint style="info" %}
If no reviewers are assigned, an [assessment can be submitted](/plextrac-documentation/product-documentation/assessments/submitting-an-assessment) anytime.&#x20;
{% endhint %}

## Adding Reviewers

<mark style="background-color:yellow;">Step 1:</mark> From the **Assessments** module home page, click the row of the assessment to work on or **Edit** from the "Actions" menu.&#x20;

<div align="left"><figure><img src="/files/IxgNiltfQ7bWn4ELMT54" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2: C</mark>lick **Add Reviewers** at the top right of the page.&#x20;

<div align="left"><figure><img src="/files/TCzA6Kxj1B0fRHQuEF9N" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Select the reviewer(s) from the entries in the pulldown menu of users. Typing text into the box will narrow the list. Repeat as needed. No limit exists on how many reviewers can be added. When finished, click **Save**.

<div align="left"><figure><img src="/files/TdHTZScELIwLuuFTAJ6O" alt="" width="446"><figcaption></figcaption></figure></div>

The person assigned as a reviewer will receive an email notifying them of the task. The assessment is now in review mode.

<div align="left"><figure><img src="/files/3AL1QownSP6qNEnHmNod" alt="" width="563"><figcaption></figcaption></figure></div>

## Managing Reviewers

<mark style="background-color:yellow;">Step 1:</mark> From the **Assessments** module home page, click the row of the assessment to work on or **Edit** from the "Actions" menu.

<div align="left"><figure><img src="/files/D4ytfDmoJXmGPIDox6RO" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Click the **In review** button.

<div align="left"><figure><img src="/files/XKn7n5JeWWNFU9fe9ier" alt="" width="563"><figcaption></figcaption></figure></div>

A modal appears listing the reviewers and their approval status.

<div align="left"><figure><img src="/files/0ayWjW3cI7upUMyACNcM" alt="" width="435"><figcaption></figcaption></figure></div>

The two values provided are "Approved" and "Pending Approval."

Current reviewers can be removed by clicking the "X" next to their name, while new ones can be added by placing the cursor in the box and selecting a new reviewer. Click **Save** when finished.

{% hint style="info" %}
A removed reviewer will still appear on the dialog box list until **Save** is clicked.&#x20;
{% endhint %}

<div align="left"><figure><img src="/files/G2OfmaQ2RDtojmAbQY4T" alt="" width="440"><figcaption></figcaption></figure></div>

If the user has the necessary permissions, the "Approve" button will appear, provided the reviewer has not yet approved the assessment. If the reviewer has approved the assessment, an option to remove the approval will appear.

<div align="left"><figure><img src="/files/xVaEEywF8ufcomivIq5Q" alt="" width="435"><figcaption></figcaption></figure></div>

## Approving an Assessment

<mark style="background-color:yellow;">Step 1:</mark> From the **Assessments** module home page, click the row of the assessment to work on or **Edit** from the "Actions" menu.

<div align="left"><figure><img src="/files/D4ytfDmoJXmGPIDox6RO" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Click the **In review** button.

<div align="left"><figure><img src="/files/XKn7n5JeWWNFU9fe9ier" alt="" width="563"><figcaption></figcaption></figure></div>

A modal appears listing the reviewers and their approval status.

<div align="left"><figure><img src="/files/0ayWjW3cI7upUMyACNcM" alt="" width="435"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Click **Approve**.

<div align="left"><figure><img src="/files/5K7BRtKxv1u6mvMWZ9AH" alt="" width="437"><figcaption></figcaption></figure></div>

After a reviewer clicks **Approve**, the status changes within the modal to "Approved."

<div align="left"><figure><img src="/files/ii4pkUmLJJh60jBrlkAZ" alt="" width="440"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4:</mark> Click **Save**.

<div align="left"><figure><img src="/files/PhzyO02zxwCKzsy8RdrT" alt="" width="440"><figcaption></figcaption></figure></div>

The modal disappears. If all reviewers have approved, the status of the assessments changes on the button previously clicked in Step 3.

<div align="left"><figure><img src="/files/9wnj4XspgNQVPep1mMa7" alt="" width="563"><figcaption></figcaption></figure></div>

In addition, the status of the assessments changes on the **In progress/completed** tab.

<div align="left"><figure><img src="/files/44kzpL3bPu1sdF9A98oh" alt="" width="563"><figcaption></figcaption></figure></div>

## Revoking an Approval

A user can revoke the approval of an assessment that has not been submitted (i.e., a status of "In Progress") by opening the assessment, clicking the **Approved** button at the top right of the screen, and then clicking **Remove approval** from the modal.&#x20;

<div align="left"><figure><img src="/files/ngYf5tmJMOBekIMdds27" alt="" width="439"><figcaption></figcaption></figure></div>

This will return the assessment approval status to "In Review" and display the reviewer as "Pending Approval."&#x20;

<div align="left"><figure><img src="/files/U3pEj1L8OERAwmJxUZdV" alt="" width="439"><figcaption></figcaption></figure></div>


# Submitting an Assessment

Once an assessment is submitted in PlexTrac, the platform automatically generates a report and directs the user to the **Report** module readout view, and all questions are turned into findings. This published report contains all the findings from the assessment, making it readily accessible to stakeholders and analyst users. This feature enables quick dissemination of information to relevant parties.

## Submitting an Assessment

<mark style="background-color:yellow;">Step 1:</mark> From the **Assessments** module home page, click the row of the assessment to work on or **Edit** from the "Actions" menu.&#x20;

<mark style="background-color:yellow;">Step 2:</mark> Click **Submit assessment**.&#x20;

{% hint style="danger" %}
This action cannot be undone. Once submitted, a report will be generated with recorded responses.
{% endhint %}

<figure><img src="/files/sb1KZMtu2dDXWee2HfLJ" alt="" width="563"><figcaption></figcaption></figure>

{% hint style="info" %}
If a submittal is attempted with questions not completed, a warning message will appear:\
\
![](/files/Sm17YIlEveOItuLgV3f5)
{% endhint %}

<mark style="background-color:yellow;">Step 3:</mark> If all questions have been completed, a message confirming action appears. Click **Submit assessment**.&#x20;

<div align="left"><figure><img src="/files/YIpsv0E9Z7AvdJJNllw4" alt="" width="331"><figcaption></figcaption></figure></div>

A report readout from the **Reports** tab of the **Clients** module will be presented, providing assessment details. The answered questions are now findings. Each finding includes the question, description, assigned score, checkbox status, and any accompanying notes and relevant documentation incorporated into the assessment.&#x20;

If required, users can edit the report before exporting it. This feature ensures that the final report accurately reflects any updates or changes made during the assessment process. Users can review and modify the report as necessary, guaranteeing its accuracy and completeness before sharing it with stakeholders.

The assessment is still listed within the **Assessment** module, now with a "Completed" status.

## Assessment Findings Status&#x20;

Once an assessment is submitted, all questions, including custom fields, are transformed into findings. PlexTrac then assigns a status to each finding, using business rules corresponding to the answer type and values of the question.

{% hint style="info" %}
More information on answer types and values can be found on the [Creating Questions page](/plextrac-documentation/product-documentation/assessments/questionnaires#creating-questions) and under [General Settings](/plextrac-documentation/product-documentation-1/account-management/account-admin/tenant-settings/general-settings#answer-types) of the **Admin Dashboard**.
{% endhint %}

### Findings Status Logic

Below are the guidelines used to determine the value given to a finding status. These rules are followed in sequence until the status is resolved and a value is determined.&#x20;

To ensure the accuracy of the rules listed in the table, the answer type value must match the value in the table, where applicable. For example, an answer type value of `Not Compliant` will result in a match and a findings status assigned, while a value of `Non Compliant` will not.

The same logic is applied to custom fields. If, for example, a custom field answer type is "Yes (Pass) / No (Fail)" and the value is "Yes," the finding status assigned is `Closed`. If the custom field answer type scenario and value are not found below, the finding status assigned is `In Process`.

{% hint style="info" %}
If multiple answer types exist for a question, only the first answer type assigns a status to a finding.
{% endhint %}

<table><thead><tr><th width="126">Sequence</th><th>Logic</th><th width="182">Answer type value </th><th>Assigned finding status</th></tr></thead><tbody><tr><td>1</td><td>Answer type value is Yes AND Answer type is "Yes (Pass) / No (Fail)"</td><td>Yes</td><td>Closed</td></tr><tr><td></td><td>Answer type value is Yes AND Answer type is NOT "Yes (Pass) / No (Fail)"</td><td>Yes</td><td>Open</td></tr><tr><td>2</td><td>Answer type value is No AND Answer type is "Yes (Pass) / No (Fail)"</td><td>No</td><td>Open</td></tr><tr><td></td><td>Answer type value is No AND Answer type is NOT "Yes (Pass) / No (Fail)"</td><td>No</td><td>Closed</td></tr><tr><td>3</td><td>Answer type is "CMMC Processes" or "CMMC Practices"</td><td>Any value</td><td>Open</td></tr><tr><td>4</td><td>Answer type value was left blank or not answered</td><td></td><td>Open</td></tr><tr><td>5</td><td>Answer type value is checked against a list of values that are mapped (if the answer type is Multiple Choice and more than one box was checked, the value of the topmost option is used)</td><td>No (Pass)</td><td>Closed</td></tr><tr><td></td><td></td><td>Not Started</td><td>Open</td></tr><tr><td></td><td></td><td>Strongly Disagree</td><td>Open</td></tr><tr><td></td><td></td><td>Initial </td><td>Open</td></tr><tr><td></td><td></td><td>Yes (Fail)</td><td>Open</td></tr><tr><td></td><td></td><td>Operational</td><td>Closed</td></tr><tr><td></td><td></td><td>Strongly Agree</td><td>Closed</td></tr><tr><td></td><td></td><td>Optimizing</td><td>Closed</td></tr><tr><td></td><td></td><td>Compliant</td><td>Closed</td></tr><tr><td></td><td></td><td>Not Compliant</td><td>Open</td></tr><tr><td></td><td></td><td>Required</td><td>Open</td></tr><tr><td></td><td></td><td>Extremely Effective</td><td>Closed</td></tr><tr><td></td><td></td><td>Not Effective</td><td>Open</td></tr><tr><td></td><td></td><td>In Place</td><td>Closed</td></tr><tr><td></td><td></td><td>Not In Place</td><td>Open</td></tr><tr><td></td><td></td><td>N/A</td><td>Closed</td></tr><tr><td></td><td></td><td>In Place w/CCW</td><td>Closed</td></tr><tr><td></td><td></td><td>Not Tested</td><td>Open</td></tr><tr><td>6</td><td>Finding still does not have an assigned status</td><td></td><td>In Process</td></tr></tbody></table>


# Reports

The **Reports** module makes generating security reports for penetration tests more efficient and effective. It enhances the value and quality of the reports by presenting the test findings clearly and concisely with relevant context and actionable recommendations. This helps ensure that all vulnerabilities, weaknesses, and potential risks are documented, allowing clients and stakeholders to understand their systems or applications' security posture.

Users access the module by clicking **Reports** in the application's main menu.

<div align="left"><figure><img src="/files/08o5cZ9xn8XkV7AS6Y94" alt="" width="319"><figcaption></figcaption></figure></div>

## Overview

The Reports module home page displays all reports that a user has permission to view. It provides a list of reports with fields the user selects (instructions on how to customize below), plus an Actions menu that allows quick access to the report readout page, report findings, and the option to delete the report.

Reports can also be [imported](/plextrac-documentation/product-documentation/reports/import-plextrac-report) or [created](/plextrac-documentation/product-documentation/reports/create-report) from this page.&#x20;

<div align="left"><figure><img src="/files/kqnc7BEjQx78QpsAkA99" alt="" width="563"><figcaption></figcaption></figure></div>

## Bulk Actions Menu

To access the bulk actions menu, click on any box to the left of a report's name or the box next to the column header to select all reports.

<div align="left"><figure><img src="/files/guhY8FUThTSY2pKKTHSb" alt="" width="552"><figcaption></figcaption></figure></div>

After clicking on a box, an Actions button will appear with options to update one or more reports with various tasks from the pulldown menu.

## Configuring Table View

The table view can be customized by clicking the column view icon to the right of the search bar.

<div align="left"><figure><img src="/files/PKCqlX6NrIu8ZhL6hyD0" alt="" width="563"><figcaption></figcaption></figure></div>

Once clicked, a modal appears that lists all fields. To remove a column, click **X** within the bar.

<figure><img src="/files/qcTORTkFrSyJzXHBSgY0" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Fields that are required do not have an **X** available.
{% endhint %}

When fields are removed, an "Add Column" pulldown menu is added at the bottom left of the modal to store the field. Removed fields can be added later by clicking **Add Column** and selecting the field to add. &#x20;

<div align="left"><figure><img src="/files/6jV9smHBUhFbVEw66Y0U" alt=""><figcaption></figcaption></figure></div>

This modal represents the sequence of fields provided in the table, meaning the bar on top will be the column on the table's far left.&#x20;

The order of columns can be adjusted within this modal by clicking the six dots on the left of the bar for a field and dragging the bar to the desired sequence.

<div align="left"><figure><img src="/files/uj9tatDsSCcMCvdX0Ey1" alt=""><figcaption></figcaption></figure></div>

Click **Save** when finished.&#x20;


# Report Components

Individual reports can be accessed from either the Clients or Reports module. Once a report is selected, users can manage and update it using several tabs: **Readout**, **Details**, **Narrative**, **Findings**, **Assets**, **Procedures,** **Artifacts**, and **Attack Path**.&#x20;

## Readout Tab

The **Readout** tab provides access to the Report Narrative, Report Readout column, Findings Overview summary box, and Findings Status box. The Report Readout column has a convenient scrolling feature, making it simple for users to move through the list of findings.

<div align="left"><figure><img src="/files/lkrC1nfcDIMuWJ8O7gDj" alt="" width="563"><figcaption></figcaption></figure></div>

Report narratives can be edited by clicking **Edit/Comment** or on the **Narrative** tab.

<div align="left"><figure><img src="/files/qwd3XeoRVBaP8Mb91d5Z" alt="" width="545"><figcaption></figcaption></figure></div>

To view a finding narrative, click the corresponding box in the "Report Readout" column. To edit the finding content, click **Edit/Comment**.

<div align="left"><figure><img src="/files/EekKqo9wIfxoUGYZxHkn" alt="" width="563"><figcaption></figcaption></figure></div>

Click **Report Narrative** to return to the default report readout view.

<div align="left"><figure><img src="/files/haZjUriqFx6WcsuaUkFm" alt="" width="563"><figcaption></figcaption></figure></div>

## Details Tab

The **Details** tab offers an interface to view and modify the information entered when the report was created. For more detailed guidance on each field and its significance, refer to the [Creating a Report](/plextrac-documentation/product-documentation/reports/create-report) page.

<div align="left"><figure><img src="/files/ZNNPk7yeCaJaTQbK81M3" alt="" width="563"><figcaption></figcaption></figure></div>

## Narrative Tab

The **Narrative** tab provides an interface for viewing and modifying existing rich-text fields (RTFs), adding new custom sections, or importing from NarrativesDB.&#x20;

The existing narrative sections can be expanded or collapsed using the arrow at the right of the box.

{% hint style="info" %}
Visit the [Collaborative Editing](/plextrac-documentation/product-documentation/reports/findings/collaborative-editing) page for more information about track changes and commenting functionality within the RTFs.
{% endhint %}

<div align="left"><figure><img src="/files/hLDjRdqXYcDqPStvEKUn" alt="" width="563"><figcaption></figcaption></figure></div>

## Findings Tab

The **Findings** tab lists all findings associated with a report. It allows users to view a finding and manage and configure it further.&#x20;

<div align="left"><figure><img src="/files/fTccXS1yRAdz3Gadb7S4" alt=""><figcaption></figcaption></figure></div>

Clicking a finding row launches the findings details side drawer, which provides a snapshot view of the finding and all associated content, assets, and tags.

<div align="left"><figure><img src="/files/gNeNbV3gSAQyrtmEy8tF" alt="" width="563"><figcaption></figcaption></figure></div>

### Bulk Actions

Bulk action options appear after one or more findings are selected by clicking the checkbox to the far left of the finding row or by clicking the box next to the column header.&#x20;

Click **Actions** to see a list of options, such as adding a tag or linking to a priority.

### Configuring Table View

The table view can be customized by clicking the column view icon to the right of the search bar.

<div align="left"><figure><img src="/files/l15SJkSSNqEE19wE8sJf" alt=""><figcaption></figcaption></figure></div>

Once clicked, a modal appears that lists all fields. To remove a column, click **X** within the bar.

{% hint style="info" %}
Fields that are required do not have an **X** available.
{% endhint %}

When fields are removed, an "Add Column" pulldown menu is added at the bottom left of the modal to store the field. Any removed fields can be added later by clicking **Add Column** and selecting the field to add. &#x20;

<div align="left"><figure><img src="/files/wWRk0hvGMwMTTbkXxNnN" alt=""><figcaption></figcaption></figure></div>

This modal represents the sequence of fields provided in the table, meaning the bar on top will be the column on the table's far left.&#x20;

The order of the columns can be adjusted in this modal by clicking the six dots on the left side of a field's bar and dragging it to the preferred sequence position.

Click **Save** when finished.

## Assets Tab

The **Assets** tab displays all assets in the report that are linked via a finding. Assets are not added to a report directly; they only exist within a report when they are part of a finding that has been added to the report.

Visit [Adding Assets](/plextrac-documentation/product-documentation/clients/adding-assets-to-a-client) for more information.

<div align="left"><figure><img src="/files/2rQfUd022QIXPFezhBBj" alt="" width="563"><figcaption></figcaption></figure></div>

### Bulk Actions

Bulk action options appear after selecting one or more assets by clicking the checkbox to the far left of the asset row or by clicking the box next to the column header.&#x20;

Click **Actions** to see the options available, such as adding a tag to an asset or linking to a priority.

### Configuring Table View

The table view can be customized by clicking the column view icon to the right of the search bar.

## Procedures Tab

This tab streamlines the creation and management of procedures within reports, offering greater flexibility and efficiency. Users can view and create procedures on the fly directly from a report and add existing procedures from any repository, including their runbooks database.&#x20;

A side drawer feature also enables quick procedure review, enhancing workflow efficiency.&#x20;

<div align="left"><figure><img src="/files/iOpxZPjiQXo9ccx86gw7" alt="" width="563"><figcaption></figcaption></figure></div>

The **Tactics coverage** tab allows users to review tactics coverage, providing a more holistic view of security posture.&#x20;

<div align="left"><figure><img src="/files/UVZgP1U9jcbk6f4ccNuB" alt="" width="563"><figcaption></figcaption></figure></div>

### Configuring Table View

The table view can be customized by clicking the column view icon to the right of the search bar.

## Artifacts Tab

The **Artifacts** tab provides a dedicated space to load and associate additional information with a report. This functionality allows for the inclusion of various artifacts, such as registry keys, files, time stamps, and event logs, which can provide context and support the findings and conclusions presented in the report.

<div align="left"><figure><img src="/files/rMZJvC8z2sSiVvSjVhFJ" alt="" width="563"><figcaption></figcaption></figure></div>

## Attack Path Tab

The **Attack Path** tab visually represents the tactics, techniques, and procedures (TTPs) employed in a simulated attack, as discussed in the report. This tab offers a flexible and interactive interface that allows users to manipulate and sequence the attack path as desired.

This visual representation helps stakeholders understand the attack methodology and visualize how an attacker could exploit system vulnerabilities.

<div align="left"><figure><img src="/files/UW2EKvtzoeCIXkFFBmwd" alt=""><figcaption></figcaption></figure></div>

More information about a finding can be accessed by clicking the eye icon within a box to pull up the Finding Details page as a side drawer.

<div align="left"><figure><img src="/files/mSdQiSrp4JpLwAU0yFtA" alt=""><figcaption></figcaption></figure></div>

## Report Logs

The report log documents when a report was last imported and what new findings were added.

<mark style="background-color:yellow;">Step 1</mark>: From the **Reports** module home page, click the row of the report to view or **Readout**.

<div align="left"><figure><img src="/files/JjeqI68tBL8LGVXJ0cpC" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2</mark>: From the **Findings** tab, click **Report Logs**.

<div align="left"><figure><img src="/files/oSfMPM6EZ1RtNNe3ADbE" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3</mark>: A dialog box asks to select the import date and time. Select the desired time recorded in Universal Time (UTC).

<div align="left"><figure><img src="/files/OPD5s9WbmSQhC8ab1jRM" alt="" width="390"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4</mark>: A  list of findings added is displayed.

<div align="left"><figure><img src="/files/UYcz0WIaacAWMo7Yx1sx" alt="" width="395"><figcaption></figcaption></figure></div>


# Creating a Report

Users can generate a report by accessing the **Clients** module or creating one within the **Reports** module. The process and experience are identical, except if a report is created from within the Clients module, there is no need to select a client. Assuming the user is currently in the Reports module, they can follow the instructions below.

<mark style="background-color:yellow;">Step 1:</mark> From the **Reports** home page, click **Create Report**.

<div align="left"><figure><img src="/files/XsqaFacaEcEMVwVpOxZZ" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Select the client from the pulldown menu. All clients for a tenancy will be available for selection.

<div align="left"><figure><img src="/files/rzHchKDoVsr5pKPQ9uhM" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> The modal then expands. Enter the desired data in the fields (required fields are marked with a red asterisk).&#x20;

<div align="left"><figure><img src="/files/2rwaAYyqPPt0vrKgP160" alt=""><figcaption></figcaption></figure></div>

1. **Report Name:** Appears throughout PlexTrac as the report title. It is a required field.
2. **Report Classification**: Defines the [security tier](/plextrac-documentation/product-documentation-1/account-management/account-admin/security-and-user-management/security/classification-tiers) classification for the report, which can then be used to restrict access.&#x20;
3. **Status:** Provides the status of the report. By default, the report will be in `Draft` mode. The user can select other options, such as `Ready for Review`, `In Review`, `Approved`, or `Published` from the pulldown menu.
4. **Report Template:** [Report templates](/plextrac-documentation/product-documentation-1/account-management/account-admin/customizations/templates/report-templates) are predefined layouts that define the structure and format of a report. They can include narrative sections, custom fields, and other elements. Select the desired template from the pulldown menu to associate a report to a template.
5. **Findings Layout:** [Findings layouts](#using-a-findings-layout) are predefined templates that provide a consistent structure for collecting data when creating a finding. Select the desired template from the pulldown menu to associate a layout with a report.
6. **Operators:** This field identifies users who work on the report. Any user with their name in it will see the report listed on their **Dashboard** under the "Your reports" tab. Enter users by placing the cursor in the field box, selecting a value, or typing a name. This field can be blank or contain multiple users. Once added, an operator can be removed by clicking the "X" to the right of the name.<br>

   <figure><img src="/files/BhtA6t43vXaeVGNfFd49" alt=""><figcaption></figcaption></figure>
7. **Start Date:** Identifies the start date of the report. Place the cursor in the field box to select a date from the calendar.&#x20;
8. **End Date:** Identifies the end date of the report. Place the cursor in the field box to select a date from the calendar. &#x20;
9. **Reviewers:** This field identifies users who review the report. Any user with their name in it will see the report listed on their dashboard under the "Your reports" tab. Enter users by placing the cursor in the field box, selecting a value, or typing a name. This field can be blank or contain multiple users. Once added, a reviewer can be removed by clicking the "x" at the end of their name.
10. **Tags:** Provides help when searching for the report elsewhere in the application. Click on the field to add tags and type in your desired value. You can also scroll through the list or type in characters to narrow down your options and make a selection. This field can be blank or contain multiple tags. Once added, a tag can be removed by clicking the "x" at the end of the value.
11. **Include Raw Evidence in Export:** This option ensures that all raw evidence in the report is included when exported. It is turned off by default but can be toggled on by clicking.
12. **Custom Fields:** Add any desired custom fields by clicking **Add** **Custom Field** or selecting existing custom fields from a template to import via the pulldown menu.

<mark style="background-color:yellow;">Step 3:</mark> Click **Submit**.

<div align="left"><figure><img src="/files/7h6p1mcJj8Lh8NwucZMx" alt=""><figcaption></figcaption></figure></div>

Upon submission, the system creates the report's initial framework, which is ready for further content addition and collaboration. Other tabs can now be accessed to make necessary changes, such as adding findings or assets.

<mark style="background-color:yellow;">Step 4:</mark> Click the **Narrative** tab and add a report narrative. An existing narrative can be reused by clicking **Add from NarrativesDB,** or a new one can be added by clicking **Custom Section**.

<div align="left"><figure><img src="/files/gH6byR59gSEqEtTKkeiT" alt="" width="563"><figcaption></figcaption></figure></div>

{% hint style="info" %}
Visit the [Adding from NarrativesDB](/plextrac-documentation/product-documentation/reports/adding-from-narrativesdb) page for more information.&#x20;
{% endhint %}

<mark style="background-color:yellow;">Step 5:</mark> Use the other tabs to build the report as needed. For more information on working with[ findings ](/plextrac-documentation/product-documentation/reports/findings)and [assets](/plextrac-documentation/product-documentation/clients/managing-assets), visit the different sections of this site or view the [report components page](/plextrac-documentation/product-documentation/reports/report-components).


# Adding from NarrativesDB

<mark style="background-color:yellow;">Step 1:</mark> From the **Reports** module, select a report and click the **Narrative** tab.&#x20;

<mark style="background-color:yellow;">Step 2:</mark> Click **Add from NarrativesDB**.

<div align="left"><figure><img src="/files/3aNlxekWhpMMmaSykXGD" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Search or use the provided pulldown filters to find the desired section(s) to add.&#x20;

{% hint style="info" %}
Only repositories and sections a user can view will appear in search results.
{% endhint %}

<div align="left"><figure><img src="/files/Ct6vbvaBHUwcCHRwvniO" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4:</mark> Click the box next to the section(s) to add, and the narrative will appear on the right under the "TO BE ADDED TO NARRATIVE" column.

<figure><img src="/files/eJXXgKHunKjjju0L7MC8" alt=""><figcaption></figcaption></figure>

To add all available sections (or start with all sections selected and then uncheck those not desired), click the box next to "Sections" in the table header below the search bar.

<div align="left"><figure><img src="/files/9OtMw4J2ekbPku1gZXHL" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 5:</mark> Click the **Add X Section** button at the bottom of the page. The new section(s) will now be available for editing in the **Narrative** tab.

<mark style="background-color:yellow;">Step 6:</mark> Click the three dots to display the option to add tags or delete the section.

{% hint style="info" %}
Sections deleted from the Narratives tab will not delete the section from **NarrativesDB**.&#x20;
{% endhint %}

<div align="left"><figure><img src="/files/8zq0l1SkRxPn76JWn4wx" alt=""><figcaption></figcaption></figure></div>


# Editing a Report

## Editing from the Readout Tab

<mark style="background-color:yellow;">Step 1:</mark> From the Reports module home page, click **Readout** under the "Actions" column of the report to edit.&#x20;

<div align="left"><figure><img src="/files/TxUGglZ93jYCAsEI5EVe" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> From the Readout tab, click **Edit/Comment**.

{% hint style="info" %}
If no report narrative was added when the report was created and no findings with narratives were added, editing from this tab will not be possible as the button will not exist. The user must first go to the **Narrative** tab and enter content or add findings.
{% endhint %}

<div align="left"><figure><img src="/files/YbXaOCXwDOiMJ91JnF6i" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Modify the content as needed. All changes are autosaved.

<div align="left"><figure><img src="/files/bmJ0PiK1v9tVQXm176qi" alt="" width="563"><figcaption></figcaption></figure></div>

{% hint style="info" %}
This page does not allow editing of headings, and some other functionality is limited. As such, editing from the **Narratives** tab is recommended.
{% endhint %}

## Editing from the Narrative Tab

<mark style="background-color:yellow;">Step 1:</mark> From the Reports module home page, click **Readout** under the "Actions" column of the report to edit.&#x20;

<div align="left"><figure><img src="/files/5tr0dco10UXlmm2jOGQL" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Click the **Narrative** tab.

<div align="left"><figure><img src="/files/n4Wvl7qd4WSZtKt8ahAF" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Edit the text and titles as desired. Additional functionality exists, such as adding from NarratviesDB, creating a custom section, or leaving comments.

{% hint style="info" %}
For more details on tracking changes and adding comments in the rich-text field, visit the [Collaborative Editing](/plextrac-documentation/product-documentation/reports/findings/collaborative-editing) page.
{% endhint %}

<div align="left"><figure><img src="/files/ieT4fkBsscqpA6vzJ2Ko" alt="" width="563"><figcaption></figcaption></figure></div>


# Using Short Codes in Reports

\
Short codes can significantly improve the efficiency of data representation. They can be created to represent specific data fields at the [client](/plextrac-documentation/product-documentation/clients/using-short-codes-from-the-client-level-in-plextrac) and report levels.&#x20;

With pre-defined codes, users can quickly insert data without manually entering lengthy information, saving time and effort during the report creation process. Moreover, standardized placeholders help maintain consistency in data presentation across different reports, ensuring a uniform format and structure that creates a professional and organized image.

Short codes provide flexibility and adaptability. They enable users to customize formats and update information without changing the underlying data. This ensures that reports are presented according to individual preferences and industry standards, minimizing the risk of errors and enhancing accuracy.

{% hint style="info" %}
[Short Codes](/plextrac-documentation/product-documentation-1/account-management/account-admin/tenant-settings/short-codes) are managed by admins in the **Admin Dashboard**.
{% endhint %}

## Adding Custom Short Codes

<mark style="background-color:yellow;">Step 1:</mark> From the Reports module home page, click **Readout** under the "Actions" column of the report to edit.&#x20;

<mark style="background-color:yellow;">Step 2:</mark> Click the **Details** tab.

<div align="left"><figure><img src="/files/lze21Bymz4S70ufA4iJl" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Click the **Add new** button at the bottom of the page under "Custom fields."

<div align="left"><figure><img src="/files/zs3nhSyLSW18OrHgfcLw" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> In the first box on the left, add a label value to correspond with the short code, and in the second box on the right, insert the text value that will replace the short code.

This value will replace the short code used in the report's narratives or a finding's text fields.

<div align="left"><figure><img src="/files/AyZrafrZ3BDfccd8yxGY" alt="" width="563"><figcaption></figcaption></figure></div>

Repeat the process to add another short code.

{% hint style="warning" %}
The short code value must exist and be set by an admin as a "Report Custom Field" for Source. If it does not, contact the admin to add it under "Tenant Settings>Short Codes."\
![](/files/WVeVoDA6QjacUxnUyh4t)
{% endhint %}

The **Custom Field** label links the short code to the value (text data) that is to replace it. For example:

* **Label:** Contact Email
* **Value (text data):** <janep@karbo.com>
* **Short Code:** %%Contact\_Email%%

{% hint style="info" %}
Short Codes in the Admin Dashboard always begin and end with %% and have underscores rather than spaces.
{% endhint %}

<mark style="background-color:yellow;">Step 4:</mark> Use the short code in any report narrative. Changes will be autosaved.

<div align="left"><figure><img src="/files/G41JQLZ79ptmxzvN870V" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 5:</mark> To activate the short codes, click **Search & Replace** at the top right of the page within the **Reports** module.

<div align="left"><figure><img src="/files/LDCNMdKhIG4a8InabSFh" alt="" width="335"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 6:</mark> The **Search & Replace** modal appears. Click **Replace Short Codes** to replace all short codes in the report with their corresponding text data.

<div align="left"><figure><img src="/files/GTq2T9KZqq9Oy0EIW5Fr" alt="" width="395"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 7:</mark> Click **Confirm**.

<div align="left"><figure><img src="/files/VFhi8jPFcf6XHUgso3KN" alt="" width="395"><figcaption></figcaption></figure></div>

A confirmation message will appear.

<div align="left"><img src="/files/wEhzcx14r8X5x3mirECm" alt="" width="341"></div>

<mark style="background-color:yellow;">Step 8:</mark> Validate that the change occurred as desired, assuming the short code exists in the tenant settings.&#x20;

<div align="left"><figure><img src="/files/08AxR7WVhStG5jQNGTiV" alt="" width="563"><figcaption></figcaption></figure></div>

If the fields did not process as expected, kindly request the administrator to confirm their setup in the **Admin Dashboard** and ensure that the appropriate short code was utilized. Then, proceed to repeat steps 6-8.


# Findings

A finding is a weakness in systems, processes, policies, or procedures that could be exploited. It arises from penetration testing, vulnerability assessments, and compliance audits. These findings reveal potential points of compromise, categorized by severity, and often come with recommended remediation actions.

Organizations can use findings to allocate resources and improve security efficiently.

Findings are the most common object in PlexTrac and can be added to a report in multiple ways:

* [created from scratch within a report](https://docs.plextrac.com/plextrac-documentation/product-documentation/reports/add-custom-finding/creating-a-finding)
* [migrated from WriteupsDB](https://docs.plextrac.com/plextrac-documentation/product-documentation/reports/add-custom-finding/adding-findings-from-writeupsdb)
* imported via [files generated from third-party tools](/plextrac-documentation/product-documentation-1/integrations-and-file-imports#third-party-tools), such as Nessus or Pentera
* imported from one of PlexTrac’s [CSV finding templates](https://docs.plextrac.com/plextrac-documentation/product-documentation/reports/findings/csv-findings-templates)
* imported from an [API integration](/plextrac-documentation/product-documentation-1/integrations-and-file-imports#apis), such as Snyk or HackerOne
* [imported via PlexTrac’s API endpoints](https://api-docs.plextrac.com/#fb4b754f-e02b-46a6-9708-1a532a5594da)
* [created after an assessment was completed](https://docs.plextrac.com/plextrac-documentation/product-documentation/assessments/take-assessment-1#assessment-findings-status)
* [created after an engagement was submitted](https://docs.plextrac.com/plextrac-documentation/product-documentation/runbooks-1/engagements#submitting-an-engagement) in the **Runbooks** module

## Accessing Findings

Findings can be accessed either through a report or the **Clients** module:

### **Via a Report:**&#x20;

1. Click **Reports** from the main menu.
2. Select a report.
3. Click the **Findings** tab.&#x20;

### **Via the Clients module:**&#x20;

1. Click **Clients** from the main menu.
2. Select the client.
3. Click the **Findings** tab.&#x20;

A count for the number of findings is displayed at the top of the table to the left of the filter boxes.

<div align="left"><figure><img src="/files/XPmg2ARFuTnR9fW8ksvZ" alt=""><figcaption></figcaption></figure></div>

## Identifying the Finding Source

The source of a finding can be found on the Finding detail side drawer, which appears when clicking the row of a finding seen in the **Findings** tab of a report or client. If the finding was created in PlexTrac, a value of `plextrac` exists. If the finding was imported, the source of that file or integration is also recorded.

<figure><img src="/files/0rocc9e2rrs2SaLpUnjb" alt=""><figcaption></figcaption></figure>

## Finding ID

The finding ID can be found on the Finding detail side drawer, which appears when clicking the row of a finding in the **Findings** tab of a report or client. The finding ID is generated by importing it from the source tool or dynamically by PlexTrac when the finding is created.&#x20;

For example, [importing a Nessus file](/plextrac-documentation/product-documentation/reports/findings/import-scanner-data) will pull in the Nessus `plugin ID` as the PlexTrac `Finding ID`.

<figure><img src="/files/YYDCwWd3EsBhn7G944K3" alt=""><figcaption></figcaption></figure>

Every finding in a PlexTrac report must have a unique finding title.&#x20;

When importing findings from two scans into the same report, only additional findings from the second scan and any assets tied to existing findings are imported, even if duplicates exist.

When two findings with the same title are created in two different reports for the same client, they are displayed on the **Findings** tab in the **Clients** module, as they each receive a unique finding ID.

## **Finding Reported Date**

The finding reported date is when the finding was added to the report. This value is displayed under the "Date Reported" column from the **Findings** tab. This value can be modified through the "Actions" button when selecting one or more findings.

<div align="left"><figure><img src="/files/BFUQCqGiDSyzB02iNmbq" alt=""><figcaption></figcaption></figure></div>


# Creating a Finding

Creating a finding within PlexTrac can be initiated either through the **Clients** module or the **Reports** module, but either approach involves selecting a report to add the findings. When created within PlexTrac, users can update using five tabs: **Finding** **Details**, **Affected** **Assets**, **Screenshots/Videos**, and **Code Samples**.&#x20;

<div align="left"><figure><img src="/files/7w15fjo8rhL8I3XOCMDv" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 1:</mark> From the **Reports** module, click the row of the impacted report.

<div align="left"><figure><img src="/files/awbhO98cmOyvX6r7hkOb" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Click the **Findings** tab.

<div align="left"><figure><img src="/files/xnTFedMxdYcDsN1vXA4T" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3</mark>: Click **Create Finding** from the "Add Findings" pulldown menu.

<div align="left"><figure><img src="/files/0E0UnkmQmmSoxXrMB9O8" alt="" width="426"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4:</mark> Enter a finding name and select the finding severity. Click **Create**.

<div align="left"><figure><img src="/files/l5G8tv2lttlM4IEbDA4Q" alt="" width="395"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 5:</mark> The edit finding page has four tabs for collecting data about a finding (further details on each tab are provided below).

<div align="left"><figure><img src="/files/SRZGdVLg4kvo0S28EH18" alt="" width="563"><figcaption></figcaption></figure></div>

1. **Title (required)**: All finding titles must be unique within a report. The tool will provide an error message after clicking Save if an existing title is use&#x64;**.**&#x20;
2. **Severity (required)**: Identifies the severity rating for the finding. The values are in ascending order: `Informational`, `Low`, `Medium`, `High`, and `Critical`.&#x20;
3. **Score type:** Identifies the score associated with a finding. This can be used to record a general score, a CVSS 2.0 score, a CVSS 3.0 score, a CVSS 4.0 score, or [dynamically create a CVSS 3.1 score using the provided calculator](/plextrac-documentation/product-documentation/reports/findings/cvss-scoring).&#x20;
4. **Priorities:** Associate the finding with a priority in the Priorities module.
5. **Status:** Defines the [status of the finding](https://docs.plextrac.com/plextrac-documentation/product-documentation/reports/add-custom-finding/draft-published-flag#finding-open-or-closed-status) (`Open`, `Closed`, or `In Process`). It defaults to `Open`.
6. **Sub-Status:** Provides further details on the status of a finding if [set up by admin](/plextrac-documentation/product-documentation-1/account-management/account-admin/tenant-settings/general-settings#manage-finding-sub-statuses). If no sub-status values have been configured, this field will not appear.
7. **Assigned to:** Identifies the user assigned to a finding. Only one user can be assigned, and an email will be sent once the finding is saved. The list in the pulldown menu is derived from the list of [users added to a client](/plextrac-documentation/product-documentation/clients/manage-client-users).
8. **Description (required):** An RTF field allowing content, images, links, code examples, tables, and lists to be entered as needed. This field has [collaborative editing](/plextrac-documentation/product-documentation/reports/findings/collaborative-editing) enabled.&#x20;
9. **Recommendations:** An RTF field allowing content, images, links, code examples, tables, and lists to be entered as needed. This field has [collaborative editing](/plextrac-documentation/product-documentation/reports/findings/collaborative-editing) enabled.&#x20;
10. **References:** An RTF field allowing content, images, links, code examples, tables, and lists to be entered as needed. It has [collaborative editing](/plextrac-documentation/product-documentation/reports/findings/collaborative-editing) enabled.&#x20;
11. **CVE ID:** Common Vulnerabilities and Exposures (CVE) identifier(s) assigned to the finding.  This field requires a format of *CVE prefix + Year + arbitrary digits*. There is no limit to the number of random digits.&#x20;
    * Example ID with four digits: `CVE-2014-3127`
    * Example ID with five digits: `CVE-2018-54321`
    * Example ID with six digits: `CVE-2019-456132`<br>

      <div align="left"><figure><img src="/files/MVEkINGYLC2pa9yCgAyp" alt=""><figcaption></figcaption></figure></div>
12. **CWE ID:** The Common Weakness Enumeration (CWE) identifier(s) assigned to the finding. This field requires a two-to-four-digit number format.&#x20;
    * Example ID with two digits: `99`
    * Example ID with three digits: `243`
    * Example ID with four digits: `1423`<br>

      <div align="left"><figure><img src="/files/cd3kH3SDdeWMlOMAdo7H" alt=""><figcaption></figcaption></figure></div>
13. **Tags:** Stores any tags associated with a finding to help manage and retrieve the finding more easily later.&#x20;
14. **Custom Fields**: Click **Add custom field** to insert more labels and values as needed.

<mark style="background-color:yellow;">Step 5:</mark> Click **Save**.&#x20;

The information entered is now displayed in the **Findings Details** tab and can be modified as needed. More details of a finding can be added by continuing to the other available tabs.

## Affected Assets Tab

This tab displays any affected assets associated with a finding. The Affected Assets page provides more information on this topic, such as how to import or create.

<div align="left"><figure><img src="/files/K1kfJAOCjrOXC9pCKhWA" alt=""><figcaption></figcaption></figure></div>

## Screenshots/Videos Tab

This tab stores screenshots and videos associated with a finding, as videos are not allowed in the **Finding Details** rich-text fields.&#x20;

To add a file, drag it onto the box on the page or click to navigate to files on the computer. Repeat as needed.

<div align="left"><figure><img src="/files/nU6BISFhWMvaYQ6VA0TX" alt=""><figcaption></figcaption></figure></div>

## Code Samples Tab

This tab stores any code samples related to a finding for future reference.  Click **Add Section** to add additional sections. The code will be formatted when the report is published.

<figure><img src="/files/XpkxyiDhm91q8XunF6h9" alt=""><figcaption></figcaption></figure>


# Collaborative Editing

PlexTrac offers collaborative editing to save time and reduce errors when working on reports, writeups, narratives, and findings. Collaborative editing is a process in which multiple individuals work together to create, edit, and refine content in real time, with contributors simultaneously working on the same document.

Collaborative editing exists in rich-text fields (RTFs) within the platform, such as:

* In the *Description*, *Recommendations*, and *References* RTFs of the **Findings Details** tab of a finding
* In the *Value* RTF within the **Custom Fields** tab of a finding
* In the RTF of the **Narrative** tab for a report
* In the *Description*, *Recommendations*, and *References* RTFs of the **Readout** tab of a report&#x20;
* In the *Description*, *Recommendations*, and *References* RTFs of a writeup in **WriteupsDB**&#x20;
* In the Section Body RTF in **NarrativesDB**

{% hint style="info" %}
Track changes are unavailable until the content has been created and saved (i.e., the toolbar experience differs when creating a writeup vs. editing a writeup).
{% endhint %}

## Avatar Notification

When a user edits one of the fields listed above, an avatar is displayed at the top right of the content box. Up to six avatars can be displayed.

<div align="left"><figure><img src="/files/k7zUbP9iKAMpF913xPhe" alt="" width="563"><figcaption></figcaption></figure></div>

The user's full name is provided if the cursor hovers over it.

<div align="left"><figure><img src="/files/pW9inbLgx6sAQ4zM6jkR" alt="" width="163"><figcaption></figcaption></figure></div>

## Auto-Save Rules

Messaging at the top right of the section or page where collaborative editing exists indicates when content was last saved.&#x20;

<div align="left"><figure><img src="/files/qP1vpTLO9nop0rxIbpfl" alt="" width="248"><figcaption></figcaption></figure></div>

On pages with multiple content sections, autosave is *per section* (not page), and the time stamp will update when one of the collaborative editing content blocks is modified.&#x20;

For example, when one user updates the finding description at the same time another user updates the finding recommendation, both updates are saved, and the time stamp represents the last edit.

## Offline Messaging

If the internet or VPN connection is lost, an error notification will indicate the connection has been lost.

<div align="left"><figure><img src="/files/pjw6pfefjLOjRmyOZtDk" alt=""><figcaption></figcaption></figure></div>

or

<div align="left"><figure><img src="/files/1suyeNtpIS4Apg1Wh70U" alt=""><figcaption></figcaption></figure></div>

Users cannot modify any collaborative editing sections until they return online.

## Tracking Changes

Track changes record any modifications made to the text, formatting, or other elements. It can be enabled for a particular RTF or at the report level.

When the track changes feature is enabled, any modifications made to the document are highlighted and displayed. These changes can include additions, deletions, formatting adjustments, and comments. The original content remains visible, while the modifications are marked with specific indicators, such as colored text, underlines, or strike-throughs. Additionally, users can leave comments or annotations to provide further context or explanations regarding the changes made.

Collaborators can accept or reject individual changes, and the document owner or editor can review and make final decisions on which modifications to keep. This feature is helpful when multiple individuals must work on a document simultaneously or when documents undergo several revisions.

### Tracking Changes at the RTF Level

The toggle to enable track changes in an RTF is located in the RTF toolbar. Click the track changes icon to enable.

<div align="left"><figure><img src="/files/OtHTokDr9wB7UWKTv2nd" alt="" width="563"><figcaption></figcaption></figure></div>

Track changes can also be enabled by clicking the icon and toggle on from the pulldown menu.&#x20;

<div align="left"><figure><img src="/files/ybuuPpOKjW1P0v0JllLT" alt="" width="563"><figcaption></figcaption></figure></div>

When enabled, the track changes icon in the RTF toolbar is blue.

<div align="left"><figure><img src="/files/OqxM1M0EhRwF5DQWqeqA" alt="" width="563"><figcaption></figcaption></figure></div>

Content additions are now shown in green, deletions in red, and a log of changes appears to the right of the RTF.

<div align="left"><figure><img src="/files/f888r0rYYE5fYxmJeXAU" alt="" width="563"><figcaption></figcaption></figure></div>

Changes can be accepted or rejected by clicking the checkmark or **X** in the audit box.

<div align="left"><figure><img src="/files/uLjDzZcyWJzkormtubKf" alt="" width="342"><figcaption></figcaption></figure></div>

Once accepted or rejected, the box and markup will disappear, and the content will reflect the choices.

### Tracking Changes at the Report Level

Track changes can be controlled at the report level. This toggle applies to all RTFs within a report and appears to the right of the tab headers.&#x20;

<div align="left"><figure><img src="/files/DyYb2B84Drw7N9gwW5PL" alt="" width="449"><figcaption></figcaption></figure></div>

When track changes are enabled at the report level, individual RTFs will indicate that changes are being tracked (the track changes icon in the toolbar will be blue).\
\
The toggle bar available from the pulldown menu is now green (indicating track changes are on), but the ability to turn off track changes for an RTF is greyed out.&#x20;

<div align="left"><figure><img src="/files/phTbAOk90zZZgFyNYI48" alt="" width="563"><figcaption></figcaption></figure></div>

{% hint style="info" %}
If turned **on** at the report level, track changes can only be turned **off** at the report level.
{% endhint %}

### Adding Comments

Comments are added by highlighting content and clicking the comment icon in the RTF toolbar.

<div align="left"><figure><img src="/files/bmNreet7xXSnhSxt7Xgg" alt="" width="563"><figcaption></figcaption></figure></div>

A comment box appears on the right of the RTF to capture any notes. Click **Comment** when finished.&#x20;

<div align="left"><figure><img src="/files/P4mlKfZc1J9s48dvY8Hr" alt="" width="563"><figcaption></figcaption></figure></div>

Unless resolved or deleted, the comment will stay visible with the associated text highlighted in the RTF. Someone must click the checkmark within the text box to resolve a comment.

<div align="left"><figure><img src="/files/4CL11kTYeMU7NZpEbmay" alt="" width="563"><figcaption></figcaption></figure></div>

When resolved, the comment and highlighted text disappear, but a history of the comments can be viewed by clicking the comment archive icon in the toolbar. Comments can be viewed or reopened from the archive.&#x20;

<div align="left"><figure><img src="/files/E1BCX8zTgfqNPClVZk07" alt="" width="563"><figcaption></figcaption></figure></div>

{% hint style="warning" %}
The comment archive feature only applies to comments within an RTF. Comments for other fields, such as a title, must be deleted to be removed from view.\
\
![](/files/2RxguoQKSilvTL5heeg7)
{% endhint %}

### Bulk Actions

In scenarios where multiple changes were made to an RTF, users can accept or reject them with one click using the options provided in the track changes pulldown menu.

The solutions available depend on the scenario:

* If a user has not specified specific RTF modifications, only "Accept all suggestions" and "Discard all suggestions" will be available.&#x20;
* If a user has manually highlighted RTF content, additional options are provided, allowing the user to approve only the selected content.

<div align="left"><figure><img src="/files/qjM2vTnf57VcygwwxqKb" alt="" width="563"><figcaption></figcaption></figure></div>


# Importing Findings from a File

PlexTrac can import findings from third-party tools and a CSV template for centralized data. This provides real-time visibility, holistic analysis, and efficient reporting, simplifying compliance and promoting proactive risk management.

{% hint style="info" %}
If importing from a CSV file, visit the [CSV Findings Templates page](/plextrac-documentation/product-documentation/reports/findings/csv-findings-templates) for more information.

For a list of all third-party tool integrations and field mappings, visit the [Integrations and Mappings](/plextrac-documentation/product-documentation-1/integrations-and-file-imports) section.
{% endhint %}

The file-queuing feature allows users to upload multiple files simultaneously, with the ability to view the progress and status of each import. This enhancement significantly improves efficiency by enabling background processing, which lets users continue working while files are being processed. The benefits include reduced wait times, increased productivity, and enhanced visibility into the import process.

{% hint style="info" %}
Up to 25 files no larger than 5GB each with a combined aggregate size of 20GB can be imported simultaneously.&#x20;
{% endhint %}

## Importing From a File

<mark style="background-color:yellow;">Step 1</mark>: Within the **Reports** module, click the impacted report from the list to bring up the **Readout** tab.

<mark style="background-color:yellow;">Step 2</mark>: Click the **Findings** tab.

<div align="left"><figure><img src="/files/WG9Snz0yMeALumArXsNK" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3</mark>: Click **Add Findings** and select **File Imports** from the pulldown menu.

<div align="left"><figure><img src="/files/zyD080HXtUAZkMDEvgt3" alt="" width="426"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4</mark>: A side window appears. Drop the file into the provided box or browse it on the computer. Repeat as necessary for up to 10 files (totaling 20GB).

If required, select the source from the pulldown menu.

<div align="left"><figure><img src="/files/xQof7N7VnLONh0AiGFjL" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 5:</mark> Click **Continue**.&#x20;

<mark style="background-color:yellow;">Step 6:</mark> On the second tab, "Select tags & upload," add any desired finding and asset tags (optional). When finished, click **Import**.&#x20;

<div align="left"><figure><img src="/files/adHdSxUnivlCOMvsjw0R" alt="" width="563"><figcaption></figcaption></figure></div>

The status of files imported can be viewed by clicking the icon next to the notification bell at the top of the page.

<div align="left"><figure><img src="/files/VYkNSkAnIv9HXcdPlwmV" alt="" width="497"><figcaption></figcaption></figure></div>


# CSV Findings Templates

PlexTrac understands the importance of simplifying the process of importing findings and other data into the platform, whether for a specific report or multiple reports and assets. To facilitate this, PlexTrac offers CSV templates and scripts that help streamline the import process and make it more efficient.

CSV templates serve as pre-defined structures that align with the required format for importing data. These templates specify the fields and corresponding data types expected when importing findings or other information. Users can leverage these templates to ensure that their data is correctly mapped and formatted for import, minimizing errors and ensuring consistency.

Two CSV options are available to import findings into a report. Consult the table below to determine the most suitable solution for your needs.

| Report Findings CSV Import                                    | Python General CSV Import                                                    |
| ------------------------------------------------------------- | ---------------------------------------------------------------------------- |
| Imports to a single report                                    | Imports to multiple reports                                                  |
| Request is processed on the backend in less than five minutes | Each finding is processed individually and can take up to several hours\*    |
| Must order CSV columns to match template schema exactly       | CSV columns are mapped to findings on a finding and sequence is not relevant |
| Imports to select finding fields only                         | Imports to all finding and asset fields                                      |
| Does not import client and report information                 | Imports client and report information                                        |

\*The script can create parsed findings in PlexTrac by sending API calls to create each finding individually (which results in an extended script runtime) or by generating a PTRAC file. Manually importing the generated PTRAC file takes the same time as the PlexTrac Report Finding CSV Template.&#x20;

{% hint style="info" %}
The generated PTRAC only contains the report and finding information. Asset information will not be added.
{% endhint %}

### Report Findings CSV Template&#x20;

Please click on the box below to access instructions and a downloadable CSV file that can serve as a template for uploading findings into a report. The CSV file contains fields pre-filled with sample values.

<table data-card-size="large" data-view="cards"><thead><tr><th></th><th>used in</th><th>accepted file types</th><th><select multiple><option value="ba7c14c1fa02401289b0893e52d560ba" label="field mappings" color="blue"></option><option value="05e94a2ac08c47daa95dd9eefd1ae410" label="instructions" color="blue"></option></select></th><th data-hidden data-card-cover data-type="files"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><strong>Report Finding Template</strong></td><td>Findings/Reports</td><td>CSV</td><td></td><td><a href="/files/xsjN3r5nYIw43KLZAAtp">/files/xsjN3r5nYIw43KLZAAtp</a></td><td><a href="/pages/jInAIQyUootzWtUVw0K4">/pages/jInAIQyUootzWtUVw0K4</a></td></tr></tbody></table>

### Python General CSV Template

Click on the box below to learn about importing data through the PlexTrac API using a script. The script requires two CSV files: one for importing data and another for field mappings.

This script is designed to help users import data into multiple clients and reports. It works by parsing a CSV file and creating client, report, finding, and asset objects. Once the objects are generated, the script uses the PlexTrac API to import and create them in the user's tenant.&#x20;

<table data-card-size="large" data-view="cards"><thead><tr><th></th><th>used in</th><th>accepted file types</th><th><select multiple><option value="ba7c14c1fa02401289b0893e52d560ba" label="field mappings" color="blue"></option><option value="05e94a2ac08c47daa95dd9eefd1ae410" label="instructions" color="blue"></option></select></th><th data-hidden data-card-cover data-type="files"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><strong>Python General Template</strong></td><td>Findings/Reports</td><td>CSV</td><td></td><td><a href="/files/srTIX5Sd3Huq2XLYZTef">/files/srTIX5Sd3Huq2XLYZTef</a></td><td><a href="https://github.com/PlexTrac-Labs/general-csv-import">https://github.com/PlexTrac-Labs/general-csv-import</a></td></tr></tbody></table>


# Using Report Findings CSV Template

PlexTrac provides a downloadable CSV file that can be used as a template for uploading findings offline and [importing them into PlexTrac](/plextrac-documentation/product-documentation/reports/findings/import-scanner-data) later using the **Add Findings** button within the **Findings** tab of a report.

<div align="left"><figure><img src="/files/39HTUR8Zspdp1YxVEoBu" alt=""><figcaption></figcaption></figure></div>

To download the template, click the file below:

{% file src="/files/hZ2cdTDBxNZuYR9LED8v" %}

The file has the required fields prepopulated in the CSV file, along with sample values.&#x20;

{% hint style="warning" %}
Save the file in CSV UTF-8 format to prevent including non-UTF characters that may break the importer.
{% endhint %}

## Importing the CSV File

<mark style="background-color:yellow;">Step 1:</mark> Download the CSV file above.

<mark style="background-color:yellow;">Step 2:</mark> Remove the sample values and populate the fields with desired values. A [list of the fields with definitions](#csv-mappings) and [instructions on importing custom fields](#undefined) is below.

<mark style="background-color:yellow;">Step 3:</mark> [Import the file into PlexTrac](/plextrac-documentation/product-documentation/reports/findings/import-scanner-data).

When importing the file via the **Add Findings** button in the **Findings** tab of a report, select the value  "CSV" from the pulldown menu.

<div align="left"><figure><img src="/files/Yal13506tfZPQ7yFxJkv" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4:</mark> Select the CSV file to upload and click **Continue**.

<div align="left"><figure><img src="/files/eidLKNKLdUihpLaDDxtz" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 5:</mark> Add any optional tags or leave them blank. Click **Upload**.&#x20;

<div align="left"><figure><img src="/files/ogLSEZqcflbD8WtEaQMB" alt=""><figcaption></figcaption></figure></div>

A message will appear, validating that the file is uploading.<br>

<div align="left"><figure><img src="/files/aB572KnBV9TQgA7C1WUA" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 6:</mark> Validate that the information was added to the report. When the data has been imported successfully, the screen will display the information without refreshing the page.

{% hint style="info" %}
The time required to load depends on the amount of data in the CSV file.&#x20;
{% endhint %}

<div align="left"><figure><img src="/files/iNj3PwiOTpHfgnMHjWcg" alt=""><figcaption></figcaption></figure></div>

The source of the finding will list "CSV" as the value. Below is how the data is displayed in the Finding Detail window using the sample values in the CSV template.

<div align="left"><figure><img src="/files/GPonUj7V5zlBeEqLmK0t" alt=""><figcaption></figcaption></figure></div>

## CSV Finding Field Mappings

All fields below must appear as column headers when importing the CSV file. All field values must follow the rules defined in the table, or the file may be rejected when imported or require further manual editing within PlexTrac.

{% hint style="warning" %}
**Title**, **description**, and **severity** are required.&#x20;
{% endhint %}

<table><thead><tr><th width="202">PlexTrac Field</th><th>CSV Header Label</th><th>Notes</th></tr></thead><tbody><tr><td>title</td><td>title</td><td>This is a required field.</td></tr><tr><td>severity</td><td>severity</td><td>This is a required field.<br><br>The severity value must be one of the following (not case-sensitive): <br>Informational, Low, Medium, High, Critical<br><br>If no value is provided in CSV, a value of "Informational" will be assigned.</td></tr><tr><td>status</td><td>status</td><td>Value must be one of the following: Open, Closed, In Process</td></tr><tr><td>description</td><td>description</td><td>This is a required field.</td></tr><tr><td>recommendations</td><td>recommendations</td><td>This is the findings recommendations.</td></tr><tr><td>references</td><td>references</td><td><p>This field accepts multiple values delimited with a comma.<br></p><p>For example: "Item 1, Item 2, Item 3"<br><br>NOTE: Do not use commas if providing complete sentences, as any comma will result in a para break. Periods do not trigger a para break.</p></td></tr><tr><td>assets</td><td>affected_assets</td><td><p>This field accepts multiple values delimited with a comma.<br></p><p>For example: "Item 1, Item 2, Item 3"</p></td></tr><tr><td>tags</td><td>tags</td><td><p>This field accepts multiple values delimited with a comma.<br></p><p>For example: "Item 1, Item 2, Item 3"</p></td></tr><tr><td>riskScore</td><td>cvss_temporal</td><td>This is the CVSS 3.0 score.<br><br>Example value: "5.5"</td></tr><tr><td>common identifiers</td><td>cwe</td><td>This field requires a format of <em>CWE prefix</em> + <em>a two-to-four digit number</em>.<br><br>Example value: "CWE-772"</td></tr><tr><td>common identifiers</td><td>cve</td><td>This field requires a format of <em>CVE prefix + Year + arbitrary digits</em>.<br><br>Example value: "CVE-2018-54321"</td></tr><tr><td>field: category</td><td></td><td>This column must exist in the CSV and is imported as a custom field.</td></tr><tr><td>    label</td><td>category</td><td>The column header must be "category". </td></tr><tr><td>    value</td><td>category value</td><td>This is the value entered for the category. </td></tr></tbody></table>

## Custom Fields

The CSV import will accept custom fields, which must be added at the spreadsheet's end after the template's columns.

<div align="left"><figure><img src="/files/NeUNj3YwZWCJCbOtukwG" alt=""><figcaption></figcaption></figure></div>

Row A of the CSV template will be the custom field title, and subsequent row(s) will be the custom field value(s), as entered in the spreadsheet. Add multiple columns and values as needed.

When imported, the custom fields will appear on the **Finding Detail** page.

<div align="left"><figure><img src="/files/CZGNCG6HUyXMrGqLgZi1" alt=""><figcaption></figcaption></figure></div>

The custom fields can be edited or deleted after import via the **Custom Fields** tab of the finding.

<div align="left"><figure><img src="/files/71MpMlPid78THto0SC3z" alt=""><figcaption></figcaption></figure></div>


# Importing Findings via an Integration

Findings may be imported into PlexTrac via a licensed API integration and configured by an admin.&#x20;

## Importing from an Integration

<mark style="background-color:yellow;">Step 1</mark>: Within the **Reports** module, click a report from the list to bring up the **Readout** tab.

<div align="left"><figure><img src="/files/lCuvHnTY4k0oSPhTBWzy" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2</mark>: Click the **Findings** tab.

<div align="left"><figure><img src="/files/KEh5Qk27b31Ge6Col0Ju" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3</mark>: Click **Add Findings** and select **Integrations** from the pulldown menu.

<div align="left"><figure><img src="/files/jxPUFngDmTSa0bA2xEKE" alt="" width="426"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4</mark>: Select the desired integration from the pulldown menu (the values shown in the pulldown menu are entered by the admin when the integration is set up).&#x20;

<div align="left"><figure><img src="/files/ILqnfZMGeJ8iAQOHlKhS" alt=""><figcaption></figcaption></figure></div>

{% hint style="info" %}
If an integration is not licensed or not configured by an admin, the option will not appear in the pulldown menu.
{% endhint %}

<mark style="background-color:yellow;">Step 5</mark>: Click **Continue with X** at the bottom of the page.

<div align="left"><figure><img src="/files/KFnhAt0z6dsgAUD5KQrC" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 6</mark>: The **Select Findings** tab appears with a list of filters and values that are tool-specific to an integration. Use the filters and facets to select the query parameters to determine which findings appear on the page.

<div align="left"><figure><img src="/files/nL9gw5IlBfYfyUIfCvnB" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 7</mark>: Click **Search** to retrieve the findings query results.

<div align="left"><figure><img src="/files/Lls63KhP8sYt3rnqDhfi" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 8</mark>: Select the findings from the query results to import by clicking the box at the top left of the table header row or by selecting findings individually by clicking the box next to the finding. <br>

At least one finding must be selected to continue.

<div align="left"><figure><img src="/files/5tXsgrAHtTpIDElddrR4" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 9</mark>: Click **Continue with X issues**.

<div align="left"><figure><img src="/files/gK98vdcZ4JBHevUyUTEm" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 10</mark>: Insert desired tags associated with each finding and asset when imported (optional). Click **Import X Findings**.

<div align="left"><figure><img src="/files/e5U1M5R6dYL9zyLflL1s" alt=""><figcaption></figcaption></figure></div>

Notifications will appear confirming that the import was successful.

<div align="left"><figure><img src="/files/mGCV83dOVcKLN7r0wf9a" alt=""><figcaption></figcaption></figure></div>

{% hint style="info" %}
More information on specific tools, such as field mappings, can be found on the [admin integrations page.](/plextrac-documentation/product-documentation-1/account-management/account-admin/integrations-and-webhooks/integrations-api)
{% endhint %}


# Importing Findings from WriteupsDB

[**WriteupsDB**](/plextrac-documentation/product-documentation/content-library/writeupsdb) is a repository for all PlexTrac writeups. It categorizes, associates them with use cases, and facilitates reuse. By structuring and refining findings, writeups can be used in other deliverables, such as a report.

Once a writeup becomes a finding, it is a standalone object that is not impacted if the source writeup or repository is deleted or the same writeup added to another report is edited or deleted.

## Importing from WriteupsDB

<mark style="background-color:yellow;">Step 1</mark>: From the Reports module, click the report row or Readout under the "Actions" column.

<div align="left"><figure><img src="/files/G1fZZeAHN16kq7drlC81" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2</mark>: Click the **Findings** tab.

<div align="left"><figure><img src="/files/Pwl8eqwb1oLiHh4xF1Xr" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3</mark>: Click **Add Findings**, then select **From WriteupsDB** from the pulldown menu.

<div align="left"><figure><img src="/files/Tc1S3guuj7981mg5V0Hw" alt="" width="426"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4:</mark> Search or use the provided filters to find the desired writeups to add, then click the box to select them.&#x20;

<div align="left"><figure><img src="/files/20fCHT8yPtNzmam1Wjxb" alt=""><figcaption></figcaption></figure></div>

Selected writeups to be added are shown in the column on the far right.&#x20;

<div align="left"><figure><img src="/files/xMHRuV6NA2UNI7xSZcka" alt=""><figcaption></figcaption></figure></div>

&#x20;<mark style="background-color:yellow;">Step 5:</mark> Click **Add X Writeups** at the bottom of the page.&#x20;

<div align="left"><figure><img src="/files/xst6ehg1sAXp5qYehekz" alt=""><figcaption></figcaption></figure></div>

A confirmation message will briefly appear, and the writeups are added to the report and listed on the **Findings** tab.

<div align="left"><figure><img src="/files/KF7iwHSE1y70I5lQgSLu" alt=""><figcaption></figcaption></figure></div>


# Finding Status

Findings are associated with metadata and labels that provide status and current standing. Visual cues using color in the platform also identify specific finding status states.

## Draft or Published State

Findings can be in draft or published mode, and this status is provided visually within the **Findings** tab.&#x20;

Findings in draft mode have an orange background row color and a dot next to the title. The published findings have a white background row color with no dot.

<div align="left"><figure><img src="/files/7O4lrGrb2CBU6o7xdqLl" alt=""><figcaption></figcaption></figure></div>

{% hint style="info" %}
Analyst user roles cannot view draft findings, so publishing the finding before publishing a report allows other user roles within PlexTrac to see critical issues the client needs to address immediately without requiring the report to be completed.&#x20;
{% endhint %}

### Setting to Draft or Published  &#x20;

<mark style="background-color:yellow;">Step 1:</mark> Navigate to the desired finding and click **Edit** under the "Actions" column.

<div align="left"><figure><img src="/files/hSTaaJw8DiW5hD6T5oMX" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Update the finding status by clicking the toggle button to the desired state. Changes are autosaved.

<div align="left"><img src="/files/Tqz4CPrUbKRU9u8q9DdP" alt=""></div>

### Bulk Editing Draft or Published

<mark style="background-color:yellow;">Step 1:</mark> From the **Findings** tab, select one or more findings. An **Actions** button will appear.   &#x20;

<div align="left"><figure><img src="/files/g76bDwk8RydiGGTkeRJQ" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Click the **Actions** button and click **Set Published Status**.&#x20;

<div align="left"><figure><img src="/files/er1CFgVqVCOiq2sWzgcF" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Toggle the publish status and click **Save**.

<div align="left"><figure><img src="/files/oN7cEOaW7KtPDqOaAk2N" alt=""><figcaption></figcaption></figure></div>

## Finding Status

A finding can either be `Open`, `In Process`, or `Closed`. That status is displayed on the **Findings** tab.&#x20;

{% hint style="info" %}
Admins can define and configure which finding statuses are available to users in RBAC under "Report Findings," if more granular control is needed.&#x20;
{% endhint %}

<div align="left"><figure><img src="/files/2AXYBLKM6TlwLHtM7HEu" alt=""><figcaption></figcaption></figure></div>

{% hint style="info" %}
[Click here for the business rules](/plextrac-documentation/product-documentation/assessments/submitting-an-assessment) on a question in an assessment that is assigned a status as a finding after the assessment is submitted.
{% endhint %}

Findings may also have a sub-status value. These do not exist unless added by an admin. Once added, they will be available to associate with a finding but are optional.&#x20;

<div align="left"><figure><img src="/files/8uGQgpa2O9vH4pbuSjbr" alt=""><figcaption></figcaption></figure></div>

The Sub Status column is available when viewing findings in a report. It does not exist when viewing findings for a client.

### Updating Finding Status

<mark style="background-color:yellow;">Step 1:</mark> From the **Findings** tab, click the status button of the finding to change.

<div align="left"><figure><img src="/files/DATJOyP6z0IRAMYrRYya" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Click **Add Update**.

<div align="left"><figure><img src="/files/wOFSA9dsrFLjF1Bus6F0" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> The "Add Update" model appears with any previously populated values. Use the pulldown menus to update Status, Sub-Status, and Assigned to values. Enter any optional comments to provide context.

Click **Save**.

<div align="left"><figure><img src="/files/Tex0mehR82yX60cTjhkE" alt=""><figcaption></figcaption></figure></div>

The changes are reflected in the log notes of the finding status tracker, which can be viewed at any time by clicking the finding status label.

<div align="left"><figure><img src="/files/VENf4aE31rLz2AmMY1KN" alt=""><figcaption></figcaption></figure></div>

### Bulk Updating Finding Status&#x20;

<mark style="background-color:yellow;">Step 1:</mark> From the **Findings** tab, select one or more findings. An **Actions** button will appear.   &#x20;

<div align="left"><figure><img src="/files/g76bDwk8RydiGGTkeRJQ" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Click the **Actions** button and click **Assign/Update Status**.&#x20;

<div align="left"><figure><img src="/files/fd2VXnXV83uuUWnfpmHW" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> The "Add Update" modal appears with any previously entered values. Use the pulldown menus to update Status, Sub-Status, and Assigned to. Enter any optional comments to provide context.

Click **Save**.

<div align="left"><figure><img src="/files/Tex0mehR82yX60cTjhkE" alt=""><figcaption></figcaption></figure></div>

The changes are added to the selected findings.


# Creating Jira Tickets

PlexTrac can be integrated with Jira and allow information about findings to be sent to Jira. Visit the [Jira Cloud integrations page](/plextrac-documentation/product-documentation-1/account-management/account-admin/integrations-and-webhooks/integrations-api/jira#setting-up-a-jira-integration) for details on setting up Jira.&#x20;

{% hint style="info" %}
The PlexTrac to Jira integration supports field content only. Rich text formatting (e.g., bold, italics, bullet points) is not preserved when syncing data to Jira.
{% endhint %}

## Linking a Finding to a Jira ticket

<mark style="background-color:yellow;">Step 1:</mark> Navigate to the **Findings** tab of a report.

<div align="left"><figure><img src="/files/h4WMsBdYOxirKWN5upp3" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Click the three dots under the "Actions" column of the finding to update.

<div align="left"><figure><img src="/files/EH5ph0HuIcN3RAOtjuLg" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Click **Link Jira Ticket**.

<div align="left"><figure><img src="/files/q4P1P2dwejjyJF5NH1Vp" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4:</mark> Select the Jira project and issue to associate the finding with. Click **Create ticket**.

<div align="left"><figure><img src="/files/tPqFsSRkjZ8ZPUo3sZ6C" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 5:</mark> The Jira ticket is now listed under "Linked Ticket."

<div align="left"><figure><img src="/files/5VLaGjaA9L9RHRk0W8uU" alt=""><figcaption></figcaption></figure></div>

Clicking the linked ticket value will open Jira. If mapped by the Admin, the finding date reported value will appear in Jira as a value for "Start Date."&#x20;

<div align="left"><figure><img src="/files/MxkTZZRoKSI9mhhYTYIt" alt=""><figcaption></figcaption></figure></div>

If set up for two-way data flow in integration mapping, updating the start date in Jira will update PlexTrac the next time synchronization occurs.

## Creating a Jira Ticket

<mark style="background-color:yellow;">Step 1:</mark> Navigate to the **Findings** tab of a report.

<div align="left"><figure><img src="/files/N5mih0vG3mTC3cua7lQP" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Click **Status** under the "Actions" column of the finding used to create a Jira ticket.

<div align="left"><figure><img src="/files/h2CSrYnLzMeZSTo1pWWw" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Click **Create Jira Ticket & Link.**

<div align="left"><figure><img src="/files/pIix7VmpEgRFPyh3Oh4Z" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4:</mark> Select the Jira project and issue to link with. Click **Create ticket**.&#x20;

<div align="left"><figure><img src="/files/CdlaKJso54K2E5SoVVc3" alt=""><figcaption></figcaption></figure></div>

A ticket in Jira is created, and the ticket number is listed under "Linked Ticket" on the **Findings** tab.

<div align="left"><figure><img src="/files/gTkYdfqASQdOa4xygOit" alt=""><figcaption></figcaption></figure></div>

## Unlinking a Jira Ticket

<mark style="background-color:yellow;">Step 1:</mark> Navigate to the **Findings** tab of a report.

<div align="left"><figure><img src="/files/N5mih0vG3mTC3cua7lQP" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Click the three dots under the "Actions" column of the finding linked to a Jira ticket.

<div align="left"><figure><img src="/files/h2CSrYnLzMeZSTo1pWWw" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Click **Unlink Jira ticket.**

<div align="left"><figure><img src="/files/CV1iX8XYpwvaqgkyBgYc" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> A modal appears, confirming the action. Click **Ok**.

<div align="left"><figure><img src="/files/PqUpbVdSHfgoUthAQ3xT" alt=""><figcaption></figcaption></figure></div>

## Bulk Creating Jira Tickets

<mark style="background-color:yellow;">Step 1:</mark> Navigate to the **Findings** tab of a report.

<div align="left"><figure><img src="/files/D2nWmkWY8VAbkehoJtt7" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Select the desired finding(s) by clicking the check box of the finding row.

<div align="left"><figure><img src="/files/3RO2neVGh2u9nzMfkOGe" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Hover over the "Actions" button to bring up the pulldown menu and click **Create Jira Tickets**.

<div align="left"><figure><img src="/files/qXSBa3wH0cxVCLuOhGie" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4:</mark> Select the Jira project and issue type to which the finding(s) should be assigned. Click **Create ticket**.

<div align="left"><figure><img src="/files/Vz1XvVuFbjHNV0uT3zHe" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 5:</mark> A message will confirm that ticket(s) were created, and the linked ticket number will now be displayed for finding on the page.&#x20;

<div align="left"><figure><img src="/files/S2LWrZfk4vNmiNcAt5gG" alt=""><figcaption></figcaption></figure></div>

Clicking the linked ticket value will take you directly to Jira for viewing.&#x20;


# CVSS Scoring

The Common Vulnerability Scoring System (CVSS) is an industry benchmark for evaluating the seriousness of identified vulnerabilities. It calculates a CVSS score by considering three metric categories (base, temporal, and environmental) encompassing various aspects of a vulnerability's impact and ability to persist in different contexts.

PlexTrac allows users to input or adjust scores when generating or revising findings, facilitating precise vulnerability assessment.

{% hint style="info" %}
CVSS is owned by FIRST and used with permission. This calculator is based on [FIRST CVSS documentation](https://www.first.org/cvss/).
{% endhint %}

## Entering a Findings Score

<mark style="background-color:yellow;">Step 1:</mark> From the **Findings** tab, click **Edit** under the "Actions" column of the finding to modify.

<div align="left"><figure><img src="/files/Th8RVNDUYESL5Gsh5UPT" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> On the **Finding Details** tab, select the applicable standard from the **Score type** pulldown menu ([information specifically on CVSS v3.1 and CVSS v4.0 is located further below](#cvss-3.1-calculator)). If not using CVSS, click **General**.

<div align="left"><figure><img src="/files/ltn7lkBtnNDt3K9gVxMl" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Enter values in the provided fields.&#x20;

<figure><img src="/files/y2GQ1dZ1CZyGiBa0ZI7v" alt=""><figcaption></figcaption></figure>

The score information for that finding is now displayed on the **Finding Detail** page.

<div align="left"><figure><img src="/files/IneQddmzF0x6gOOpUZ91" alt=""><figcaption></figcaption></figure></div>

## CVSS v3.1/v4.0 Calculator

PlexTrac has a built-in calculator that generates a CVSS score based on selected input values. It also generates a CVSS vector and assigns severity to a finding based on the information selected and calculated score.

Users can create a value by clicking through the provided calculator, typing in a vector, or combining both actions.&#x20;

The calculator is available when `CVSS v3.1` or `CVSS v4.0` is selected from the "Score type" field.

<div align="left"><figure><img src="/files/wprSstzupgt8m8q5NQR5" alt=""><figcaption></figcaption></figure></div>

{% hint style="info" %}
If the value in the **Severity** field is manually changed at any point after a CVSSv3.1 score has been created, a warning message will appear:

<img src="/files/EbWmbwBRh5XGJwdozcwt" alt="" data-size="original">
{% endhint %}

### Entering a Score Manually

If the score is already known, it can be entered in the "Score" field, and the finding's severity will update to match the score.&#x20;

<div align="left"><figure><img src="/files/mXRAY2CjICHUd3Eaw2w8" alt=""><figcaption></figcaption></figure></div>

### Entering a Vector Manually

If the CVSS vector is known, entering the value in the "Vectore" field will dynamically set the finding severity. &#x20;

<div align="left"><figure><img src="/files/pVS0wU1bXeTAJECd2M0w" alt=""><figcaption></figcaption></figure></div>

### Using the Calculator

<mark style="background-color:yellow;">Step 1:</mark> In the "Score type" field, select `CVSS v3.1` or `CVSS v4.0`, then click **Calculate Score**.

<div align="left"><figure><img src="/files/RlWjxmvgmKG6WxYe5iOe" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> To create a vector, select values by clicking the fields provided. All values must be entered.

{% hint style="info" %}
The metrics available to configure differ depending on the score type selected.
{% endhint %}

<div align="left"><figure><img src="/files/aevomACq5fnjokSk8rLc" alt=""><figcaption></figcaption></figure></div>

After entering a value for all fields, a severity score, severity value, and vector value are populated.

<div align="left"><figure><img src="/files/k3yB9mDH7IHD0tIh5FEt" alt=""><figcaption></figcaption></figure></div>

Validation is performed on multiple fields to ensure accurate score and severity using vector string and record, which must be kept in sync.

The calculator updates the vector record string when a field is clicked. However, the string is displayed only when all base values are selected. The option to save will appear afterward.

When the vector string has changed, the string is then validated. If the string is valid, the record and selected values are updated in the calculator modal. If not, a warning message is displayed, and the save button is disabled.

<mark style="background-color:yellow;">Step 3:</mark> For more advanced scoring options, expand "Show temporal and environmental scoring.<mark style="background-color:yellow;">"</mark>

<div align="left"><figure><img src="/files/pf0QE4UQkQ7HAQnczqGZ" alt=""><figcaption></figcaption></figure></div>

Additional fields specific to the score type will be displayed for editing.

<div align="left"><figure><img src="/files/xMoXqXlm58ARHX8e3Tpt" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 5</mark>: When finished, scroll to the bottom of the modal and click **Save**. The severity, score, and vector are populated in the appropriate fields on the **Findings Details** tab.&#x20;

<div align="left"><figure><img src="/files/wFDrTvvzrEhmntG72CMa" alt=""><figcaption></figcaption></figure></div>

CVSS 3.1 scores can also be viewed on the **Findings** tab of a report or client if that field has been configured to appear in the table.

<div align="left"><figure><img src="/files/yQzX6nbKCG24IJT41x7M" alt=""><figcaption></figcaption></figure></div>


# Affected Assets

Affected assets are managed from the finding, as opposed to the client. Affected assets contain information about an affected asset and relational metadata about the finding it is tied to.&#x20;

An affected asset object on a finding will have a subset of fields compared to the client asset with the same ID. Some additional fields make sense when the finding and client asset are viewed together, such as the date the finding started affecting the client asset, the affected ports, location access to vulnerability, vulnerable parameters, and evidence of the affection.

{% hint style="info" %}
[Click here](https://docs.plextrac.com/plextrac-documentation/master/plextrac-api-overview/object-structures/asset-object#affected-asset-structure) for more information about the affected asset object structure and all the fields and values it might contain.
{% endhint %}

## Viewing Affected Assets

<mark style="background-color:yellow;">Step 1:</mark> From the **Reports** module, click the row of the impacted report.

<div align="left"><figure><img src="/files/k8nSj7yQSRHLm6gVbOCS" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Click the **Findings** tab.

<div align="left"><figure><img src="/files/2jkzOKF6rWplqBmc7HFA" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Click the row of a finding.

<div align="left"><figure><img src="/files/P48Bc9Ouc0xDWBhkW2fD" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4:</mark> If an affected asset(s) exist for this finding, they are listed on the Finding Detail modal.

<div align="left"><figure><img src="/files/dD4vLFP8dznROMNxt9Yh" alt=""><figcaption></figcaption></figure></div>

A parent asset can be accessed directly by clicking the provided link within the table.

<mark style="background-color:yellow;">Step 5:</mark> Click **View** under the "Actions" column of the affected asset to see more information.

<div align="left"><figure><img src="/files/Q3E47udMtFk2uuAoRlqU" alt=""><figcaption></figcaption></figure></div>

The Asset Detail modal appears with information about the affected asset and a link to any parent, if applicable.&#x20;

<div align="left"><figure><img src="/files/y68LjPMUh2eUDvh4mCC8" alt=""><figcaption></figcaption></figure></div>

## Configuring Views

The table view can be customized by clicking the column view icon to the right of the **Add assets** button.

<figure><img src="/files/MxtE8hXb07eUVajPbJo9" alt=""><figcaption></figcaption></figure>

Once clicked, a modal appears that lists all fields. To remove a column, click **X** within the bar.

<div align="left"><figure><img src="/files/RSDZb8dYQqjFHCcepxfh" alt=""><figcaption></figcaption></figure></div>

{% hint style="info" %}
Fields that are required do not have an **X** available.
{% endhint %}

When fields are removed, an "Add Column" pulldown menu is added at the bottom left of the modal to store the field. Any removed fields can be added later by clicking **Add Column** and selecting the field to add. &#x20;

This modal represents the sequence of fields provided in the table, meaning the bar on top will be the column on the table's far left.&#x20;

The order of columns can be adjusted within this modal by clicking the six dots on the left of the bar for a field and dragging the bar to the desired sequence place.

<figure><img src="/files/4rOeEPETzME0iKpu6QvF" alt=""><figcaption></figcaption></figure>

Click **Save** when finished.&#x20;

## Creating an Affected Asset

<mark style="background-color:yellow;">Step 1:</mark> From the **Reports** module, click the impacted report.

<div align="left"><figure><img src="/files/ben6K3JKRcZF8uc7uWkF" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Click the **Findings** tab.

<div align="left"><figure><img src="/files/ip3HkxCldckEeJkRtExq" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Click **Edit** of the finding the affected asset is being added to.

<div align="left"><figure><img src="/files/Qk8nhphQOgOqT4f9aex6" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4:</mark> Click the **Affected Assets** tab.

<figure><img src="/files/2roUw692MVwE77fTYATj" alt=""><figcaption></figcaption></figure>

<mark style="background-color:yellow;">Step 5:</mark> Click the **Add Assets** button and select **Create new asset**.

<figure><img src="/files/rl11fbhJAihi6iOIPrt1" alt=""><figcaption></figcaption></figure>

<mark style="background-color:yellow;">Step 6:</mark> Enter information about the affected asset in the appropriate fields within the **Asset Information** tab.

<div align="left"><figure><img src="/files/oHU8rQYKXJRQrDcObwIu" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 7:</mark> Click the **Affected Areas** tab. Enter information about the following:

* **Affected Ports:** Network ports vulnerable to a security exploit or attack.
* **Location/URL:** The URL of the affected asset.
* **Vulnerable Parameters:** The inputs or settings in a system or program that an attacker can exploit to compromise the security or integrity of the system. These parameters can include usernames, passwords, API keys, and configuration files.
* **Notes:** A text box for any additional information to provide context on the affected asset.

<figure><img src="/files/U121zhav1DIHJikkMM98" alt=""><figcaption></figcaption></figure>

<mark style="background-color:yellow;">Step 8:</mark> Click the **Evidence** tab. This tab contains two text fields (title and description) per item but as many items of evidence can be added as needed. Evidence represents when or how the affected asset was found, and often is the scanner output from the scanning process.

<div align="left"><figure><img src="/files/e85ljJMcEFOwQvOA7kCZ" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 9:</mark> Click **Save**.

The asset is now listed in the **Affected Assets** tab of the finding.&#x20;

## Editing an Affected Asset

<mark style="background-color:yellow;">Step 1:</mark> From the **Affected Assets** tab of a finding, click **Edit** under the "Actions" menu.

<div align="left"><figure><img src="/files/Xus3p4rkv8kEQ1cRdABl" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Edit or add information as desired and click **Save**.&#x20;

## Deleting an Affected Asset

<mark style="background-color:yellow;">Step 1:</mark> From the **Affected Assets** tab of a finding, click **Remove** under the "Actions" menu.

<div align="left"><figure><img src="/files/PHnbuXTXK0Q9nMqjGahL" alt=""><figcaption></figcaption></figure></div>

A modal appears, confirming the deletion. Click **Remove**.&#x20;

## Adding Existing Assets

Assets already in PlexTrac can also be added as an affected asset for a finding.

<mark style="background-color:yellow;">Step 1:</mark> From the **Affected Assets** tab of a finding, click the **Add Assets** button and select **Add existing assets** from the pulldown menu.

<figure><img src="/files/q3NasHNwVrRGWOl52B95" alt=""><figcaption></figcaption></figure>

<mark style="background-color:yellow;">Step 2:</mark> Choose the asset(s) from the pulldown menu and click **Save**.

<div align="left"><figure><img src="/files/ADOtPts61ofVA4ioX1jO" alt=""><figcaption></figcaption></figure></div>

## Importing Affected Assets

Assets can be imported using a PlexTrac CSV Asset import template. [Click here](https://docs.plextrac.com/plextrac-documentation/product-documentation/clients/adding-assets-in-clients#importing-an-asset) to download the template and enter asset data to import.

<mark style="background-color:yellow;">Step 1:</mark> From the **Affected Assets** tab of a finding, click the **Add Assets** button and select **Import assets** from the pulldown menu.

<figure><img src="/files/0aSuhkLyrGAwsr69EyYy" alt=""><figcaption></figcaption></figure>

<mark style="background-color:yellow;">Step 2:</mark> Drag a file into the modal or click the box to navigate to the file on the computer.&#x20;

<div align="left"><figure><img src="/files/PCrl77KqeEaiWdMTtDp6" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Click **Import**.&#x20;

<div align="left"><figure><img src="/files/kb7gMyeDsfznXmuUvPIe" alt=""><figcaption></figcaption></figure></div>

A message will appear confirming import.

The asset(s) are now listed in the **Affected Assets** tab.

## Bulk Importing Affected Assets

<mark style="background-color:yellow;">Step 1:</mark> From the **Affected Assets** tab of a finding, click the **Add Assets** button and select **Bulk paste** from the pulldown menu.

<figure><img src="/files/IsmqkXpJp1CLWnWZXoqI" alt=""><figcaption></figcaption></figure>

<mark style="background-color:yellow;">Step 2:</mark> Enter the assets into the box by separating each value with a comma. PlexTrac will parse the assets and add them to the finding. URLs with paths (ex., [www.plextrac.com/test/](http://www.plextrac.com/test/)) will be separated into parent and child assets. Click **Next**.

<div align="left"><figure><img src="/files/2i16e7dQ60Ofm13FccMp" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Asset, ports, and child asset values are dynamically assigned. Review and uncheck the box next to any new assets that should not be added. Click **Next**.

<div align="left"><figure><img src="/files/9RDsFa2R1qIdwStD7dJh" alt=""><figcaption></figcaption></figure></div>

{% hint style="info" %}
Any subdirectories listed for an asset's domain will be loaded as its asset and considered a 'child' in relation to the 'parent' domain. This relationship will be tracked and maintained within PlexTrac.\
\
For example, **[www.plextrac.com/home](http://www.plextrac.com/home)** will become two assets, with **/home** a child to \*\*[www.plextrac.com.\*\*\\](http://www.plextrac.com.**\\)
\
![](/files/i8qfoGw87yN6ENbHAaNv)
{% endhint %}

<mark style="background-color:yellow;">Step 4:</mark> Add any desired optional tags. Tags will be assigned to all added assets. Existing assets will retain current tags. Click **Add X assets**.

<div align="left"><figure><img src="/files/NB9ruHHruhHW7jbNdh9L" alt=""><figcaption></figcaption></figure></div>

The new assets are displayed in the **Affected Assets** tab of the findings.

<div align="left"><figure><img src="/files/Isbkx39lrZqmebxf0D8Z" alt=""><figcaption></figcaption></figure></div>

## Bulk Updating&#x20;

<mark style="background-color:yellow;">Step 1:</mark> From the **Affected Assets** tab of a finding, click the box in the header row to the left of "Asset."&#x20;

<div align="left"><figure><img src="/files/nXnIWam0lHCA9B3nPS3x" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> The "Actions" button appears with the following options:

* Add affected location/url
* Add affected ports
* Delete&#x20;

<div align="left"><figure><img src="/files/X0R3J9H1GLcromVAl2Df" alt=""><figcaption></figcaption></figure></div>

Click the desired task from the pulldown menu and continue reading for additional details on each action.

### Add Affected Location/URL

A modal will appear with a field to enter a URL. The query parameters will be parsed out into the inputs provided. Click **Add Parameter** to include vulnerable parameters. Click **Save** when finished.

<div align="left"><figure><img src="/files/HOdg8r6iRKeFB3D7rePT" alt=""><figcaption></figcaption></figure></div>

The new value appears on the **Affected Assets** tab under the "Location/URL" column.

<div align="left"><figure><img src="/files/M6yV4dnt1oIbHsowT6h0" alt=""><figcaption></figcaption></figure></div>

### Add Affected Ports

A modal will appear with a field to enter any affected ports. Click Add Port to repeat the process as needed. Click Save when done.

<div align="left"><figure><img src="/files/zSbNWF3O6BoHoAph5AyX" alt=""><figcaption></figcaption></figure></div>

The new values will appear under the appropriate columns on the **Affected Assets** tab.

<div align="left"><figure><img src="/files/zzQIrcaF5xxIpYyvzvfG" alt=""><figcaption></figcaption></figure></div>

### Delete

A modal will appear, asking for confirmation of the action. Click **Delete Assets**.&#x20;

<div align="left"><figure><img src="/files/2j0VEXdwKiNFtjhBsaBG" alt=""><figcaption></figcaption></figure></div>


# Importing a Report

PTRAC files (.ptrac) can be imported into PlexTrac for cross-team collaboration. For instance, a red team from one tenant can share with a blue team client with its own PlexTrac instance.

Reports can be imported either in the **Client** module or the **Reports** module. The instructions below are specific to the **Reports** module, assuming the user has an exported report in PTRAC format.

## Importing Permissions

Admins can configure the options to import files via the **Admin Dashboard** on the "Role Based Access" page. To do so, select a custom role and click the "Ability to import reports" button under Reports Permissions. A dialog box will appear with options to turn on/off the ability to import reports.

<div align="left"><figure><img src="/files/uuimiJnpYRZdwcY2dUzI" alt="" width="438"><figcaption></figcaption></figure></div>

## Importing a Report

<mark style="background-color:yellow;">Step 1:</mark> From the **Reports** module home page, click **Import Report**.

<div align="left"><figure><img src="/files/jTE34rcgYR4mEfqMCWDn" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Select the client the report will be associated with from the pulldown menu on the modal.

<div align="left"><figure><img src="/files/Zsx7UaRoPBhCkOMKTgCJ" alt="" width="401"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Drag the .ptrac file to the box provided or click the box and navigate to the file on the computer.

<div align="left"><figure><img src="/files/rhB7zHquSMtP1dxfBxlS" alt="" width="398"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4:</mark> Click **Submit**.

<div align="left"><figure><img src="/files/ncZkZu0V7Hb2bd3qAtP1" alt="" width="396"><figcaption></figcaption></figure></div>

A progress bar will indicate the status; the upload may take a minute or two.

<div align="left"><img src="/files/Z7q8usNi4IB8rINEknsb" alt="" width="433"></div>

When completed successfully, a confirmation message will appear.

<div align="left"><img src="/files/lEXkEeaCPlNAGX7uES6J" alt="" width="347"></div>


# Exporting a Report

PlexTrac reports can be shared between tenants to enable cross-team collaboration through importing and exporting.&#x20;

For example, an external red team of one tenant may want to export a report and share it with an internal blue team client that manages its PlexTrac instance.

## Export File Formats

The following export file options exist for reports:

* **Portable Document Format (.pdf)**: While a .pdf file is not easily editable, it offers a reliable way to share and distribute documents while maintaining original formatting and visual integrity.
* **Microsoft Word (.doc)**: A .doc file can contain various elements and formatting options, such as font styles, sizes, and colors. It supports rich text formatting, allowing users to customize the appearance of their documents.\
  \
  Desktop Microsoft Word (Windows/Mac) is the officially supported rendering environment for Word exports. Microsoft 365 Word Online compatibility is provided on a best-effort basis.
* **Markdown (.md):** Markdown is a lightweight markup language that allows authoring in plain text that is then converted into formatted content using plain text characters to denote elements like headings, lists, emphasis (bold or italic), links, images, code blocks, etc.
* **Comma-separated values (.csv)**: A .csv file is a plain text file format commonly used for storing and exchanging tabular data that allows data to be organized in rows and columns, similar to a spreadsheet. Each line typically represents a row of data, and commas separate the values within the row. Each value corresponds to a specific column, allowing the data to be structured in a tabular format.
* **CSV - findings by assets (.csv)**: A CSV file format tailored explicitly for organizing and presenting findings by assets. Each row represents a unique asset, with columns detailing various attributes. This format allows for easy sorting, filtering, and analyzing asset-specific data, making it particularly useful for large-scale asset management and security assessments.
* **Extensible Markup Language (.xml):** An .xml file is a plain text file that uses tags to define elements and their hierarchical relationships.
* **PlexTrac/JSON (.ptrac)**: A .ptrac file provides more structure and the ability to maintain relational data similar to JSON and XML than a CSV. Images are stored using Base64, a binary-to-text encoding scheme representing binary data as a sequence of ASCII characters.

{% hint style="warning" %}
Comments made within a report are not exported, and images with a border larger than 6 points may not export correctly.&#x20;
{% endhint %}

## Exporting Permissions

Admins can configure the options users see in the platform via the **Admin Dashboard** on the "Role Based Access" page. To accomplish this, select a custom role and click the "Ability to export reports" button under Report Access.

A dialog box will appear with options to turn on/off the ability to export reports.

<div align="left"><figure><img src="/files/5PGVK5X5ofGf4E9lMdRQ" alt="" width="425"><figcaption></figcaption></figure></div>

## Exporting a Report

<mark style="background-color:yellow;">Step 1:</mark> From the **Reports** module home page, click the row of the report to export.

<mark style="background-color:yellow;">Step 2:</mark> Click **Export report**.

<div align="left"><figure><img src="/files/0xieEr9jbkRNW8eKz27o" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Select the desired export format from the pulldown menu.&#x20;

{% hint style="info" %}
Options available depend on permissions and the [export template](/plextrac-documentation/product-documentation-1/account-management/account-admin/customizations/templates/export-templates) associated with the report.&#x20;
{% endhint %}

<div align="left"><figure><img src="/files/QHqLZLVGWpEl1kifYogy" alt="" width="305"><figcaption></figcaption></figure></div>

Once the option is selected, the file download to the local system begins processing.

If an error exists, a message providing more information will appear.

<div align="left"><figure><img src="/files/lweQESBx11GdnDdng6Qy" alt="" width="471"><figcaption></figcaption></figure></div>


# Priorities

The **Priorities** module gives users an advanced view that provides valuable insights into their security efforts. This module is crucial for effectively managing findings and assets. It offers a collaborative platform that empowers team members to work together and address security challenges efficiently. Additionally, users can customize security measures to meet the unique requirements of individual clients or business groups.

Users access the module by clicking **Priorities** in the application's main menu.

<div align="left"><figure><img src="/files/xy7QSmYqwTmdxdB2p2Lu" alt=""><figcaption></figcaption></figure></div>

{% hint style="warning" %}
More detailed instructions regarding the impact of tenant-level vs. client-level settings can be found in the [Licensing](/plextrac-documentation/product-documentation-1/account-management/account-admin/licensing/licensing#priorities) section. Information on equations can be found in the [Automations](/plextrac-documentation/product-documentation-1/account-management/account-admin/automations/risk-scoring/managing-priority-equations) section.&#x20;
{% endhint %}

## Overview

The Priorities module offers value to teams seeking to streamline and automate reporting processes while providing a layer of risk assessment to existing manual pentests and offensive security data.&#x20;

Key benefits include:

1. **Automated Workflow Efficiency:** Automating workflow processes streamlines reporting cycles, reducing manual efforts and time spent on tasks.
2. **Risk Prioritization:** Enables custom scoring equations to prioritize identified risks, allowing teams to focus on the most critical issues for immediate remediation.
3. **Proactive Risk Management:** This tool enables a proactive approach to managing offensive security data by providing an aggregated view of vulnerabilities, allowing for better risk assessment and remediation planning.
4. **Continuous Risk Reduction:** Through ongoing validation, it demonstrates a continuous risk reduction, ensuring that remediation efforts effectively mitigate future security risks.

<div align="left"><figure><img src="/files/zmJgPRQgA8MMWZp8PvWs" alt="" width="563"><figcaption></figcaption></figure></div>

## Dashboard Visibility

An indicator will be displayed on the **My work** button if a user owns or authors a priority. Clicking the **Your priorities** box will display the priority and role assigned, along with other fields specific to the Priorities module.

<div align="left"><figure><img src="/files/BzBfjzPVGF6q66DYq0yT" alt="" width="563"><figcaption></figcaption></figure></div>

The following roles will result in a user having a priority box displayed:

* Priority Owner
* Priority Author
* Treatment Owner

## Notifications

Depending on the tenancy configuration and user role assignment, an email may be sent to users for the following event changes:

* Priority status
* Priority assignment
* Finding status
* Finding substatus
* Assignment


# Priorities Components

Users can view and access all priorities related to their tenancy on the **Priorities** home page. This view provides options for sorting and filtering on multiple fields.&#x20;

<div align="left"><figure><img src="/files/AuKFjWPdvG9mqHmDBnDX" alt="" width="563"><figcaption></figcaption></figure></div>

Clicking the priority row or **View** under a priority's "Actions" column directs users to the priority **Details** summary, including additional tabs for **Findings** and **Assets**.&#x20;

## Details Tab

The **Details** tab provides the priority description, recommendation, treatment, and any assigned tags. The column on the right provides additional information about the priority.&#x20;

<div align="left"><figure><img src="/files/d1WnVtRa9swnBbiSFbCv" alt="" width="563"><figcaption></figcaption></figure></div>

## Findings Tab

This tab displays all findings contained in the priority.&#x20;

<div align="left"><figure><img src="/files/omAFi7JE6KHvGDf1nQpB" alt="" width="563"><figcaption></figcaption></figure></div>

### Bulk Actions

Bulk action options appear after one or more findings are selected on the home page. To access them, click the checkbox to the far left of the finding title field or the box next to the column header.&#x20;

Click **Actions** to see the list of options, such as adding tags or changing the reported date.

### Configuring Table View

The table view can be customized by clicking the column view icon to the right of the search bar.

Once clicked, a modal appears that lists all fields. To remove a column, click **X** within the bar.

{% hint style="info" %}
Fields that are required do not have an **X** available.
{% endhint %}

When fields are removed, an "Add Column" pulldown menu is added at the bottom left of the modal to store the field. Any removed fields can be added later by clicking **Add Column** and selecting the field to add. &#x20;

This modal represents the sequence of fields provided in the table, meaning the bar on top will be the column on the table's far left.&#x20;

The order of columns can be adjusted within this modal by clicking the six dots on the left of the bar for a field and dragging the bar to the desired sequence place.

<div align="left"><figure><img src="/files/rPIHmAwPadj96vwz3Jol" alt="" width="563"><figcaption></figcaption></figure></div>

Click **Save** when finished.&#x20;

## Assets Tab

This tab displays all assets contained in the priority.&#x20;

<div align="left"><figure><img src="/files/fk5zQojG8NIHUMQNarxn" alt="" width="563"><figcaption></figcaption></figure></div>

### Bulk Actions

Bulk action options appear after one or more findings are selected on the home page. To access them, click the checkbox to the far left of the finding title field or the box next to the column header.&#x20;

Click **Actions** to see the list of options.

### Configuring Table View

The table view can be customized by clicking the column view icon to the right of the search bar.

## Additional Configuration

Admins do additional setup and configuration in the **Admin Dashboard**.

{% hint style="warning" %}
It is recommended to read the admin settings documentation before using priorities to understand the impact each setting has on the experience.&#x20;
{% endhint %}

### Tenant Level Settings

Priorities can be set at the tenant or client levels and configured under "Priorities" in the **Admin Dashboard**.

<div align="left"><figure><img src="/files/7M1GqWEox7824HW7Vmku" alt="" width="352"><figcaption></figcaption></figure></div>

### Risk Scoring

PlexTrac allows admins to leverage a priority score equation instead of the manual approach of setting a score based on likelihood and impact. Equations can be enabled and customized under the "[Risk Scoring](/plextrac-documentation/product-documentation-1/account-management/account-admin/automations/risk-scoring)" section of the **Admin Dashboard**.

### Viewing the Priority Score

The priority score can be viewed under the progress bar on the **Details** tab of a priority.

<div align="left"><figure><img src="/files/vWQnbOZ3Y8p467WEA70C" alt="" width="278"><figcaption></figcaption></figure></div>


# Creating a Priority

<mark style="background-color:yellow;">Step 1:</mark> From the **Priorities** module home page, click **Create Priority**.

<div align="left"><figure><img src="/files/qGKurMRc8NiiJJufEXEG" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark>  Set the scope of the priority, and select what should be prioritized, *Assets* or *Findings.* Click **Add details**.

If client-specific priorities are enabled, select a client by scrolling through the list or using the search box to filter.&#x20;

<div align="left"><figure><img src="/files/qq3HJxhOYxxVJYEdk75c" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Enter a priority name and additional information into the fields on the page.

<div align="left"><figure><img src="/files/SnPq7qcjeH1olP2ozEaz" alt="" width="554"><figcaption></figcaption></figure></div>

* **Priority name (required**): The title of the priority.&#x20;
* **Automatically add new recurring instances to this priority (optional):** Check this box if for every instance of an Asset or Finding, it will be brought into the priority automatically. This is recommended for a project whose scope might change.
* **Ignore information instances (optional):** Check this box if the priority excludes instances that do not contain a vulnerability.
* **Assignee(s) (optional):** Click the input field to select the assignee(s) for the priority.
* **Remediation owners (optional)**: A list of owner(s) who will own the priority remediation.&#x20;
* **Target remediation date (optional)**: Identifies the ideal date on which findings for the priority will be resolved. Place the cursor in the field box to select a date from the calendar.&#x20;
* **Description (optional):** An RTF field to enter a description of the priority.
* **Recommendation (optional)**: An RTF field to enter a recommendation for remediating the priority. A recommendation is the ideal advice or guidance to address a particular issue or concern. It suggests a best practice or a course of action to help prevent or mitigate security risks.
* **Remediation**: An RTF field to enter a remediation of the priority.&#x20;
* **Tags**: Enter any tags associated with the client (new or existing). Any special characters will be removed, and any spaces will be replaced with an underscore (\_).

<mark style="background-color:yellow;">Step 4:</mark> Click **Link assets.**

The information entered is presented on the priority details page.&#x20;

<div align="left"><figure><img src="/files/P8ux6d7kEEimAHEOvwnf" alt=""><figcaption></figcaption></figure></div>


# Linking Findings and Assets

After creating a priority, findings and assets can be associated with the **Priorities** module.

{% hint style="info" %}
Findings and assets can also be linked to a priority from the **Clients** module using bulk actions.
{% endhint %}

## Linking Findings

<mark style="background-color:yellow;">Step 1:</mark> From the **Priorities** module home page, click the row or **View** under the "Actions" column of the priority to update.&#x20;

<div align="left"><figure><img src="/files/H3cpvYOdobz4xXLryo3e" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Click the **Findings** tab.

<div align="left"><figure><img src="/files/mFVSLBzDo3qJvEag0ulc" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Click **Link Findings**.

<div align="left"><figure><img src="/files/hagOzTaQaAgmKgvP6hFZ" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4:</mark> Use the filters on the left nav bar to reduce the list.

<div align="left"><figure><img src="/files/gudTpwKH9XJQcUi6L9i8" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 5:</mark> Select the findings to link. Click **Continue with X findings**.

<div align="left"><figure><img src="/files/AYbQ9aRBirdfona1eGRT" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 6:</mark> Select any affected assets to link. Use the assets filters to narrow the search results. Click **Link affected asset** or **Continue without assets**.

<div align="left"><figure><img src="/files/KtdsqAWMRDklh5ctZeL5" alt="" width="563"><figcaption></figcaption></figure></div>

The user is returned to the **Findings** tab page. A notification confirms the action, and the page refreshes with the recently added findings.&#x20;

<div align="left"><figure><img src="/files/zTChMa5FzZwkb3xKpeEH" alt="" width="563"><figcaption></figcaption></figure></div>

Any affected assets added will be displayed on the **Assets** tab.

## Linking Assets

<mark style="background-color:yellow;">Step 1:</mark> From the **Priorities** module home page, click the row or **View** under the "Actions" column of the priority to update.&#x20;

<div align="left"><figure><img src="/files/QXGKbTwVFLT0c4ysXQVa" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Click the **Assets** tab.

<div align="left"><figure><img src="/files/mZciwsrJpk5E6LGs9YsO" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Click **Link Assets**.

<div align="left"><figure><img src="/files/GBtNtXJuUe3qGLmpyxMA" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4:</mark> Use the filters so that the list only shows assets relevant to the priority.

<div align="left"><figure><img src="/files/Dl1ccOpLWM5BBziJIcIl" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 5:</mark> Select the assets to link. Click **Continue with X assets**.

<div align="left"><figure><img src="/files/Bh2BqCnmsfm9Cd2198he" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 6:</mark> Select any associated findings to link. Use the findings filters to narrow the search results. Click **Link x associated findings** or **Continue without findings**.

<div align="left"><figure><img src="/files/7s3uVmACoBo3x4jxwucE" alt="" width="563"><figcaption></figcaption></figure></div>

The user is returned to the **Assets** tab page. A notification will appear confirming the action, and the page will refresh with the recently added assets appearing.

## Unliking Findings and Assets

Findings and assets included in a priority can be removed individually or via bulk actions. Any findings or assets removed from a priority will remain in their existing reports and not be deleted from PlexTrac.&#x20;

{% hint style="info" %}
Any assets associated with a finding will remain in the priority after the finding is unlinked, and any findings added via its association with an asset will remain after an asset is unlinked.&#x20;
{% endhint %}

### Unlinking a Finding

<mark style="background-color:yellow;">Step 1</mark>: Click the **Findings** tab from the priority details page.

<div align="left"><figure><img src="/files/vDBrLV0zMHu5fAFtLorW" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2a</mark>: Click the meatballs menu of the priority and click **Unlink finding from priority**.

<div align="left"><figure><img src="/files/gnVhygKoIBDH3bsM2MYD" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2b</mark>: Select multiple findings, click the Actions button, and click **Unlink findings from priority**.

<div align="left"><figure><img src="/files/1tavZHmXlTXHfwgbo8NQ" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3</mark>: A dialog box will appear asking for confirmation. Click **Unlink**.&#x20;

<div align="left"><figure><img src="/files/7EfKVg8Wr6uoZAcHJw8f" alt="" width="362"><figcaption></figcaption></figure></div>

### Unlinking an Asset

<mark style="background-color:yellow;">Step 1</mark>: Click the **Assets** tab from the priority details page.

<div align="left"><figure><img src="/files/6YQRS0kApTVSq3jLRUH1" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2a</mark>: Click the meatballs menu of the priority and click **Unlink asset from priority**.

<div align="left"><figure><img src="/files/l58W9VSkycVCCbeyXWaq" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2b</mark>: Select multiple findings, click the Actions button, and click **Unlink assets from priority**.

<div align="left"><figure><img src="/files/N9qq8Hd3fJ3IR1GWHRsq" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3</mark>: A dialog box will appear asking for confirmation. Click **Unlink**.&#x20;

<div align="left"><figure><img src="/files/cWNrXa0H3QDWDNmocOy5" alt="" width="358"><figcaption></figcaption></figure></div>


# Managing Priorities

## Updating Progress

The progress meter for a priority can be viewed on the **Priorities** home page (if the table is configured to display the field) or on the **Details** tab of a priority. The value shows 0% when the priority is created and progress is updated manually.&#x20;

To edit the progress value, perform the following steps:

<mark style="background-color:yellow;">Step 1:</mark> Click **Update progress** from the **Details** tab of a priority.

<div align="left"><figure><img src="/files/LhjlCwoghBzdR4vj1Cww" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Select the desired value on the scale with the cursor in increments of ten.

<div align="left"><figure><img src="/files/Q6XTOFURIRLlC7gy1QXz" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Click **Update**.

<div align="left"><figure><img src="/files/HMTAj6oTCH5wJYwYKN2z" alt="" width="563"><figcaption></figcaption></figure></div>

The updated value now appears on the Details tab page.

## Updating the Score

The priority score is viewed on the Priorities home page and the **Details** tab of a priority.

<div align="left"><figure><img src="/files/Fpe7NKnSqK7tbnEHfTam" alt="" width="563"><figcaption></figcaption></figure></div>

It can be updated by clicking **Update Score** under the meatballs menu.

<div align="left"><figure><img src="/files/nIOSVS0HLWnOy8mFM30Z" alt="" width="563"><figcaption></figcaption></figure></div>

## Updating Status

The priority status is viewed on the Priorities home page and the **Details** tab of a priority.&#x20;

<div align="left"><figure><img src="/files/kZwxyU2ucFu2IBryISKK" alt="" width="563"><figcaption></figcaption></figure></div>

Status can be updated via bulk actions, but to update for one priority, perform the following steps:

<mark style="background-color:yellow;">Step 1:</mark> Click the priority status flag on the Priorities home page (or click the priority status flag displayed on the **Details** page).

<div align="left"><figure><img src="/files/97J1QwH50vgEFgtpRla3" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Select the desired status indicator from the pulldown menu.

<div align="left"><figure><img src="/files/DH4EqOUkGzQJYWZ0f7Rt" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Click **Update status**.

<div align="left"><figure><img src="/files/SmSV1RPN8GhNvhPa87bk" alt="" width="563"><figcaption></figcaption></figure></div>

A notification confirms the action.

## Editing Fields

Existing priorities can be updated in two ways:

<mark style="background-color:yellow;">Step 1a</mark>: From the Priorities home page, click **Edit priority** under the meatballs menu.

<div align="left"><figure><img src="/files/NKVUxWLiOvUYBxdiSIGG" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 1b</mark>: From the **Details** tab of a priority, click **Edit priority**.

<div align="left"><figure><img src="/files/DZeWrjocv4u4hBjfpCR8" alt="" width="563"><figcaption></figcaption></figure></div>

All fields that were available when the priority was created can now be edited.&#x20;

<mark style="background-color:yellow;">Step 2</mark>: Click **Save** when finished.&#x20;

## Bulk Actions

Bulk action options appear after one or more priorities are selected by clicking the checkbox to the far left of the Priority title field or by clicking the box next to the column header.&#x20;

Click **Actions** to see the list of options.


# Priorities Metrics

The **Metrics** tab in the Priorities module provides a comprehensive overview and management system for priorities. It aims to give security teams a centralized place to track priority remediation efforts and related findings and assets.

Users can filter by various criteria, utilize charts for in-depth analysis, and gain insights into top findings, asset tags, and severity breakdowns.

This page is available by clicking **Metrics** from the Priorities home page.

<div align="left"><figure><img src="/files/IwSqtJb0OhT5ysbqmMOc" alt="" width="563"><figcaption></figcaption></figure></div>

## Overview

The page is divided into multiple sections to help users quickly navigate and access the information. The modular layout ensures that each topic is self-contained, allowing users to find relevant details more efficiently.

<div align="left"><figure><img src="/files/MAA0HpkMNZkQQHiJAkvx" alt="" width="563"><figcaption></figcaption></figure></div>

## Managing Charts

The fields in a graph can be removed or added by clicking the field name above the chart. When removed, the field is shown in grey, and the data for that field is removed from the chart.

{% hint style="info" %}
Although the field is removed for display purposes, it does not change the overall calculation of the metrics.
{% endhint %}

<div align="left"><figure><img src="/files/140mh5Zzl2O6KDNlhXPr" alt="" width="563"><figcaption></figcaption></figure></div>

Click a field that is greyed out to add it back.&#x20;

When applicable, a box provides a bar or pie chart of priorities by status and score. In the upper right-hand corner, click the option to toggle between the two views.

<div align="left"><figure><img src="/files/CQgMGNToJah1pwgTlGFm" alt="" width="442"><figcaption></figcaption></figure></div>

Some graphics provide more details by hovering over the image with the cursor.

<div align="left"><figure><img src="/files/vEndaLw2M3wDqk4RLvxj" alt="" width="400"><figcaption></figcaption></figure></div>

Clicking results (when available) within a graphic launches a side drawer with more information about the prioritized items.

<div align="left"><figure><img src="/files/TSMbdDV1riEazgPOUTRN" alt="" width="563"><figcaption></figcaption></figure></div>

## Filters

This section enables filtering of priority metrics displayed to the client by date range, severity, owner, tags, and status.

{% hint style="info" %}
The URLs within the Metrics tab will contain the filters used and shared with other users.
{% endhint %}

<div align="left"><figure><img src="/files/s1610Q6bvsXbSYwVKCnE" alt="" width="563"><figcaption></figcaption></figure></div>

## Priorities Health Indicator

This section displays key priority metrics.&#x20;

<div align="left"><figure><img src="/files/k9xRH5vqnrTqojVrAhGf" alt="" width="563"><figcaption></figcaption></figure></div>

Click a box to view more detailed information about each metric (all boxes will open a side drawer except the "Percentage of linked findings to priorities" box).&#x20;

<div align="left"><figure><img src="/files/nIPDb3hjouPIkJEAagU5" alt="" width="563"><figcaption></figcaption></figure></div>

Clicking the priority listed in the side drawer will open the Priority Detail side drawer for further investigation.&#x20;


# Content Library

The **Content Library** menu provides access to repositories for narratives, writeups and runbooks. These repositories allow users to create, manage, and reuse content across the platform when generating reports or findings.

Users access it by clicking **Content Library** in the application's main menu.

<div align="left"><figure><img src="/files/lajZUnjpR5hhMbVjmim1" alt=""><figcaption></figcaption></figure></div>

## Overview

The Content Library repositories offer numerous advantages:

* **Reusability**: Users can create and access reusable items such as writeups and narrative sections. Instead of recreating content from scratch, users can leverage existing content, saving time and effort.
* **Standardization and Consistency**: The Content Library promotes standardization and consistency by organizing reusable content within repositories. Users can load and access predefined repositories and templates.
* **Efficiency**: Users can quickly locate and retrieve relevant content, streamlining the report creation process and improving overall efficiency.
* **Collaboration**: The Content Library is designed to promote collaboration and knowledge sharing. It allows users to designate repositories for multiple individuals to access and contribute.
* **Scalability**: As the Content Library accumulates reusable items, it becomes a valuable resource that grows with the organization's needs. New users can leverage existing content, maintaining consistency even as the user base expands.
* **Customization**: Users can create repositories, set permissions for viewing and editing, organize content within repositories, establish templates, customize layout, add tags or metadata, and integrate with external tools.&#x20;


# Types of Repositories

&#x20;In the Content Library, three types of repositories exist:&#x20;

1. **Open Repository**: Open repositories are available to anyone with repository access. Users with permission can *view* and *edit* the content within this repository. Open repositories are created for easy access and collaboration, allowing users to contribute and modify content freely. They serve as a shared space.
2. **Managed Repository**: Managed repositories are accessible to anyone with repository access, allowing them to *view* the repository content. Editors must be added manually. Managed repositories are suitable for creating shared spaces where multiple users can access and utilize the content but have limited editing capabilities.
3. **Private Repository**: Private repositories are the most restricted. Only added users with specific permissions can view and edit the content within private repositories. Private repositories are ideal for in-process documents or content that should only be accessible to select individuals.

<div align="left"><figure><img src="/files/uuwGOvrYeYSYahO1fj7m" alt=""><figcaption><p>Content Library Repository Types</p></figcaption></figure></div>

Users' level of access and editing permissions should be considered when selecting a repository type.&#x20;

Managed repositories allow for broader access with limited editing capabilities, private repositories restrict access to authorized individuals, and open repositories provide an open and collaborative environment for content sharing and editing.

<div align="left"><figure><img src="/files/WXZm18IzoSsNOTMUHbh4" alt="" width="563"><figcaption></figcaption></figure></div>

## Open Repository

**Definition**: A “Dropbox” to which any user with feature-level access may contribute content.&#x20;

**Default behavior**: None

**Recommended Use**: To enable all users to contribute without restriction.

## Managed Repository

**Definition**: Users can view, but only those added to a given repository as an editor and have an RBAC of `MANAGE_{content}_REPOSITORIES` under Content Library permissions may add or edit content.&#x20;

**Default behavior**: View-only access unless an editor is added to enable modification of content or the user has appropriate RBAC permissions.

**Recommended Use**: To restrict edit access to qualified individuals (copy editors) within a defined set of narrative sections. This is ideal for teams working on various projects who want to maintain their versions of narrative sections and small to mid-size teams that don’t need to restrict access to use but want to limit curation to leadership.

## Private Repository

**Definition**: A repository to store narrative sections is unavailable unless a user is explicitly given read and edit permissions.

**Default behavior**: Users may view only (Viewer) or edit (Editor).

**Recommended Use**: This is a place to copy manually created sections that may contain client-specific data that needs to be sanitized, a place to work on drafts for new narrative sections not ready for general use, or a place to store final narrative sections not available for general use.


# NarrativesDB

**NarrativesDB** is a repository that houses all of PlexTrac's narrative sections. Its primary purpose is facilitating categorization, association with defined use cases, and reusability.&#x20;

Users access by clicking **Content Library** in the application's main menu and then clicking **NarrativesDB**.

<div align="left"><figure><img src="/files/6YQsOj3L08rn8ShkySFX" alt=""><figcaption></figcaption></figure></div>

## Overview

Reports use narratives to provide context, clarify complex information, and improve comprehension. These narratives also serve as persuasive tools, influencing opinions and motivating action through storytelling. By placing data and facts into real-life contexts, narratives help audiences understand the relevance of information, making them versatile and impactful tools. As a result, narratives are valuable assets in reports and promote effective communication.

NarrativesDB enables users to create and manage this messaging, freeing up time for problem-solving.

For example, instead of initiating each report from scratch and composing a unique narrative every time, organizations have the flexibility to create simple sections that serve as a starting point. These sections can be reused or further enhanced to align with the specific needs of each report, providing a time-saving and efficient solution for report generation.<br>


# NarrativesDB Home Page

The NarrativesDB home page consists of two tabs:

* **Repositories**: A centralized location where all sections can be stored and managed.
* **Sections**: A dedicated space to create reusable content for narrative sections within a report.

<div align="left"><figure><img src="/files/PfAlPEcRyPz3EwGl0NnC" alt="" width="563"><figcaption></figcaption></figure></div>

## Repositories Tab

PlexTrac provides a sample narratives repository containing six sample narrative sections to demonstrate how content reuse might exist.&#x20;

The sample repository is an [Open repository](/plextrac-documentation/product-documentation/content-library/types-of-repositories#types-of-repositories) that cannot be deleted but can be modified.

## Sections Tab

Sections are containers that contain a title, body, and tags. They are reusable in reports and are stored in this tab.

<div align="left"><figure><img src="/files/qz8XhQz3pOj4nydasz6T" alt="" width="563"><figcaption></figcaption></figure></div>

### Configuring Views

The table view can be customized by clicking the column view icon to the right of the search bar.

Once clicked, a modal appears that lists all fields. To remove a column, click **X** within the bar.

<figure><img src="/files/tFxVB3LWNUrccOAAoozE" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Fields that are required do not have an **X** available.
{% endhint %}

When fields are removed, an "Add Column" pulldown menu is added at the bottom left of the modal to store the field. Any removed fields can be added later by clicking **Add Column** and selecting the field to add. &#x20;

<figure><img src="/files/8IKqamQYvook9sD6qt3d" alt=""><figcaption></figcaption></figure>

This modal represents the sequence of fields provided in the table, meaning the bar on top will be the column on the table's far left.&#x20;

The order of columns can be adjusted within this modal by clicking the six dots on the left of the bar for a field and dragging the bar to the desired sequence place.

<div align="left"><figure><img src="/files/p1YN67zUU3ckmVJGeLGt" alt=""><figcaption></figcaption></figure></div>

Click **Save** when finished.&#x20;


# Managing Repositories

## Changing Settings

Admins can modify the repository name, prefix, description and access setting.

<mark style="background-color:yellow;">Step 1</mark>: From the **Repositories** tab of the **NarrativesDB** home page, click the card of the repository to modify.

<div align="left"><figure><img src="/files/0Dfz0felKIWyDoecDfiX" alt=""><figcaption></figcaption></figure></div>

&#x20;<mark style="background-color:yellow;">Step 2</mark>: Click **Repository Settings**.&#x20;

<div align="left"><figure><img src="/files/0LU7uVmq4ZUsNApZ3Wjm" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3</mark>: Click **Update**.

<div align="left"><figure><img src="/files/ZIY9m2xR9rAgQJJr6v40" alt=""><figcaption></figcaption></figure></div>

## Copying a Repository

<mark style="background-color:yellow;">Step 1:</mark> From the **Repositories** tab of the **NarrativesDB** module, click the three dots in a repository card and click **Copy Repository**.

<div align="left"><figure><img src="/files/rl0VXIenCcpM2Bhm5YoI" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Update the repository name, add a section ID, and validate access permissions. Click **Copy**.

<div align="left"><figure><img src="/files/5hgqUpWUTWxeCYL0bFhX" alt=""><figcaption></figcaption></figure></div>

The new repository is created and listed on the **Repositories** tab.&#x20;

<div align="left"><figure><img src="/files/ByoM0OjWSwuD8FcHlS0w" alt=""><figcaption></figcaption></figure></div>

## Deleting a Repository

{% hint style="danger" %}
This action will permanently delete the repository and all its sections for all users.&#x20;
{% endhint %}

Admins can delete a repository in two ways:

Click the three dots in a repository card from the **NarrativesDB** home page, then click **Delete Retory**.

<div align="left"><figure><img src="/files/ybblEos4eu5RCw1XuGKd" alt=""><figcaption></figcaption></figure></div>

or

Go to the repository settings and click **Delete Repository**.

<div align="left"><figure><img src="/files/e8KBsLZVSNUJkAAPpbvl" alt=""><figcaption></figcaption></figure></div>

## Configuring Views

The table view can be customized by clicking the column view icon to the right of the search bar.

<figure><img src="/files/E1xKQ8pSxqHFESES1Avm" alt=""><figcaption></figcaption></figure>

Once clicked, a modal appears that lists all fields. To remove a column, click **X** within the bar.

<figure><img src="/files/tFxVB3LWNUrccOAAoozE" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Fields that are required do not have an **X** available.
{% endhint %}

When fields are removed, an "Add Column" pulldown menu is added at the bottom left of the modal to store the field. Any removed fields can be added later by clicking **Add Column** and selecting the field to add. &#x20;

<figure><img src="/files/8IKqamQYvook9sD6qt3d" alt=""><figcaption></figcaption></figure>

This modal represents the sequence of fields provided in the table, meaning the bar on top will be the column on the table's far left.&#x20;

The order of columns can be adjusted within this modal by clicking the six dots on the left of the bar for a field and dragging the bar to the desired sequence place.

<div align="left"><figure><img src="/files/uj9tatDsSCcMCvdX0Ey1" alt=""><figcaption></figcaption></figure></div>

Click **Save** when finished.&#x20;


# Managing Users

If the repository is not an "Open" type repository, admins have the option of managing users by clicking **Users & Permissions**.

## Adding Users

<mark style="background-color:yellow;">Step 1</mark>: From the **Repositories** tab of the **NarrativesDB** home page, click the card of the repository to modify.

<div align="left"><figure><img src="/files/0Dfz0felKIWyDoecDfiX" alt=""><figcaption></figcaption></figure></div>

&#x20;<mark style="background-color:yellow;">Step 2</mark>: Click **Users & Permissions**.&#x20;

<div align="left"><figure><img src="/files/rLsHeOaP108AMr7ZJNAr" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Click **Add User**.

<div align="left"><figure><img src="/files/8BPSwTyiKEwqqKDnj7yG" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4:</mark> Type in the user from the pulldown menu and select the permission. Repeat as necessary. Click **Add X Users**.&#x20;

<div align="left"><figure><img src="/files/aMpUHNolsu9ujzIYgShf" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 5:</mark> Edit the permission or delete a user, if needed. Click **Done**.

<div align="left"><figure><img src="/files/dNVPECSXyi7H0mQ56NUe" alt=""><figcaption></figcaption></figure></div>

## Deleting Users

<mark style="background-color:yellow;">Step 1</mark>: From the **Repositories** tab of the **NarrativesDB** home page, click the card of the repository to modify.

<div align="left"><figure><img src="/files/0Dfz0felKIWyDoecDfiX" alt=""><figcaption></figcaption></figure></div>

&#x20;<mark style="background-color:yellow;">Step 2</mark>: Click **Users & Permissions**.&#x20;

<div align="left"><figure><img src="/files/rLsHeOaP108AMr7ZJNAr" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Identify the user to remove and click the **X** in that row.

<div align="left"><figure><img src="/files/wkMp6yUY5CHQ880JWyUe" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4:</mark> Click **Done**.


# Creating a Repository

<mark style="background-color:yellow;">Step 1:</mark> From the **Repositories** tab of the **NarrativesDB** module, click **New Repository**.

<div align="left"><figure><img src="/files/yBEaXKOgPG40RzlxZoCV" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Enter information in the fields (a red asterisk marks required fields), select the desired security access for the repository, and click **Create**.

{% hint style="info" %}
The Section ID Prefix value informs the future relationship of all sections created within the repository to a specific repository. Once assigned to a particular repository with the prefix, sections will automatically increment as they are added.
{% endhint %}

<div align="left"><figure><img src="/files/jmjgECrX2nrhXzOc8vkm" alt=""><figcaption></figcaption></figure></div>

The new repository is now listed on the **Repositories** tab.

<div align="left"><figure><img src="/files/XgdP3wUw8y1qttCYbnSy" alt="" width="563"><figcaption></figcaption></figure></div>


# Managing Sections

NarrativesDB comes with six sections that are part of the sample repository. These sections can be modified, copied to another repository, or deleted.

{% hint style="info" %}
Narrative sections can be created/edited but not copied from an external source. They can be added *to* a report from NarrativesDB but not *from* a report to NarrativesDB.
{% endhint %}

## Editing a Section

<mark style="background-color:yellow;">Step 1:</mark> From the **Repositories** tab of the **NarrativesDB** module, click **Sections**.&#x20;

<div align="left"><figure><img src="/files/OtYVYon1HMZizVJq1iTe" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Navigate to the desired section to update and click **Edit**.

<div align="left"><figure><img src="/files/Rx8UDn5Dw8Ryfmumi4SH" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Make desired edits to the section. Click **Close** when finished.&#x20;

<div align="left"><figure><img src="/files/0EVjpPr7hbxKrs82W6xe" alt=""><figcaption></figcaption></figure></div>

{% hint style="info" %}
All changes are saved dynamically.
{% endhint %}

## Copying a Section

<mark style="background-color:yellow;">Step 1:</mark> From the **Repositories** tab of the **NarrativesDB** module, click **Sections**.&#x20;

<div align="left"><figure><img src="/files/OtYVYon1HMZizVJq1iTe" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Navigate to the desired section to update and click **Copy To**.

<div align="left"><figure><img src="/files/OIX8PUZLzMLAmDIOsofU" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Select the repository to copy the section from the pulldown menu.

<div align="left"><figure><img src="/files/iUNB7zyYpawnopCfcg9H" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4:</mark> Click **Copy**.

<div align="left"><figure><img src="/files/OIuxPqOnlXjhr1YV0617" alt=""><figcaption></figcaption></figure></div>

A notification confirms the action was successful, and the copied section now appears in the new repository.

## Deleting a Section

{% hint style="warning" %}
Completing this task permanently deletes the section and cannot be undone.&#x20;
{% endhint %}

<mark style="background-color:yellow;">Step 1:</mark> From the **Repositories** tab of the **NarrativesDB** module, click **Sections**.&#x20;

<div align="left"><figure><img src="/files/OtYVYon1HMZizVJq1iTe" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Click the three dots under the "Actions" column, then click **Delete**.&#x20;

<div align="left"><figure><img src="/files/SyLRWnJ2MdniQWpjTJBF" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> A modal will appear, confirming the action. Click **Delete Section**.&#x20;

<div align="left"><figure><img src="/files/k54RQQ06gPSyYgwQ8x5F" alt=""><figcaption></figcaption></figure></div>

## Bulk Actions

When editing multiple sections, PlexTrac offers bulk action capabilities. Bulk actions provide several advantages, including time-saving and increased efficiency by processing numerous items simultaneously.

Bulk action options appear after selecting one or more sections by clicking the checkbox or the box next to the column header.&#x20;

<div align="left"><figure><img src="/files/9tp39pX7bp1QurzhYUvK" alt=""><figcaption></figcaption></figure></div>

Click **Actions** to see the list of options available.

## Configuring Table View <a href="#configuring-table-view-2" id="configuring-table-view-2"></a>

The table view can be customized by clicking the column view icon to the right of the search bar.

<div align="left"><figure><img src="/files/u20cpNeg9qa0ZUFqoUbG" alt=""><figcaption></figcaption></figure></div>

Once clicked, a modal appears that lists all fields. To remove a column, click **X** within the bar.

Fields that are required do not have an **X** available.

When fields are removed, an "Add Column" pulldown menu is added at the bottom left of the modal to store the field. Any removed fields can be added later by clicking **Add Column** and selecting the field to add.

This modal also represents the sequence of fields provided in the table, meaning the bar on top will be the column on the table's far left.

The order of columns can be adjusted within this modal by clicking the six dots on the left of the bar for a field and dragging the bar to the desired sequence place.

<div align="left"><figure><img src="/files/Nye16e5YSBM6JieFepRT" alt=""><figcaption></figcaption></figure></div>

Click **Save** when finished.


# Creating a Section

## Creating a Section

<mark style="background-color:yellow;">Step 1:</mark> From the **Repositories** tab of the **NarrativesDB** module, click **Sections**.&#x20;

<div align="left"><figure><img src="/files/OtYVYon1HMZizVJq1iTe" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Click **New Section**.

<div align="left"><figure><img src="/files/IvFtpAXqkSFfDYoO6zbM" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Enter desired information (required fields are marked with a red asterisk).&#x20;

<div align="left"><figure><img src="/files/znaHwc0SaSYImNUdwiqO" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4:</mark> Click **Close**.

## &#x20;<a href="#configuring-table-view-2" id="configuring-table-view-2"></a>


# WriteupsDB

**WriteupsDB** is a central repository for all the writeups available in PlexTrac. Its purpose is to categorize them, associate them with specific use cases, and facilitate reuse. By structuring and refining the findings, writeups can be seamlessly incorporated into other deliverables, such as a report.&#x20;

Users access by clicking **Content Library** in the application's main menu and then clicking **WriteupsDB**.

<div align="left"><figure><img src="/files/KoP73EoVqT2JgMlZlN5a" alt=""><figcaption></figcaption></figure></div>

## Overview

WriteupsDB serves as a valuable tool for tracking and organizing vulnerability information. Benefits of WriteupsDB include:

* **Enhanced Organization and Access:** WriteupsDB provides a centralized database where items can be added or imported, making it effortless to organize and access information related to vulnerabilities. This centralized approach improves efficiency and streamlines tracking and documenting vulnerabilities.
* **Improved Permissions and Segregation**: With the introduction of repositories, PlexTrac offers improved permissions and segregation capabilities. Instead of managing writeups as a list, users can create repositories to categorize and segregate writeups based on different contexts, such as incident response or vulnerability management. This feature ensures that the right users have the appropriate level of access in their specific domains and can work without interference from unrelated teams.
* **Standardization and Collaboration:** WriteupsDB enables the standardization of vulnerability documentation by encouraging and reusing templates. This ensures consistency in the format and language, making it easier for stakeholders to understand and analyze vulnerabilities. The platform also supports collaboration, allowing multiple users to work on writeups simultaneously and facilitating peer reviews for improved quality and accuracy.&#x20;


# WriteupsDB Home Page

The **WriteUpsDB** module has two tabs:

* **Repositories**: Displays all writeup repositories that exist in a tenancy. A repository can be [Open, Managed, or Private](/plextrac-documentation/product-documentation/content-library/types-of-repositories).&#x20;
* **Writeups**: Displays all writeups in various repositories, including those created manually and imported. &#x20;

## Repositories Tab

PlexTrac provides a default repository container for any existing writeups. This repository can be renamed, modified, and deleted.

<div align="left"><img src="/files/yQnV3b7f3dd5U4ypMO9l" alt="" width="329"></div>

Once added, any extra repositories will be displayed on the page alphabetically according to their title.

<div align="left"><figure><img src="/files/tAQ9sJAqVv79WZYZLkSY" alt="" width="563"><figcaption></figcaption></figure></div>

Each repository card provides the following information:&#x20;

<div align="left"><figure><img src="/files/Bf26ZRTVOC4jAsAvTAL0" alt=""><figcaption></figcaption></figure></div>

1. **Repository Title**
2. **Repository Type**: Open, Managed, or Private
3. **Meatballs Menu**: options to copy or delete the repository
4. **Repository Description**
5. **Number of contained writeups**&#x20;
6. **Number of added users**&#x20;

## Writeups Tab

Click the **Writeups** tab to view all writeups for a tenancy. This view will display helpful information such as the writeup ID, parent repository, writeup severity, source, assigned tags, and the ability to edit, copy, or delete any selected writeup.

<div align="left"><figure><img src="/files/fwSKgLqiefgUlPEIW1vO" alt="" width="563"><figcaption></figcaption></figure></div>

### Bulk Actions

When editing multiple reports, PlexTrac offers bulk action capabilities. Bulk actions provide several advantages, including time-saving and increased efficiency by processing numerous items simultaneously.

Bulk action options appear after one or more writeups are selected by clicking the checkbox to the far left of the Title field or by clicking the box next to the column header.&#x20;

<div align="left"><figure><img src="/files/SPH97dftePJIG8mXiA3w" alt="" width="563"><figcaption></figcaption></figure></div>

Click **Actions** to see the list of options.

<div align="left"><figure><img src="/files/DbMeNnQoRQ3PFhZyKDGI" alt="" width="263"><figcaption></figcaption></figure></div>

### Configuring Views

The table view can be customized by clicking the column view icon to the right of the search bar.

<div align="left"><figure><img src="/files/n4sTmBUubco9Ul2H1AC5" alt=""><figcaption></figcaption></figure></div>

Once clicked, a modal appears that lists all fields. To remove a column, click **X** within the bar.

<div align="left"><figure><img src="/files/2aixTJITa2LgZItoVi4B" alt="" width="563"><figcaption></figcaption></figure></div>

{% hint style="info" %}
Fields that are required do not have an **X** available.
{% endhint %}

When fields are removed, an "Add Column" pulldown menu is added at the bottom left of the modal to store the field. Any removed fields can be added later by clicking **Add Column** and selecting the field to add. &#x20;

<div align="left"><figure><img src="/files/mrrPcGXNLEV7wmJ372GK" alt=""><figcaption></figcaption></figure></div>

This modal represents the sequence of fields provided in the table, meaning the bar on top will be the column on the table's far left.&#x20;

The order of columns can be adjusted within this modal by clicking the six dots on the left of the bar for a field and dragging the bar to the desired sequence place.

<div align="left"><figure><img src="/files/9NG7kZ9cgeVwnqCEX8gZ" alt=""><figcaption></figcaption></figure></div>

Click **Save** when finished.&#x20;


# Managing Repositories

A repository is a versatile tool for managing writeups. It organizes content into structured categories, allowing for efficient reuse across reports. Repositories grant varying access permissions, enhancing collaboration and control.

## Changing Settings

<mark style="background-color:yellow;">Step 1:</mark> From the **WriteupsDB** module home page, click the repository to update.

<div align="left"><figure><img src="/files/P70XSItzrBhqssfM3AHr" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Click **Repository Settings.**&#x20;

{% hint style="info" %}
If the repository is not an "Open" type repository, admins will also see a [**Users & Permissions**](/plextrac-documentation/product-documentation/content-library/writeupsdb/managing-users) link next to the settings option.&#x20;
{% endhint %}

<div align="left"><figure><img src="/files/T1GnxY6wKR1zwssMjfZi" alt="" width="540"><figcaption></figcaption></figure></div>

All fields that existed when creating the repository are available for editing, with an additional button to delete the repository.

<div align="left"><figure><img src="/files/3RkO6o240vbPNQB9Nwkt" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Click **Submit** when finished.

## Copying a Repository

<mark style="background-color:yellow;">Step 1:</mark> From the **Repositories** tab of the **WriteupsDB** module, click the meatballs menu found on the repository card to copy.

<div align="left"><figure><img src="/files/w6Ry3cTXpdwl4PYq5Rs1" alt="" width="295"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Click **Copy Repository**.

<div align="left"><figure><img src="/files/6Vih6xSnF8BN8yA2XFmc" alt="" width="343"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Change the repository name, add a section ID, update the description as needed, and validate access permissions. Click **Save**.

<div align="left"><figure><img src="/files/lpCwi0Tm4nhWgCGRv8hx" alt="" width="563"><figcaption></figcaption></figure></div>

The new repository has been created and is listed on the **Repositories** tab.&#x20;

## Deleting a Repository

{% hint style="danger" %}
This action will delete the repository and all its writeups for all users.&#x20;
{% endhint %}

A repository can be deleted in two ways:

1. Click the meatballs menu on the repository card from the **Repositories** tab of the WriteupsDB module. Then, click the meatballs menu again in the repository card and click **Delete Repository**.\
   ![](/files/hCzT5sya2YSpDkC2fNnF)
2. Click the meatballs menu on the repository card from the **Repositories** tab of the WriteupsDB module. Select **Repository Settings**, then scroll to the bottom and click **Delete Repository**.\
   ![](/files/GLB1vKg9s49Lfw9SDMlq)

A warning message will appear asking for validation. Click **Delete** to continue.&#x20;

<div align="left"><figure><img src="/files/bUsqCQW3YvjzEsAeh98x" alt="" width="330"><figcaption></figcaption></figure></div>


# Managing Users

If the repository is not an "Open" type repository, admins can manage users by clicking Users & Permissions.

## Adding Users

<mark style="background-color:yellow;">Step 1:</mark> From the **Repositories** tab of the **WriteupsDB** home page, click the card of the repository to modify.

<div align="left"><figure><img src="/files/Ha8fi9BONF01Zaw7Dx2H" alt="" width="563"><figcaption></figcaption></figure></div>

&#x20;<mark style="background-color:yellow;">Step 2</mark>: Click **Users & Permissions**.&#x20;

<div align="left"><figure><img src="/files/pHgKVF0s41pB8yB121j5" alt="" width="452"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Click **Add User**.

<div align="left"><figure><img src="/files/JwxFBwfu8Gk7IWLe6P1Z" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4:</mark> Type in the user from the pulldown menu and select the permission. Repeat as necessary. Click **Add X Users**.&#x20;

<div align="left"><figure><img src="/files/aMpUHNolsu9ujzIYgShf" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 5:</mark> Edit the permission or delete a user, if needed. Click **Done**.

<div align="left"><figure><img src="/files/dNVPECSXyi7H0mQ56NUe" alt="" width="563"><figcaption></figcaption></figure></div>

## Modifying Users

<mark style="background-color:yellow;">Step 1:</mark> Select the desired repository card from the **WriteupsDB** home page and click **Users & Permissions**.

<div align="left"><figure><img src="/files/JCcZ3RI4RwrT1cSW5rqa" alt="" width="452"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Select the user to modify and change permissions from the pulldown menu.

<div align="left"><figure><img src="/files/6wv9JH5PAgq4iDDuRAeb" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> When finished, click **Done**.&#x20;

## Deleting Users

<mark style="background-color:yellow;">Step 1:</mark> Select the desired repository card from the **WriteupsDB** home page and click **Users & Permissions**.

<div align="left"><figure><img src="/files/Zh9W8YF4RRPZzMnjHLow" alt="" width="452"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Select the user to remove and click the **X** in that row.

<div align="left"><figure><img src="/files/ApsiC9gJ0h677JpnP8df" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> When finished, click **Done**.&#x20;


# Creating a Repository

<mark style="background-color:yellow;">Step 1:</mark> From the **WriteupsDB** module home page, click **New Repository**.

<div align="left"><figure><img src="/files/ZtQdesNeIFmxi81jhTzG" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Fill out the provided fields.

<div align="left"><figure><img src="/files/TdMHiBFJmnKUl9VCAJZd" alt="" width="563"><figcaption></figcaption></figure></div>

1. **Repository Name**: Describes the repository and is displayed on the repository card from the **Repositories** tab.
2. **Writeup ID Prefix**: A three-character value that is unique to this repository. The Section ID Prefix value informs the future relationship of all sections created within the repository to a specific repository. Once assigned to a particular repository with the prefix, sections will automatically increment as they are added. An error message will display if the prefix already exists after clicking the **Create** button.<br>
3. **Description**: Describes the repository in 350 characters or less. The number of characters remaining in the description is presented at the bottom right of the box.<br>
4. **Repository Access**: Defines what [users and roles can access](/plextrac-documentation/product-documentation/content-library/types-of-repositories) the writeups in this repository.&#x20;

<mark style="background-color:yellow;">Step 3:</mark> Click **Create**.

<div align="left"><figure><img src="/files/Vim6k0e5DRtvltFojtx0" alt=""><figcaption></figcaption></figure></div>

A notification confirms the action and the repository will appear as a card on the **Repositories** tab.


# Creating a Writeup

The process of creating a writeup is similar to that of creating a finding.&#x20;

<mark style="background-color:yellow;">Step 1</mark>: From the **WriteupsDB** home page, click the **Writeups** tab.

<div align="left"><figure><img src="/files/ZHFCGYWDMWd3xdVXhhrF" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Click **New Writeup**.

<div align="left"><figure><img src="/files/SzndmfKBQT71pmPYvm1l" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> A modal will appear with the option to start from default finding fields or use a custom findings layout. Choose an option and click **Next**.

<div align="left"><figure><img src="/files/7TArflyxu2fyM5QhaH02" alt="" width="476"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4:</mark> Enter the writeup name and select the repository and severity. Click **Create**.

<div align="left"><figure><img src="/files/PBWQrHegLqY6ULQcjuCI" alt="" width="478"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 5:</mark> Enter the information in the provided fields on the "Create New Writeup" page. Required fields are denoted with a red asterisk.

{% hint style="info" %}
Visit the [Creating a Finding page](/plextrac-documentation/product-documentation/reports/findings/creating-a-finding) for documentation on the fields referenced below.
{% endhint %}

<div align="left"><figure><img src="/files/c7MXM6zZGESnuolMWBke" alt="" width="563"><figcaption></figcaption></figure></div>

New sections for the writeup can be added by clicking **Add new custom field** at the bottom of the page. There is no limit to the number of new sections that can be added. Any section can be deleted by clicking the **Remove** button.

<mark style="background-color:yellow;">Step 6:</mark> Click **Close** at the top of the page. All changes are autosaved.


# Copying a Writeup

Writeups can be copied within the **WriteupsDB** module or from a finding within a report.&#x20;

## Copying a Writeup Within a Report

<mark style="background-color:yellow;">Step 1:</mark> Within a report, click the **Findings** tab.

<div align="left"><figure><img src="/files/eNUFpnD0fnlv6PJJCqSp" alt="" width="554"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Find the finding to copy. Click the meatballs menu (three dots) under "Actions" and click **Copy to WriteupsDB**.

<div align="left"><figure><img src="/files/aPGYcm4sAASeufK2KEAK" alt="" width="479"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Select the repository from the pulldown menu and click **Copy.**

<div align="left"><figure><img src="/files/dIiO4lDNE9BBxeHSXj1K" alt="" width="365"><figcaption></figcaption></figure></div>

{% hint style="warning" %}
Finding details unique to this report will also be copied; remove any sensitive information.
{% endhint %}

## Copying within WriteupsDB

<mark style="background-color:yellow;">Step 1:</mark> From the **WriteupsDB** module, go to the writeup to copy and click **Copy To** under the "Actions" column.

<div align="left"><figure><img src="/files/8dmKA42lfC6AnoSCdud1" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Select the destination repository from the pulldown menu and click **Copy**.

<div align="left"><figure><img src="/files/lzXySQa2OpebwswMKGeb" alt="" width="400"><figcaption></figcaption></figure></div>


# Adding to a Report

<mark style="background-color:yellow;">Step 1:</mark> From a report, click the **Findings** tab.

<div align="left"><figure><img src="/files/Iw2uzw9FhpTesjEqkv9t" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Click **Add Findings** and select "From WriteupsDB" from the pulldown menu.

<div align="left"><figure><img src="/files/oQ04dFTKCJOArMMrHHnl" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Search for or use the provided pulldown filters to display the desired writeups(s) to add.

<div align="left"><figure><img src="/files/rrwEgUGAEUl33gTnDviq" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4:</mark> Click the box next to the writeup(s) to add. Selected writeups will appear in the "TO BE ADDED TO REPORT" column on the right. Click **Add X Writeups**.&#x20;

{% hint style="info" %}
Click the box next to "Writeups" in the table header to add all available writeups.
{% endhint %}

<div align="left"><figure><img src="/files/zqNX6tUFF3IJTWi7pjcf" alt="" width="563"><figcaption></figcaption></figure></div>

The selected writeups now appear on the **Findings** tab of the report.

{% hint style="info" %}
Once a writeup becomes a finding, it is a standalone object that is not impacted if the source writeup or repository is deleted or the same writeup added to another report is edited or deleted.
{% endhint %}


# Importing via CSV Template

PlexTrac provides a downloadable CSV file that can be used as a template for entering writeups offline and importing them into **WriteupsDB**.&#x20;

## Downloading the CSV Template

<mark style="background-color:yellow;">Step 1:</mark> From the **WriteupsDB** module, click the **Writeups** tab.

<div align="left"><figure><img src="/files/y9egC5MMeavpkAdrxMko" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Click **Import Writeups**.

<figure><img src="/files/fXwxW7B5D7Hey13hGQMR" alt=""><figcaption></figcaption></figure>

<mark style="background-color:yellow;">Step 3:</mark> Click **Download CSV template file**.

<div align="left"><figure><img src="/files/ZSQ74vIGecRuLyUTgjxz" alt="" width="563"><figcaption></figcaption></figure></div>

The file will be downloaded locally for editing.

{% hint style="warning" %}
Save the CSV template in UTF-8 format to prevent including non-UTF characters that may break the importer.
{% endhint %}

## Writeups CSV Field Mappings

When importing the CSV file, all fields below must appear as column headers and follow the rules defined in the table. Otherwise, the file may be rejected when imported or require further manual editing within PlexTrac.

{% hint style="warning" %}
**Title**, **description**, and **severity** are required.&#x20;
{% endhint %}

<table><thead><tr><th width="202">PlexTrac Field</th><th>CSV Header Label</th><th>Notes</th></tr></thead><tbody><tr><td>title</td><td>title</td><td>This is a required field.</td></tr><tr><td>severity</td><td>severity</td><td>This is a required field.<br><br>The severity value must be one of the following (not case-sensitive): <br>"Informational, Low, Medium, High, Critical"<br><br>If no value is provided in CSV, a value of "Informational" will be assigned.</td></tr><tr><td>description</td><td>description</td><td>This is a required field.</td></tr><tr><td>recommendations</td><td>recommendations</td><td>These are the writeup recommendations.</td></tr><tr><td>references</td><td>references</td><td><p>This field accepts multiple values delimited with a comma.<br></p><p>For example: "Item 1, Item 2, Item 3"<br><br>NOTE: Do not use commas if providing complete sentences, as any comma will result in a para break. Periods do not trigger a para break.</p></td></tr><tr><td>tags</td><td>tags</td><td><p>This field accepts multiple values delimited with a comma.<br></p><p>For example: "Item 1, Item 2, Item 3"</p></td></tr><tr><td></td><td>custom field</td><td>The headers will be converted to keys and labels in the writeup after import.<br><br>As many custom fields can be used as desired. For example, "custom field 1," "custom field 2," etc.</td></tr><tr><td></td><td>score::cvss3</td><td>The value before the double colon is the score; the value after is the vector string (calculation), if provided.<br><br>For example: "9.8::CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"</td></tr><tr><td></td><td>score::cvss</td><td>For example: "9.5"</td></tr><tr><td></td><td>score::YourLabel</td><td>Replace "YourLabel" with the Label of a custom scoring system.<br><br>The value before the double colon is the score; the value after is the vector string (calculation), if provided.<br><br>For example: "1000::a+b+c+d"</td></tr><tr><td></td><td>cves</td><td>Separate values with a column. For example: "CVE-1999-0001, CVE-2000-0001"</td></tr><tr><td></td><td>cwes</td><td>Separate values with a column. For example: "CWE-787, CWE-79, CWE-89"</td></tr><tr><td></td><td>score::cvss3.1</td><td>The value before the double colon is the score; the value after is the vector string (calculation), if provided.<br><br>For example: "3.7::AV:A/AC:H/PR:H/UI:R/S:C/C:N/I:L/A:L"</td></tr><tr><td></td><td>score::cvss4</td><td>The value before the double colon is the score; the value after is the vector string (calculation), if provided.<br><br>For example: "5.7::AV:L/AC:H/AT:P/PR:L/UI:A/VC:N/VI:L/VA:H/SC:H/SI:L/SA:N"</td></tr></tbody></table>

## Importing the CSV Template

<mark style="background-color:yellow;">Step 1:</mark> From the **WriteupsDB** module, click the **Writeups** tab.

<div align="left"><figure><img src="/files/Hye9hOTdLZCpPdOCV4U5" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Click **Import Writeups**.

<div align="left"><figure><img src="/files/9uepHpe8x40w3sN3Hjey" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Drag the file into the designated box or navigate to the file on the computer.&#x20;

<div align="left"><figure><img src="/files/ph4cBA87uOdb8XqyE8I1" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4</mark>: Click **Upload**.&#x20;

<div align="left"><figure><img src="/files/kQG9ustg8klbUZ931hnr" alt=""><figcaption></figcaption></figure></div>

When completed, the imported writeups will be displayed within the selected repository.


# RunbooksDB

**RunbooksDB** enables collaborative testing for threat emulation and simulation, known as Purple Teaming. Organizations can create reusable test plans that encompass a set of procedures.

Users access by clicking **Content Library** in the application's main menu and then clicking **RunbooksDB**.

<div align="left"><figure><img src="/files/HA9YvF81KSloZccT9yQQ" alt=""><figcaption></figcaption></figure></div>

## Overview

Runbooks comprise a particular methodology, a series of tactics, techniques, and procedures collectively known as TTPs. Runbooks are executed and turned into an engagement tied to a specific client. Once the engagement is finished and submitted, it becomes a report.

RunbooksDB offers several benefits:

* **Standardization**: Runbooks provide standardized procedures and workflows for various tasks and processes. This consistency helps ensure that critical steps are not missed during an operation.
* **Efficiency**: By having predefined procedures and automation scripts within runbooks, teams can respond to incidents and complete tasks more efficiently, which reduces the time and effort required for routine operations.
* **Consistency:** Runbooks help maintain consistency in task performance. This is crucial in cybersecurity and incident response, as consistent procedures are necessary to identify and mitigate threats effectively.
* **Training and Onboarding**: Runbooks are valuable training materials for new team members. They can use runbooks to learn how to perform various tasks and understand best practices, ensuring a smooth onboarding process.


# RunbooksDB Home Page

The **RunbooksDB** home page consists of five tabs:

* **Repositories:** A set of processes that can be reused and have controlled access.
* **Procedures:** A set of steps required to execute a tactic. For example, a procedure for browser extension-based persistence could describe how a malicious extension is injected to maintain persistence.
* **Techniques:** A grouping of procedures. Techniques are added to a tactic for use in an engagement. For example, if a tactic is persistence, a technique could exist for browser extensions.
* **Tactics:** A grouping of techniques. Tactics are added to a methodology for use in a runbook. This usually represents a type of attack, such as persistence or a privilege escalation from the [MITRE ATT\&CK](https://attack.mitre.org/) framework. This can also be a logical grouping or structure for techniques.
* **Methodologies:** A grouping of tactics that are put into a runbook. It contains a title, ID, description, and the selected series of tactics. Tactics can be chosen to apply to the methodology when used as a runbook. This is similar to how the MITRE ATT\&CK is broken down, where the methodology represents the framework for TTP&#x73;**.**&#x20;

<div align="left"><figure><img src="/files/RSxZa2jHJguuIfPnMMus" alt="" width="563"><figcaption></figcaption></figure></div>

## Repositories Tab

PlexTrac provides a container for all instances called "PlexTrac Curated" that contains community-produced procedures on MITRE/CTI.&#x20;

<div align="left"><figure><img src="/files/hYpZJjsmUP1MVZr0T0G3" alt="" width="563"><figcaption></figcaption></figure></div>

This repository contains over 1,500 MITRE procedures from the ATT\&CK matrix that can be leveraged. It is available to all users and cannot be deleted.

<div align="left"><figure><img src="/files/I6VsRyGhpWP5jfmC6P0U" alt="" width="563"><figcaption></figcaption></figure></div>

Once a test plan is imported, another default repository is created. This repository contains all procedures included in the imported test plans.&#x20;

<div align="left"><figure><img src="/files/UNTGMWH05jBFyPf7cnXL" alt=""><figcaption></figcaption></figure></div>

{% hint style="info" %}
The default repositories cannot be deleted.
{% endhint %}

Once added, any additional repositories will be displayed on the page alphabetically according to their title.

Each repository card offers an overview of its contents and settings. It includes the Repository Title, which helps identify the repository, and the Repository Type, which can be categorized as Open, Managed, or Private. The meatballs menu provides convenient options for copying or deleting the repository. Additionally, a Repository Description is available for further context. The card also displays the number of procedures contained, giving insight into the repository's complexity and the number of added users. This indicates the level of collaboration or access granted to others.

## Procedures Tab

To view all procedures, click the **Procedures** tab. This view will display helpful information such as the procedure ID, repository ID, methodology, repository, source, assigned tags, and the ability to edit or delete a procedure.

<div align="left"><figure><img src="/files/yDpVm9soiGyOIdC8aA7U" alt="" width="563"><figcaption></figcaption></figure></div>

### Configuring Table View <a href="#configuring-table-view" id="configuring-table-view"></a>

The table view can be customized by clicking the column view icon to the right of the search bar.

## Techniques Tab

Click the **Techniques** tab to view all techniques. This view will display the title, ID, leveraged tactics, and the ability to edit or delete them.

<div align="left"><figure><img src="/files/UoPEFrSlDglsl8aaF7kT" alt="" width="563"><figcaption></figcaption></figure></div>

### Configuring Table View <a href="#configuring-table-view" id="configuring-table-view"></a>

The table view can be customized by clicking the column view icon to the right of the search bar.

## Tactics Tab

To view all tactics, click the **Tactics** tab. This view will display the title, ID, leveraged methodology, and the ability to edit or delete.

<div align="left"><figure><img src="/files/gVoiRf7c77hstm5I95Bt" alt="" width="563"><figcaption></figcaption></figure></div>

### Configuring Table View <a href="#configuring-table-view" id="configuring-table-view"></a>

The table view can be customized by clicking the column view icon to the right of the search bar.

## Methodologies Tab

Click on the **Methodologies** tab to see all methodologies and find the title, ID, and options to edit or delete them.

<div align="left"><figure><img src="/files/jLjmZTALcQfpKUDzn5d6" alt="" width="563"><figcaption></figcaption></figure></div>


# Managing Repositories

## Changing Settings

Admins can modify the repository name, prefix, description, and access settings.&#x20;

<mark style="background-color:yellow;">Step 1</mark>: From the **Repositories** tab of the **RunbooksDB** home page, click the card of the repository to modify.

<div align="left"><figure><img src="/files/F7ap6bgU6ueOJ5y3jw2N" alt="" width="563"><figcaption></figcaption></figure></div>

&#x20;<mark style="background-color:yellow;">Step 2</mark>: Click **Repository Settings**.&#x20;

<div align="left"><figure><img src="/files/NcbHHHZbYbjEMqcZPcvN" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3</mark>: Make the desired changes, then click **Save**.

<div align="left"><figure><img src="/files/WDtEfr0zQWolVK5zEXfp" alt="" width="524"><figcaption></figcaption></figure></div>

## Deleting a Repository

{% hint style="danger" %}
This action will permanently delete the repository and all its sections for all users.&#x20;
{% endhint %}

From the RunbooksDB home page's **Repositories** tab, click the three dots in the repository card and then click **Delete Repository**.

<div align="left"><figure><img src="/files/8edfAyiG814eLEy6Ivn5" alt="" width="431"><figcaption></figcaption></figure></div>

A warning message appears asking for validation. Click **Delete Repository**.&#x20;

<div align="left"><figure><img src="/files/dsCduFHH4Burw98HvsLj" alt="" width="352"><figcaption></figcaption></figure></div>


# Managing Users

If the repository is not an "Open" type repository, admins can manage users by clicking **Users & Permissions**.

## Adding Users

<mark style="background-color:yellow;">Step 1:</mark> From the **Repositories** tab of the **RunbooksDB** home page, click the card of the repository to modify.

<div align="left"><figure><img src="/files/cbaUI7fDFXaEDtR2idBc" alt="" width="563"><figcaption></figcaption></figure></div>

&#x20;<mark style="background-color:yellow;">Step 2</mark>: Click **Users & Permissions**.&#x20;

<div align="left"><figure><img src="/files/nqVSHUL8XY7ryMi18YGf" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Click **Add User**.

<div align="left"><figure><img src="/files/AzCUwjiBhXRhli5fPm91" alt="" width="525"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4:</mark> Type in the user from the pulldown menu and select the permission. Repeat as necessary. Click **Add X Users**.&#x20;

<div align="left"><figure><img src="/files/aMpUHNolsu9ujzIYgShf" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 5:</mark> Edit the permission or delete a user, if needed. Click **Done**.

<div align="left"><figure><img src="/files/dNVPECSXyi7H0mQ56NUe" alt="" width="563"><figcaption></figcaption></figure></div>

## Modifying Users

<mark style="background-color:yellow;">Step 1:</mark> From the **RunbooksDB** home page, click the desired repository card and click **Users & Permissions**.

<div align="left"><figure><img src="/files/GX6umQ6V2w3Kv8JP5AmL" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Select the user to modify and change permissions from the pulldown menu.

<div align="left"><figure><img src="/files/I9QIBXEkrTUCnO1tMBpK" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> When finished, click **Done**.&#x20;

## Deleting Users

<mark style="background-color:yellow;">Step 1:</mark> From the **RunbooksDB** home page, click the desired repository card and click **Users & Permissions**.

<figure><img src="/files/hFDjhLAF8aTeIfxcdo4J" alt=""><figcaption></figcaption></figure>

<mark style="background-color:yellow;">Step 2:</mark> Select the user to remove and click the **X** in that row.

<div align="left"><figure><img src="/files/FoUki7dKpm74dn2OPhdk" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> When finished, click **Done**.&#x20;


# Creating a Repository

<mark style="background-color:yellow;">Step 1:</mark> From the **Repositories** tab of the **RunbooksDB** module, click **New Repository**.

<div align="left"><figure><img src="/files/D8DzsoCaKOHl5uVF77qB" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Enter information in the fields and select the desired security access for the repository.

<figure><img src="/files/Le7TblB98qAtwwWTWYJd" alt=""><figcaption></figcaption></figure>

1. **Repository Name**: Describes the repository and is displayed on the repository card from the **Repositories** tab.
2. **Writeup ID Prefix**: A three-character value that is unique to this repository. An error message will display if the prefix already exists after clicking the **Create** button in Step 3.\
   ![](/files/Jdanl1W5qya6RHm90LFQ)
3. **Description**: Describes the repository.
4. **Repository Access**: Defines what [users and roles can access](/plextrac-documentation/product-documentation/content-library/types-of-repositories) the writeups in this repository.&#x20;

<mark style="background-color:yellow;">Step 3:</mark> Click **Create**.

<div align="left"><figure><img src="/files/MGyzWnYgn0cRDds4FgQI" alt="" width="527"><figcaption></figcaption></figure></div>

The new repository now has a card on the **Repositories** tab.

<div align="left"><figure><img src="/files/QA1SevQZmhhJsFiccOAB" alt="" width="563"><figcaption></figcaption></figure></div>


# Creating a Procedure

A procedure is a predefined set of steps and actions that must be followed to accomplish a specific security-related task or address a particular issue. Procedures are often documented and provide a systematic approach to incident response, patch management, access control, and vulnerability assessment. They help ensure that tasks are executed consistently and comply with security policies.

<mark style="background-color:yellow;">Step 1:</mark> Click the **Procedures** tab of the **RunbooksDB** module.&#x20;

<mark style="background-color:yellow;">Step 2:</mark> Click **New Procedure**.&#x20;

<div align="left"><figure><img src="/files/HLzjIRnJXYPEZFefjTXA" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Fill out the provided fields.

<div align="left"><figure><img src="/files/JuQnVDZ1rCliKYGLYjkH" alt="" width="563"><figcaption></figcaption></figure></div>

1. **Procedure Title (required):** The procedure title should include MITRE technique numbers when applicable (e.g., T1027), with an additional local indicator to distinguish it from the official MITRE technique, such as "Obfuscated Files or Information AE-T1027."
2. **Procedure ID (required):** The procedure ID should combine the MITRE technique number (e.g., T1027) with an organization-specific identifier and a sequential number, such as "AE-T1027-001" or "T1027-AE-001". This maintains consistency, links to MITRE techniques, and supports standardization within an organization.
3. **RunbooksDB Repository (required)**: Every procedure must be associated with a **RunbooksDB** repository and only repositories that the user can edit appear in the pulldown menu.
4. **Techniques**: Click **Add Techniques** to add existing techniques in **RunbooksDB** to the procedure. They will then appear on the "New Procedure" page.\
   ![](/files/V1CMNgUo79Q4Jp3G15DH)
5. **Procedure Description (required):** A rich-text field to enter any content, images, or tables needed to describe the procedure. A procedure description should be detailed and actionable, including clear objectives, step-by-step instructions, and mapping to relevant MITRE ATT\&CK techniques. It should be based on real-world adversary behaviors and include technical details, expected outcomes, and potential variations. Additionally, it should provide safety precautions and guidance on detection and mitigation strategies.&#x20;
6. **Tags:** Enter any tags to help future search and filtering tasks.
7. **Execution Steps (required)**: A set of steps to achieve specific security-related goals and address potential threats or vulnerabilities. A procedure must have at least one step.
8. **Add Step Success Criteria**: Click this to access a rich-text field to provide the success criteria of the previously entered step. A good step success criteria should include measurable outcomes that align with the exercise's objectives. These criteria should be based on observable indicators that reflect real-world adversary behaviors. For example, success might be defined as achieving unauthorized access within a certain timeframe using specific tactics.
9. **Add Another Execution Step**: Click this button to add additional steps.

<mark style="background-color:yellow;">Step 4:</mark> Click **Save** at the top of the page.

The procedure is now available from the **Procedures** tab and can be viewed, edited, or deleted from this location.


# Creating a Technique

Cyber attackers or threat actors use specific methods, tactics, and procedures known as techniques to compromise computer systems, gain unauthorized access, or achieve their malicious objectives. These techniques exploit vulnerabilities and weaknesses in computer systems and networks by adversaries.

<mark style="background-color:yellow;">Step 1:</mark> Click the **Techniques** tab of the **RunbooksDB** module. &#x20;

<mark style="background-color:yellow;">Step 2:</mark> Click **New Technique**.&#x20;

<div align="left"><figure><img src="/files/T481mAPFSKuhnIiInpeM" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Fill out the provided fields.

<div align="left"><figure><img src="/files/76wKLIt8FadI36oGIdZ8" alt="" width="563"><figcaption></figcaption></figure></div>

1. **Technique Title (required)**
2. **Technique ID (required)**
3. **Procedures**: Click **Add Procedures** to bring up a new modal to add procedures to the technique.&#x20;
4. **Tactic**: Click **Add Tactics** to bring up a new modal to add tactics to the technique.&#x20;
5. **Technique Description:** A rich-text field to enter any content, images, or tables to describe the technique.
6. **Tags:** Enter any tags to help future search and filtering tasks.

<mark style="background-color:yellow;">Step 4:</mark> Click **Save**.

The technique is now available from the **Techniques** tab, which can be viewed, edited, or deleted.


# Creating a Tactic

Tactics are higher-level categories or strategies used by adversaries to achieve their goals. In the MITRE ATT\&CK framework, tactics are broader than techniques and represent the overall objectives of an attack. For example, tactics might include "Execution," "Persistence," "Privilege Escalation," and "Defense Evasion." Tactics encompass a range of techniques that support a specific objective.

<mark style="background-color:yellow;">Step 1:</mark> Click the **Tactics** tab of the **RunbooksDB** module. &#x20;

<mark style="background-color:yellow;">Step 2:</mark> Click **New Tactic**.

<div align="left"><figure><img src="/files/6gGpwpqBGjIVvtZUOBYG" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Fill out the provided fields.

<div align="left"><figure><img src="/files/tGIRar4XrhFFzLTm9gjf" alt="" width="563"><figcaption></figcaption></figure></div>

1. **Tactic Title (required)**
2. **Tactic ID (required)**
3. **Techniques**: Click **Add Techniques** to bring up a new modal to add techniques to the tactic.&#x20;
4. **Methodologies**: Click **Add Methodologies** to bring up a new modal to add methodologies to the tactic.&#x20;
5. **Tactic Description:** A rich-text field to enter any content, images, or tables to describe the tactic.
6. **Tags:** Enter any tags to help future search and filtering tasks.

<mark style="background-color:yellow;">Step 4:</mark> Click **Save**.

The tactic is now available from the **Tactics** tab, which can be viewed, edited, or deleted.


# Creating a Methodology

A methodology is a structured approach or framework to guide a comprehensive and systematic process. In cybersecurity, a methodology is often a documented set of guidelines and procedures for performing tasks such as penetration testing, risk assessment, security assessments, or incident response. Methodologies provide a structured way to conduct activities and ensure consistency in approach.

<mark style="background-color:yellow;">Step 1:</mark> Click the **Methodologies** tab of the **RunbooksDB** module. &#x20;

<mark style="background-color:yellow;">Step 2:</mark> Click **New Methodology**.&#x20;

<div align="left"><figure><img src="/files/94TDghoqLJ0BEERE5Yd5" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Enter a methodology title and ID (both fields are required). &#x20;

<div align="left"><figure><img src="/files/M2PylDYrqfNAOtqLDkes" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4:</mark> Click **Add Tactics**. A modal will appear with available tactics to add to the methodology. Click **Select** next to the tactics to add, and the selected tactics will appear in the right column.

<div align="left"><figure><img src="/files/U0o6nTU1EsOWX1oYibGT" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 5:</mark> When finished, click **Add X Tactics**.

<div align="left"><figure><img src="/files/mzRWBRPDp4KjyUD0zJlx" alt="" width="563"><figcaption></figcaption></figure></div>

&#x20;Enter a methodology description and any desired tags.

<div align="left"><figure><img src="/files/sV3J9f1v0OwTYEdmuxoS" alt="" width="508"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 6:</mark> Click **Save** at the top of the page.

The methodology is now available from the **Methodologies** tab and can be viewed, edited, or deleted from this location.


# Analytics

The **Analytics** module provides one central location to obtain valuable metrics and view findings, assets, runbooks, and SLA trends. This module consists of four sections: **Findings**, **Assets**, and **Trends & SLAs**.&#x20;

{% hint style="info" %}
Users with data from the legacy Runbooks V1 solution will see a fourth tab for [Runbooks](/plextrac-documentation/product-documentation/analytics/runbooks).
{% endhint %}

<div align="left"><figure><img src="/files/9QcYMfuuTEsrPQm9OIAb" alt=""><figcaption></figcaption></figure></div>

{% hint style="info" %}
Analytics filter values and data sets are updated every minute. If a tag or field was updated but does not appear as expected, wait one minute and try again.
{% endhint %}

## Overview

The **Analytics** module defaults to the **Findings** tab.&#x20;

Only data for findings from *published* reports (a status of "Published") that the user has permission to view are displayed.

<div align="left"><figure><img src="/files/BwI4GNHNHdvYvNhCdclN" alt=""><figcaption></figcaption></figure></div>

Data can be refined using one or more filters in the right column. When filters are selected, the data displayed refreshes, and the active filters are listed at the top of the page.&#x20;

The number of active filters is displayed next to "Active Filters." Click **Clear All** to reset filters.

<div align="left"><figure><img src="/files/yRw96yYmVDT2vyWUeEQ4" alt=""><figcaption></figcaption></figure></div>

Filter options are specific to the type of data being queried, and the facets and values available dynamically change when navigating through the **Findings**, **Assets**, and **Trends & SLAs** tabs.

## Search Filter Presets

A search filter set is a collection of grouped search filters to provide more comprehensive results. Practical search filter sets can improve the user experience by reducing the time and effort required to find relevant search results and increasing the likelihood of a successful search.

{% hint style="info" %}
Preset filters are available for all tabs in the **Analytics** module.
{% endhint %}

### Creating a Filter Preset

<mark style="background-color:yellow;">Step 1:</mark> Select the filters that will make up the preset.

<mark style="background-color:yellow;">Step 2:</mark> Click **Create Preset** at the top of the filter column.

<figure><img src="/files/8CtKHqTywTOZPWiWzG1V" alt=""><figcaption></figcaption></figure>

<mark style="background-color:yellow;">Step 3:</mark> Enter a value for "Filter Name." This value will be used to select the query later, so it should be intuitive.&#x20;

{% hint style="info" %}
To make this preset the default filter, check the box next to "Make Default Filter."
{% endhint %}

<div align="left"><figure><img src="/files/0UBfPdpcGcLLqS8UIlJv" alt="" width="397"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4:</mark> Click **Create Filter**.&#x20;

The filter preset now appears in the pulldown menu as an available option.&#x20;

### Updating a Filter Preset

This process can be used to rename an existing filter preset, adjust the filter parameters, or use it as a clone to create a new filter preset.

<mark style="background-color:yellow;">Step 1:</mark> Select the filter preset to delete from the pulldown menu.

<div align="left"><figure><img src="/files/KLCN2LAdawitWaxdk1vi" alt="" width="329"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Adjust the filter parameters.

<mark style="background-color:yellow;">Step 3:</mark> Click **Update Selected Filer**.

<div align="left"><figure><img src="/files/rryGqB68hejzzV2GRlvY" alt="" width="329"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4:</mark> A modal appears. Rename the filter to keep the original filter unchanged, or click **Update**.

### Deleting a Filter Preset

<mark style="background-color:yellow;">Step 1:</mark> Select the filter preset to delete from the pulldown menu.

<div align="left"><figure><img src="/files/0miErS3O1JpBijd8YDDk" alt="" width="329"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Click **Delete Selected Filter**.

<div align="left"><figure><img src="/files/Tl6TbPjq8bX0LFyAdbwH" alt="" width="329"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> A modal appears confirming action. Click **Delete Filter**.


# Findings

The **Findings** tab has two containers of information that can be expanded or collapsed:&#x20;

* **Findings**: an overall view of all findings that the user has access to view and have been published
* **Findings by client**: a view of findings filtered by the client

{% hint style="info" %}
Only published findings from reports with a "Published" status are included in the analytics module. In the **Admin Dashboard**, administrators can [default findings to "Published"](https://docs.plextrac.com/plextrac-documentation/product-documentation-1/account-management/account-admin/tenant-settings/general-settings#findings-default-published) upon creation.
{% endhint %}

<div align="left"><figure><img src="/files/iVXc1RyHArqQDPhcChsx" alt="" width="563"><figcaption></figcaption></figure></div>

When filters are selected, the data displayed refreshes, and the active filters are listed at the top of the page.&#x20;

## Findings Filters

Search filters allow users to refine and narrow their search results based on specific criteria or parameters.

Analytics filter values and data sets are updated every minute. If a tag or field was updated but did not appear as expected, wait one minute and try again.

A list of all filters and values for the **Findings** tab exists below:

* Client(s)
* Client Tags&#x20;
* Date Range&#x20;
* Asset(s)
* Asset Tags&#x20;
* Finding Severity: Unchecking a severity will hide any asset with only findings of that severity.
  * Critical
  * High
  * Medium
  * Low
  * Informational
* Asset Severity
  * Critical
  * High
  * Medium
  * Low
  * Informational
  * Unspecified
* Finding Tags
* Finding Status
  * Open
  * In Process
  * Closed
* Report
* Report Tags&#x20;
* Graph View&#x20;
  * Horizontal
  * Vertical
* Assignees: This field only relates to Clients, Client Tags, Finding Tags, Reports, and Report Tags. If other fields are selected, the pulldown menu for Assignees will be blank. Similarly, if a report with no assignees is set, the pulldown menu for Assignees will be empty.
* CVE ID
* CWE ID

{% hint style="info" %}
The CVE and CWE filters use an “and” query condition that requires both of the specified search terms or conditions to be present in the results. In other words, the search results must meet all of the specified conditions to be included in the results.\
\
For example, if two CVE values are added as a filter, the results will only display findings that contain both values.
{% endhint %}

## Findings Container

The **Findings** container displays the status, severity, client breakdown, and most critical findings for all tenant findings within defined query parameters and user permissions.&#x20;

<figure><img src="/files/VS8BSeiHwa0U2DTCUWDj" alt=""><figcaption></figcaption></figure>

## Findings By Clients Container

The **Findings By Client** container breaks down findings per client. Scroll down to see additional clients in the tenant.&#x20;

<div align="left"><figure><img src="/files/NrnMLIIvqPsIULAA0cre" alt=""><figcaption></figcaption></figure></div>

## Finding Information

More details about a specific finding can be obtained in the "Most Critical Findings" table.

<div align="left"><figure><img src="/files/lA83grXAL7sMUmsfaHX7" alt=""><figcaption></figcaption></figure></div>

Clicking the row of a finding brings up the finding details modal.&#x20;

1. Access the **Findings** tab of the **Report** module for further editing by clicking the "Finding ID" value.
2. Modify the finding status by clicking the "Status" value.
3. View information on an affected asset by clicking the table row of the&#x20;


# Assets

The **Assets** tab has two containers that can be expanded or collapsed to display all assets that the user has access to view:

* **Asset findings overview:** an overview of all assets
* **Assets**: a table view of assets with sortable headings

<div align="left"><figure><img src="/files/JOYi3bDFEJyIg10P7YTk" alt="" width="563"><figcaption></figcaption></figure></div>

{% hint style="info" %}
Only assets from reports with a "Published" status are included in the analytics module.
{% endhint %}

## Asset Filters

Search filters allow users to refine and narrow search results based on specific criteria or parameters.

Analytics filter values and data sets are updated every minute. If a tag or field was updated but did not appear as expected, wait one minute and try again.

A list of all filters and values for the **Assets** tab exists below:

* Client(s)
* Client Tags&#x20;
* Asset Types
* Asset(s)
* Asset Tags
* Ports
* Finding Severity
  * Critical
  * High
  * Medium
  * Low
  * Informational
* Asset Severity
  * Critical
  * High
  * Medium
  * Low
  * Informational&#x20;
  * Unspecified
* Finding Tags
* Report
* Report Tags
* Operating System
* Data Owner
* System Owner
* Physical Location

## Asset Findings Overview Container

This container graphically displays the number of assets that have findings and provides a breakdown of the severity of findings (for those assets with findings).

<div align="left"><figure><img src="/files/eDjXS4TLeSlkqcj3m4XY" alt=""><figcaption></figcaption></figure></div>

## Assets Container

This container displays a table that lists the asset name, client, criticality, type, and finding count. Column headers can be clicked to change the sort order and how the data is displayed.&#x20;

<div align="left"><figure><img src="/files/0UGrYebV8M3A6BIPCAe2" alt="" width="563"><figcaption></figcaption></figure></div>

Click an asset row for more information and a list of associated findings.&#x20;

Assets can be edited directly by clicking **Edit Asset** at the top right of the page. &#x20;

![](/files/9YPL7hOQH1iVRMnZjcjf)


# Runbooks

{% hint style="warning" %}
This tab only supports the legacy Runbooks V1 solution.
{% endhint %}

The **Runbooks** tab allows the ability to view success at remediating issues over time by displaying data from all published runbooks a user has permission to view. It reveals trends to see how blue and red team outcomes change (or not) over time to ensure that blue team success increases as red team success decreases.&#x20;

Each runbook is separated by a container that can be expanded or collapsed.

Clicking a container for a runbook provides a graphical view of the following information:

* **Runbook Stats**: overviews clients impacted, findings generated, and tactics covered.
* **Tactics Covered**: shows how many procedures in a runbook were created as findings and how effective a security program was at stopping a technique.
* **Red Team Outcomes:** provides a view and percentage breakdown of red team outcomes; moving the cursor around the pie chart provides additional information.
* **Blue Team Outcomes:** provides a view and percentage breakdown of blue team outcomes; moving the cursor around the pie chart provides further information.
* **Client Engagement Analysis:** provides a bar chart graph visual of blue and red team outcomes by date to measure progress over time

<div align="left"><figure><img src="/files/VMYcqzh3qRpBS4M8Vbd1" alt="" width="563"><figcaption></figcaption></figure></div>

When filters are selected, the data displayed refreshes, and the active filters are listed at the top of the page.&#x20;

![](/files/2QuLXZgGH03tGfZUqZka)

## Filters

Search filters allow users to refine and narrow their search results based on specific criteria or parameters.

Analytics filter values and data sets are updated every minute. If a tag or field was updated but did not appear as expected, wait one minute and try again.

A list of all filters and values for the tab exists below:

* Client(s)
* Date range (values selected shown in query bar)
* Runbooks (values selected shown in query bar)
* Methodologies (values selected shown in query bar)
* Engagements (values selected shown in query bar)
* Engagement Tags
* Tactics (values selected shown in query bar)
* Red Team Outcome
  * Success
  * Partial Success
  * Failed
  * Unknown
* Blue Team Outcome
  * Blocked
  * Alerted
  * Logged
  * No Evidence
* Included as Finding
  * True
  * False


# Trends & SLAs

The **Trends & SLAs** tab displays how a security program is meeting goals from an SLA perspective and provides trending data about findings in a security program. It allows the configuration of SLAs based on specific criteria and allows visual data to determine if those criteria are being met.

The Trends and SLAs tab contains multiple containers:

* **Mean time to remediate by severity:** This includes only closed findings. The MTTR number is derived from the following calculation: *Total Sum of Creation to Closure Time / Total Number of Findings Closed.*&#x20;
* **Trend of findings opened vs closed**: This graph shows progress over a period of time. To better utilize space, days with zero findings opened or closed are hidden.
* **Service-Level Agreements (SLAs):** This section will list every SLA that has been enabled for the tenant.

<div align="left"><figure><img src="/files/EqfKbWo0ras5wDcORkox" alt=""><figcaption></figcaption></figure></div>

Admins can [set up SLAs](/plextrac-documentation/product-documentation/analytics/trends-and-slas) through the **Admin Dashboard** (Tenant Settings>Service-Level Agreements) or by clicking **SLA Settings**. <br>

<div align="left"><figure><img src="/files/nwv2CTNTrQYTKlCo6VCK" alt=""><figcaption></figcaption></figure></div>

## Filters

Search filters allow users to refine and narrow search results based on specific criteria or parameters.

Analytics filter values and data sets are updated every minute. If a tag or field was updated but did not appear as expected, wait one minute and try again.

A list of all filters and values exists below:

* Client
* Client Tags&#x20;
* Date Range
* Finding Severity
  * Critical
  * High
  * Medium
  * Low
  * Informational
* Finding Tags
* Report
* Report Tags
* CVE ID
* CWE ID

## **Mean Time to Remediate by Severity**

The MTTR number is derived from the following calculation: *Total Sum of Creation to Closure Time / Total Number of Findings Closed.*&#x20;

{% hint style="info" %}
This graph includes only closed findings.
{% endhint %}

<div align="left"><figure><img src="/files/Ywbl65ghBj65ssPfmO6A" alt=""><figcaption></figcaption></figure></div>

## **Trend of Findings Opened vs. Closed Container**

This container displays a bar graph showing the monthly trend chart of open and closed findings over the period specified in the filter for findings that match the criteria.&#x20;

A trending blue line shows the total number of open findings. A green bar identifies the number of closed findings, while a red bar identifies the number of opened findings.

{% hint style="info" %}
To make this graph easier to view, days with no findings opened or closed are hidden.
{% endhint %}

<div align="left"><figure><img src="/files/X5XXPeVQVOqIZjvZh95J" alt=""><figcaption></figcaption></figure></div>

## **Service-Level Agreements (SLAs) Containers**

These containers provide visual representations and snapshots of findings based on enabled SLAs and selected query parameters.

1. A total count for all findings that exceed, are nearing or are within one day of the SLA.
2. A view of the mean time to remediate, plus any findings nearing one day of SLA over time.
3. A view of how many findings by a percentage of overall findings exceeded SLA over a period of time.

<figure><img src="/files/MTiGXmrgr0lZJMBzUzu6" alt=""><figcaption></figcaption></figure>

Further details and the ability to directly edit any findings that apply to the SLA can be obtained by clicking on the appropriate box under "CURRENT SNAPSHOT."&#x20;

<div align="left"><figure><img src="/files/zfXcGdPmiL5Jtvu812bu" alt=""><figcaption></figcaption></figure></div>


# Runbooks

In the **Runbooks** module, users can create detailed guides for red teaming and penetration testing, documenting the procedures, vulnerabilities, and recommendations for enhancing security.

Runbooks work with the [**RunbooksDB**](/plextrac-documentation/product-documentation/content-library/runbooksdb) repository in the **Content Library**, enabling the reuse of existing procedures, tactics, and methodologies with or without modifications to fit new test plans.

Users access the module by clicking **Runbooks** in the application's main menu.

<div align="left"><figure><img src="/files/JH7tm9HEGCloq1wjByic" alt=""><figcaption></figcaption></figure></div>

## Overview

In cybersecurity, professionals often rely on red teaming to test and strengthen their defenses. This process involves simulating real-world cyberattacks to assess vulnerabilities and response capabilities. During such engagements, teams create runbooks to guide actions and record findings.

These runbooks serve as comprehensive records, documenting various procedures and tactics employed during the engagements. They outline the steps the red team takes, the vulnerabilities they exploit, and the recommendations they make to improve security. In essence, runbooks are the playbook for these security exercises.

The ultimate objective of these engagements is to evaluate the red team's proficiency in executing attack procedures and the blue team's capability to detect, protect against, and respond to them. The outcomes of these engagements are compiled in reports, which are then shared with clients or internal teams. These reports offer valuable insights into the effectiveness of the existing security measures and provide recommendations for improvements.

The **Runbooks** module has two tabs:&#x20;

* **Engagements:** Displays all runbooks created for a client, including those in progress and those submitted as a report (if not deleted).&#x20;

<div align="left"><figure><img src="/files/gxblH2bsje6qafM6KO1U" alt="" width="563"><figcaption></figcaption></figure></div>

* **Test Plans**: Displays all existing test plans created or imported.&#x20;

<div align="left"><figure><img src="/files/my0WuB4lSktyqyoGaGZc" alt="" width="563"><figcaption></figcaption></figure></div>

{% hint style="info" %}
**RunbooksDB** is accessible from both tabs by clicking **Manage RunbooksDB**.
{% endhint %}


# Managing Engagements

Engagements are shown on the **Engagements** tab of the Runbooks module. This view displays the engagement title, associated test plan, related client, the date the engagement was last updated, and the progress of the engagement. In the "Actions" column, engagements can be viewed, edited, or deleted.

## **Engagement Status**

Engagements are identified as submitted, not submitted, or in progress.&#x20;

Progress is based on the completion of contained procedures, and progress is displayed in two locations:

* &#x20;On the **Engagements** tab as a progress bar:

<div align="left"><figure><img src="/files/7MA8ofMu25ywTQwbDUFx" alt="" width="563"><figcaption></figcaption></figure></div>

* Within the top toolbar of the engagement's home page:

<div align="left"><figure><img src="/files/ryPE9p60elRUTKfzdEAz" alt="" width="563"><figcaption></figcaption></figure></div>

Engagements completed but not submitted will display "Not Submitted" under the 100% progress bar.

<div align="left"><figure><img src="/files/vYLqmUnJfZ2PmjVxh46X" alt=""><figcaption></figcaption></figure></div>

Engagements submitted become reports and are identified with a green checkmark and label. They will remain listed in Runbooks until deleted.

<div align="left"><figure><img src="/files/wV9Jf8YjZy2ugnykOsjh" alt=""><figcaption></figcaption></figure></div>

{% hint style="warning" %}
Only engagements that are in progress can be edited. Once an engagement is submitted and becomes a report, it cannot be edited.
{% endhint %}

## Updating Engagement Procedures

<mark style="background-color:yellow;">Step 1:</mark> Click **View** under an in-progress engagement's "Actions" column.

<div align="left"><figure><img src="/files/W0ZQCOgzFz3rwFAqGrud" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> The engagement overview page provides information about the engagement and procedures. Click **View** under the "Actions" column of the procedure to update.

<div align="left"><figure><img src="/files/CnEb1bprDe74nlrWnUie" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Update the procedure status or finding severity by selecting the desired values from the pulldown menus.&#x20;

<div align="left"><figure><img src="/files/toGNDnCipmGPA0qqJu1m" alt="" width="563"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4:</mark> Add operators by clicking **Managing operators**. Assign an operator(s) for the red and blue teams. Click **Save**.&#x20;

When the runbook is submitted, these names appear on the test plan and become a report.

<div align="left"><figure><img src="/files/0GPIUpOeqGF316nhbdiQ" alt=""><figcaption></figcaption></figure></div>

{% hint style="info" %}
All engagement sections are in containers that can be collapsed or expanded for usability. \
\
![](/files/cJgiMZp4relv95eY81La)
{% endhint %}

<mark style="background-color:yellow;">Step 5:</mark> Run the procedure's execution steps. When completed, identify the outcomes for the blue and red teams from the provided options and enter an attack source in the provided box.

<div align="left"><figure><img src="/files/bwgq3gCgWkx4r248gvu0" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 6:</mark> Add assets, procedure logs, attachments, and notes as needed to provide additional support and context.

<div align="left"><figure><img src="/files/QsVsPCIsG8SCUMwcRapI" alt="" width="563"><figcaption></figcaption></figure></div>

&#x20;<mark style="background-color:yellow;">Step 7:</mark> Scroll to the top of the page and click **Save**.

<div align="left"><figure><img src="/files/IOLN0c3OGJCJz081fGFK" alt="" width="412"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 8:</mark> Click the page navigation aid at the top to continue the engagement.&#x20;

<div align="left"><figure><img src="/files/ZGRNlD8uQbebRqw3zehE" alt="" width="330"><figcaption></figcaption></figure></div>

Procedures can be viewed and edited on this page using the navigation icons at the top of the screen.


# Starting an Engagement

<mark style="background-color:yellow;">Step 1:</mark> From the **Runbooks** module home page (the **Engagements** tab), click **Start New Engagement**.

<div align="left"><figure><img src="/files/WKFEiulITf3OxVyuE1Ay" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Select the client from the **Client** pulldown menu.

<figure><img src="/files/uey3nzrjNLb6DecvAyCr" alt=""><figcaption></figcaption></figure>

<mark style="background-color:yellow;">Step 3:</mark> Select if the engagement is new or to be modified from an existing test plan.&#x20;

<div align="left"><figure><img src="/files/qLkpSr0NxBquIoqaBisp" alt=""><figcaption></figcaption></figure></div>

Existing test plans are greyed out unless "Start from an existing Test Plan" is selected. These plans can be leveraged as a starting point by clicking **Select** next to the test plan.

<div align="left"><figure><img src="/files/f5vERNtbPAzLzq6RvTtz" alt=""><figcaption></figcaption></figure></div>

To reduce the list of test plans provided, filter by tactic or test plan title in the search box.

<mark style="background-color:yellow;">Step 4:</mark> Click **Next**.

<div align="left"><figure><img src="/files/b0UDxlGFKyA5HHRnt7yb" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 5:</mark> On the **Engagement Details** tab, enter a title (required), a description, and any required tags. If an existing test plan was selected in the previous step, information in that test plan is populated by default and can be edited.&#x20;

Click **Continue**.&#x20;

<figure><img src="/files/dXRmKDjzGF4F6L7zYSaQ" alt=""><figcaption></figcaption></figure>

<mark style="background-color:yellow;">Step 6:</mark> On the **Select Procedures** tab, select the procedures for this engagement by clicking the **Select** button next to the procedure to add. If leveraging an existing test plan, all procedures from that template are displayed in the right-hand column.&#x20;

<div align="left"><figure><img src="/files/Os60XKtCvAU4m7GYDdOG" alt=""><figcaption></figcaption></figure></div>

This list can be reduced by clicking the x button of the procedure to remove at the right of the box.&#x20;

<div align="left"><figure><img src="/files/yjyoVvNOD27KlyqOXtte" alt=""><figcaption></figcaption></figure></div>

The procedure sequence can be adjusted by clicking and dragging the procedure to its desired line.

<div align="left"><figure><img src="/files/q1X4mz9Vd9njel7eQlYT" alt=""><figcaption></figcaption></figure></div>

The list of procedures displayed on the screen can be adjusted using the provided filter options.

<div align="left"><figure><img src="/files/8Hq1MFWRlQ7ZkfA6xvEn" alt=""><figcaption></figcaption></figure></div>

{% hint style="info" %}
If required procedures have not yet been created, the engagement can be completed and procedures added later, but it is recommended to create the procedures first in [**RunbooksDB**](/plextrac-documentation/product-documentation/content-library/runbooksdb).&#x20;
{% endhint %}

<mark style="background-color:yellow;">Step 7:</mark> Click **Add X Procedures** when finished.&#x20;

<mark style="background-color:yellow;">Step 8:</mark> View a summary of the engagement from the **Finalize Engagement** tab. The title, description, tags, engagement coverage, and assigned procedures are displayed.

Click **Create Engagement**.&#x20;

<div align="left"><figure><img src="/files/E1FxPgDOryLZCTZi1vpc" alt=""><figcaption></figcaption></figure></div>

The engagement is now active and ready to be executed.&#x20;

<div align="left"><figure><img src="/files/gANwWwm9TPkNXOc9TlLr" alt=""><figcaption></figcaption></figure></div>

It also is now listed on the **Engagements** tab.

<figure><img src="/files/G3IViLCcWeZX3lm4MA19" alt=""><figcaption></figcaption></figure>


# Submitting an Engagement

<mark style="background-color:yellow;">Step 1:</mark> Click **View** under the "Actions" column of an engagement.

<div align="left"><figure><img src="/files/GousZEILYYu2beCjLBwC" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Click **Submit Engagement**.&#x20;

{% hint style="danger" %}
Clicking **Submit Engagement** cannot be reversed.&#x20;
{% endhint %}

<div align="left"><figure><img src="/files/w7JctmTNcBfDdEfeK5YB" alt=""><figcaption></figcaption></figure></div>

The engagement is now a report, and PlexTrac redirects to the **Procedures** tab of the **Reports** module.

<div align="left"><figure><img src="/files/6zHO410NUpj4fKJMSiI9" alt=""><figcaption></figcaption></figure></div>

Submitted engagements will still be displayed in the **Runbooks** module, but the engagement can no longer be viewed or edited, and the link provided under the "Actions" column will open the **Reports** module.&#x20;

<div align="left"><figure><img src="/files/uj5mF7diwfKfNVIRMQK7" alt=""><figcaption></figcaption></figure></div>

{% hint style="info" %}
Deleting a submitted engagement in **Runbooks** does not delete the report.
{% endhint %}


# Managing Test Plans

Test plans are displayed on the **Test Plans** tab of the **Runbooks** module.

<div align="left"><figure><img src="/files/48cPt0aqbOraeE84To1V" alt=""><figcaption></figcaption></figure></div>

## Starting a Test Plan

<mark style="background-color:yellow;">Step 1:</mark> From the **Test Plans** tab of the **Runbooks** module, click **Start** under the "Actions" menu of the test plan.

<div align="left"><figure><img src="/files/vJZGqr7CzJWJrXiYq0iR" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark>  Select the client from the pulldown menu. Click **Next**.

<div align="left"><figure><img src="/files/rpXTWNS003TQobqW857n" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark>  Review and update details as desired. Click **Continue**.

<div align="left"><figure><img src="/files/UYvKkXexOlNOaeUINxzU" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4:</mark>  Review the engagement. Add new procedures by clicking **Select** next to the procedure to include or delete existing ones from the engagement by clicking the x within the procedure box in the right-hand column. Click **Add X Procedures**.

<figure><img src="/files/a7Av1KDmmfcFs7lK1rkb" alt=""><figcaption></figcaption></figure>

<mark style="background-color:yellow;">Step 5:</mark>  Review the engagement coverage. The plan can still be modified from this page by clicking Add Procedures or clicking the X to remove an existing procedure. The order of procedures can also be changed by selecting a box and dragging it to the desired location.

When ready, click **Start new engagement**.

<div align="left"><figure><img src="/files/pgY2Utu9mPU0hGeIG5FX" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 6:</mark>  Begin engagement by selecting a procedure and clicking **View**.

<div align="left"><figure><img src="/files/VFEKysKbvIPMA8rdxnhq" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 7:</mark> The procedure page will appear. Conduct the procedure, then click **Save**.

<div align="left"><figure><img src="/files/Ls9YntyjIGSHRt9A17s8" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 8:</mark> Click **Close** to return to the page of the test plan that lists all contained procedures, or click the navigation arrow to move to the following procedure.

<figure><img src="/files/l1CwMgS1FYCZTxof6qrK" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Click **Close** from the test plan overview page to return to the **Engagements** tab.

![](/files/Qrtl3v4GaZideFkF0G0x)
{% endhint %}

## Viewing a Test Plan

From the **Test Plans** tab of the **Runbooks** home page, click **View** under the "Actions" menu of the test plan.

<div align="left"><figure><img src="/files/uu5B7K7socIrLDyQY8dg" alt=""><figcaption></figcaption></figure></div>

## Editing a Test Plan

From the **Test Plans** tab of the **Runbooks** home page, click **Edit** under the "Actions" menu of the test plan. If the user cannot edit, the option will not exist.&#x20;

<figure><img src="/files/sCDebKJooB3qNfmSxt9X" alt=""><figcaption></figcaption></figure>

## Deleting a Test Plan

From the **Test Plans** tab of the **Runbooks** home page, click the three dots under the "Actions" menu of the test plan and then click **Delete**. If the user cannot delete it, the option will not exist.&#x20;

<div align="left"><figure><img src="/files/UXckZ07cZ3SYqwi0Hnhr" alt=""><figcaption></figcaption></figure></div>


# Creating a Test Plan

<mark style="background-color:yellow;">Step 1:</mark> From the **Test Plans** tab of the **Runbooks** module, click **New Test Plan**.

<div align="left"><figure><img src="/files/Uf99LJy0vLbXwdPbXBdh" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark>  Select whether to start a new plan or modify an existing test plan.

<div align="left"><figure><img src="/files/gyY8AxX2uxtqbnwik0Vl" alt=""><figcaption></figcaption></figure></div>

If starting from scratch, click **Next**.

If starting from an existing test plan, select that option, then click **Select** next to the plan to use as a template. Click **Next**.

<div align="left"><figure><img src="/files/rhpQ3oshypazhP5sEfJj" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark>  From the **Test Plan Details** tab, insert the test plan title (required) and enter a description and tags. Click **Continue**.

<div align="left"><figure><img src="/files/yQqFi6SG57ASoJFYGtgf" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4:</mark>  From the **Select Procedures** tab, add the relevant procedures to the test plan. Use the filtering options to find desired procedures.&#x20;

Add new procedures by clicking **Select** next to the procedure to include or delete existing ones from the engagement by clicking the x within the procedure box in the right-hand column. Click **Add X Procedures**.

<figure><img src="/files/a7Av1KDmmfcFs7lK1rkb" alt=""><figcaption></figcaption></figure>

<mark style="background-color:yellow;">Step 5:</mark>  Review the engagement coverage. The plan can still be modified from this page by clicking Add Procedures or clicking the X to remove an existing procedure. The order of procedures can also be changed by selecting a box and dragging it to the desired location.

When ready, click **Create Test Plan**.

<figure><img src="/files/5YBgHC9TTcBdJxSVFefe" alt=""><figcaption></figcaption></figure>

The engagement is now ready to be started. Click **Start new engagement**, or click **Close** and return to the **Test Plans** tab.

<div align="left"><figure><img src="/files/4RbGoaN8oqJklcUdekz4" alt=""><figcaption></figcaption></figure></div>

The test plan is now listed for future access on the Test Plans tab.

<div align="left"><figure><img src="/files/upw9h9zEu9CyKbkMl3Fh" alt=""><figcaption></figcaption></figure></div>


# Exporting a Test Plan

Test plans can be exported locally as a YAML file.

From the **Test Plans** tab of the **Runbooks** module, click the three dots under the "Actions" menu of the test plan and then click **Export**.&#x20;

<div align="left"><figure><img src="/files/wquUMFkrlQl33fsjaGDp" alt=""><figcaption></figcaption></figure></div>

A dialog box will appear confirming the download. Click **Continue export**.&#x20;

<div align="left"><figure><img src="/files/kNHVoK1DzaK0bXkBX1wI" alt=""><figcaption></figcaption></figure></div>

The test plan will download to the local device as a YAML file.


# Findings

PlexTrac's enhanced findings management capabilities aim to streamline Continuous Threat Exposure Management (CTEM) by breaking away from traditional report-centric workflows. These improvements give users a centralized and dynamic approach to managing findings, enabling real-time insights into security issues, prioritization, and remediation activities.

<div align="left"><figure><img src="/files/DJuXRRRA5E06QvviDe1j" alt="" width="563"><figcaption></figcaption></figure></div>

This approach allows pentesters to look at the vulnerability from the perspective of a finding or an instance.&#x20;

The key difference between a **finding** and an **instance** lies in their granularity and scope in identifying asset vulnerabilities.

**Finding:** A finding refers to identifying a vulnerability on an asset. It represents a single occurrence of a vulnerability appearing on an asset, uniquely identified by attributes such as plugin ID, port, and protocol. Findings determine whether an asset is vulnerable to a specific issue. For example, if a vulnerability affects 50 assets, there will be 50 findings, one for each affected asset.

**Instance:** An instance is a more granular representation of how a vulnerability manifests on an asset. It refers to the specific condition(s) on an asset that cause it to be vulnerable. An asset can have multiple instances of the same vulnerability due to factors like multiple versions of vulnerable software installed or exposure through different network ports. Instances provide the most detailed view of vulnerabilities and are critical for assessing risk at the most specific level.

{% hint style="info" %}
The views and functionality seen in the findings and instances tabs are the same if viewed from within the **Clients** module.&#x20;
{% endhint %}

## Key Benefits&#x20;

The findings and instances tabs offer several key benefits that enhance vulnerability management and workflow efficiency.&#x20;

* **Improved Visibility Across Clients**: The findings tab allows users to see all unique vulnerabilities across their authorized clients. This enables enterprise-level oversight of issues, deduplicated by source, title, and client, providing clarity on the scope of vulnerabilities within an organization.
* **Granular Breakdown of Vulnerabilities**: The instances page complements the findings view by detailing specific occurrences of each vulnerability across individual assets. This differentiation helps users assess whether an issue is widespread across critical assets or isolated to low-priority ones, aiding in risk prioritization.
* **Support for Light Vulnerability Management**: The tabs enable a streamlined approach to vulnerability management by creating unique records of vulnerabilities on specific assets. This allows organizations to track issues more effectively and navigate workflows more precisely.
* **First Seen Tracking**: The platform tracks when vulnerabilities were first detected in external tools and within the platform itself. This historical context supports better risk assessment and positions the platform as a data aggregation tool for managing security issues.
* **Simplified Permissions Model**: The tabs leverage existing client authorization without introducing new permissions.&#x20;
* **Automation of Findings and Instances Creation**: When reports are published, findings and instances are automatically created based on the data provided. This reduces manual effort and ensures accurate tracking of vulnerabilities across assets.


# Findings Components

By breaking away from traditional report-first workflows, findings are managed independently at the client and tenant levels, enabling teams to track, analyze, and remediate vulnerabilities more effectively.&#x20;

The Findings module consists of two tabs: **Findings** and **Instances**.&#x20;

{% hint style="info" %}
A finding represents a unique vulnerability occurrence for a specific client, while an instance represents each specific occurrence of that finding on a single asset.
{% endhint %}

## Findings Tab

The findings tab displays client-level findings, deduplicated by source and title, providing a view of unique organizational issues. A user needs authorization for every client to see all findings across the tenancy.&#x20;

### Findings Overview Section

The Findings overview section provides a consolidated view of findings and is updated hourly. It includes analytics to understand progress, such as findings by severity and a breakdown of total open findings, so users can determine what to work on next. The data can be filtered by date values and client(s).

<div align="left"><figure><img src="/files/YPlHR5YojOK2ISo9xKg6" alt="" width="563"><figcaption></figcaption></figure></div>

### Findings Inventory Section

The findings inventory list displays all client-level findings in one place, deduplicated by source and title. A user needs authorization for every client to see all findings across the tenancy.&#x20;

<div align="left"><figure><img src="/files/iXbsOxGo0PwK33WUkVYN" alt="" width="563"><figcaption></figcaption></figure></div>

## Instances Tab

A finding is a unique vulnerability within a client, while an instance is a specific occurrence of that finding on a single asset.

To illustrate:

1. **Findings Tab**: If a "Wireless Data Extraction" vulnerability exists, it is counted as one finding for each unique client where it occurs, provided the source and title are also unique. If a user has authorization to view all clients, they will see every unique vulnerability across the entire organization.
2. **Instances Tab**: When a user clicks on the "Wireless Data Extraction" finding and views its instances, they will see a list of all unique assets affected by that vulnerability. For example, if the vulnerability impacts three different assets, the page will display three instances, each representing the occurrence of the vulnerability on a specific asset.\
   \
   ![](/files/4Qw45OQnD2LyRrVkateU)

{% hint style="info" %}
A finding will always have one or more instances, while an instance will only have one finding.
{% endhint %}

### Instances Overview Section

The Instances overview section provides a snapshot of instances by status, score, and assignee, enabling users to analyze and organize finding data efficiently. The container can be collapsed by clicking the arrow at the top right.

<div align="left"><figure><img src="/files/pnWRxgxRvgscHqQlkYRP" alt="" width="563"><figcaption></figcaption></figure></div>

### Instances Inventory Section

The instances table provides a detailed breakdown of specific vulnerabilities or issues across an organization's assets. Each instance represents a unique finding on a single asset, offering granular visibility into where and how often an issue appears.&#x20;

Findings are deduplicated at a higher level, while instances show the exact scope of the problem across multiple assets, helping to determine whether an issue is widespread or isolated. Additionally, the table tracks when vulnerabilities were first detected, offering historical context for assessing how long issues have persisted.

<figure><img src="/files/OxpO4LwOohIMnJ4GnTUP" alt=""><figcaption></figcaption></figure>


# Managing Findings

The **Findings** module provides a streamlined approach to managing findings, providing enhanced visibility, automation, and granularity for vulnerability management.

## **Interacting with Metrics**

The metrics default to all clients that the user can access. Filtering by clients and date narrows the data set.

{% hint style="warning" %}
These fields do not impact the findings shown in the findings table.
{% endhint %}

<div align="left"><figure><img src="/files/K25wKFnNeCrFfBgdnSUw" alt="" width="563"><figcaption></figcaption></figure></div>

Hovering the cursor over a specific date will generate a pop-up with detailed information related to that date.&#x20;

<div align="left"><figure><img src="/files/6H1BfrP3GInk8wcpGV14" alt="" width="508"><figcaption></figcaption></figure></div>

Clicking on severity values hides them from the chart.

<div align="left"><figure><img src="/files/Mlmjd2ZXRI6AeecxylaT" alt="" width="527"><figcaption></figcaption></figure></div>

Clicking the severity bar graph in the "open findings" window will result in all `Open` or `In Process` findings with that severity being displayed in the table below.&#x20;

<div align="left"><figure><img src="/files/sWSEkNgXnfJ5yGwiTxnP" alt="" width="536"><figcaption></figcaption></figure></div>

## Using Filters

When filters have been set, the option to "Reset filters" is next to the findings count in the table header.&#x20;

<div align="left"><figure><img src="/files/JSeEjdPANYDEDffeLa1q" alt="" width="563"><figcaption></figcaption></figure></div>

The number of filters used in a specific column is identified with a purple number next to the column header.

## Viewing a Finding Instance

Click a finding row to view its instances (one or more, CVE and CWE scores (when applicable), seen history, metadata, and other options to edit the instance.

<div align="left"><figure><img src="/files/inoSHZ7PRCG4I3WxBFED" alt="" width="563"><figcaption></figcaption></figure></div>

## Viewing the Finding Activity Log

To view the activity log for a finding, click the **Activity** button in the top-right corner of the page.

{% hint style="info" %}
This feature is available to Admin users only.
{% endhint %}

<figure><img src="/files/FZjFUf2898hBYj73UX0B" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
The activity log displays events recorded on or after the 2.17 release (May 21, 2025). Activity prior to this date is not included.
{% endhint %}

## Deleting a Finding

Click Delete under the "Actions" menu to delete a finding from this table.

<div align="left"><figure><img src="/files/oR4LvjKl1aWxtwJpSpDD" alt="" width="563"><figcaption></figcaption></figure></div>

## Configuring Table View

The table view can be customized by clicking the column view icon to the right of the search bar. Once clicked, a modal appears that lists all fields.

<div align="left"><figure><img src="/files/UVAKpefkdCEXe6O4P7gg" alt="" width="407"><figcaption></figcaption></figure></div>

To remove a column, click the X within the bar. Fields that are required and cannot be eliminated do not have an X available.

When fields are removed, an "Add column" pulldown menu appears at the bottom left of the modal to store the field. Any removed fields can be added later by clicking **Add column** and selecting the field to add.

This modal represents the sequence of fields shown in the table, meaning the bar at the top corresponds to the column on the far left of the relevant box. The order of columns can be adjusted within this modal by clicking the six dots on the left of the bar for a field and dragging the bar to the desired position in the sequence.

Click **Save** when finished.


# Managing Instances

The **Instances** tab provides users with a detailed view of vulnerabilities at the asset level, enabling precise tracking and management of specific occurrences. Instances pair a finding with an affected asset, offering granular insights into how vulnerabilities manifest across an organization's infrastructure.&#x20;

Users can edit instance details, such as severity, status, tags, and evidence, while activity logs maintain a complete history of changes for transparency. Bulk actions streamline workflows, allowing users to add instances to reports or update remediation statuses efficiently.&#x20;

## **Interacting with Metrics**

The metrics provide data on all instances the user has client permissions to view.&#x20;

Clicking on the status in the box can toggle a value and update the listing in the table.

<div align="left"><figure><img src="/files/57QNJMAvnCMoVlFzxHDP" alt="" width="563"><figcaption></figcaption></figure></div>

Change the score value presented by selecting a different value in the pulldown menu.

<div align="left"><figure><img src="/files/KDKnssoxrmoP6r4XiSMj" alt="" width="386"><figcaption></figcaption></figure></div>

## Using Filters

When filters have been set, the option to "Reset filters" is next to the instance count in the table header.&#x20;

<div align="left"><figure><img src="/files/dRWWerLhLq5Qaeh9RPJl" alt="" width="563"><figcaption></figcaption></figure></div>

The number of filters used in a specific column is identified with a purple number next to the column header.

## Viewing an Instance

Click a row to launch a side drawer with details about the instance.&#x20;

<div align="left"><figure><img src="/files/7Ly2cRr6EvGt180uMWio" alt="" width="563"><figcaption></figcaption></figure></div>

The Affected ports and Activity tabs are available for viewing. The instance can be edited by clicking the edit icon at the upper right-hand corner.

## Viewing the Instance Activity Log

To view an instance's activity log, click the Activity tab in the instance detail.

{% hint style="info" %}
This feature is available to Admin users only.
{% endhint %}

<figure><img src="/files/dnKlicI5tQgX2H83qkQE" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
The activity log displays events recorded on or after the 2.17 release (May 21, 2025). Activity prior to this date is not included.
{% endhint %}

## Actions Menu

Click **Edit** under the "Actions" menu to go directly to the edit page.

<div align="left"><figure><img src="/files/4QXdZKzEzB5EhSQ2ufUs" alt="" width="468"><figcaption></figcaption></figure></div>

Click **Delete** under the "Actions" menu to delete an instance.&#x20;

<div align="left"><figure><img src="/files/O0Aw8X9zaI3gyiTTZDEq" alt="" width="468"><figcaption></figcaption></figure></div>

Click the three dots for additional options, such as adding tags, changing status, or adding ports.

<div align="left"><figure><img src="/files/LfAklIvW1N1yam5xFuDG" alt="" width="468"><figcaption></figcaption></figure></div>

## Bulk Updates

To access the bulk actions menu, click on any box to the left of an instance's name or next to the column header to select all instances on the page.

<div align="left"><figure><img src="/files/pGD9zzSW0zSDqWpCwpu1" alt="" width="436"><figcaption></figcaption></figure></div>

Click **Actions** to see the list of options for bulk update, such as adding tags, changing status, or adding ports.

## Configuring Table View

The table view can be customized by clicking the column view icon to the right of the search bar. Once clicked, a modal appears that lists all fields.

<div align="left"><figure><img src="/files/UVAKpefkdCEXe6O4P7gg" alt="" width="407"><figcaption></figcaption></figure></div>

To remove a column, click the X within the bar. Fields that are required and cannot be eliminated do not have an X available.

When fields are removed, an "Add column" pulldown menu appears at the bottom left of the modal to store the field. Any removed fields can be added later by clicking **Add column** and selecting the field to add.

This modal represents the sequence of fields shown in the table, meaning the bar at the top corresponds to the column on the far left of the relevant box. The order of columns can be adjusted within this modal by clicking the six dots on the left of the bar for a field and dragging the bar to the desired position in the sequence.

Click **Save** when finished.


# Account Management

Account settings are accessed by clicking the user name in the upper right of the page.

For standard users (non-admins), the drop-down menu will provide options to select **Profile**, **Help Center**, and **Logout**:

<div align="left"><figure><img src="/files/Iw3K2dY6NuNLkEhvESpY" alt="" width="235"><figcaption></figcaption></figure></div>

For admins, the drop-down menu will provide options to select **Profile**, **Account Admin**, **Help Center**, and **Logout**:

<div align="left"><figure><img src="/files/2OUehO8ndYbL6f6tamTY" alt=""><figcaption></figcaption></figure></div>


# Profile (Personal Settings)

The **Personal Settings** page allows users to upload a profile image, change the user display name, view the email on file, select a theme mode (light or dark), update the user password, configure how dates are displayed, and set up and manage multi-factor authentication (MFA).

The personal settings page is reached by clicking the user name in the upper right and then clicking **Profile**.&#x20;

<div align="left"><figure><img src="/files/596cnX40qeM3fQXScWms" alt="" width="188"><figcaption></figcaption></figure></div>

## Overview

The **Personal Settings** page has three tabs:

<table data-view="cards"><thead><tr><th></th><th></th><th></th><th data-hidden data-card-cover data-type="files"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><strong>Profile</strong></td><td></td><td>manage user name, profile image, date format, configure dark mode</td><td><a href="/files/KWYE1tSGf8Aa5YRNPj3Q">/files/KWYE1tSGf8Aa5YRNPj3Q</a></td><td><a href="/pages/P3y0pY2Tzw1zAKWSVx2h">/pages/P3y0pY2Tzw1zAKWSVx2h</a></td></tr><tr><td><strong>Change Password</strong></td><td></td><td>change and update password for security compliance</td><td><a href="/files/KWYE1tSGf8Aa5YRNPj3Q">/files/KWYE1tSGf8Aa5YRNPj3Q</a></td><td><a href="/pages/PjbWopAZWoiDajWa4oqe">/pages/PjbWopAZWoiDajWa4oqe</a></td></tr><tr><td><strong>Two-Factor Authentication</strong></td><td></td><td>set up and configure two-factor authentication</td><td><a href="/files/KWYE1tSGf8Aa5YRNPj3Q">/files/KWYE1tSGf8Aa5YRNPj3Q</a></td><td><a href="/pages/UVjdGFbbHjp2GiPN5ia3">/pages/UVjdGFbbHjp2GiPN5ia3</a></td></tr></tbody></table>

<div align="left"><figure><img src="/files/DtzCWYxEbAZ9OOKrjVQj" alt=""><figcaption></figcaption></figure></div>


# Managing User Profile

The Profile tab allows users to customize and manage their accounts by adjusting their user names and profile pictures. They can also tailor the date format to their personal preference or regional settings. Plus, there's an option for a dark mode interface that's easy on the eyes in low-light conditions.

## Changing User Profile Image

<mark style="background-color:yellow;">Step 1:</mark> From the **Profile** tab of the **Personal Settings** page, click the avatar circle under "Profile Image" to bring up a dialog box.

<div align="left"><figure><img src="/files/ZC9nexCaBUAVThGDlB5Z" alt="" width="342"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Drag an image to the dialog box or click the box to navigate to the file on the computer. Click **Submit**.&#x20;

<div align="left"><figure><img src="/files/BgLfD9OO0UmZKqfggAFD" alt="" width="401"><figcaption></figcaption></figure></div>

The new image is now shown in the **Profile** tab and next to the user name at the top right of the page.&#x20;

### Deleting a Profile Image

<mark style="background-color:yellow;">Step 1:</mark> From the **Profile** tab of the **Personal Settings** page, click the avatar circle under "Profile Image" to bring up a dialog box.

<div align="left"><figure><img src="/files/H30nJ8r102grCasJh7kR" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Click **Delete Profile Image**. The modal will disappear, and PlexTrac will revert to the default grey avatar icon.&#x20;

<div align="left"><figure><img src="/files/6F84SVdaxnkov0Jl3XPY" alt="" width="398"><figcaption></figcaption></figure></div>

The modal will disappear, and PlexTrac will revert to the default grey avatar icon.&#x20;

## Managing User Name

The name displayed for a user throughout PlexTrac is managed here. Users can update their information by entering the desired values in the "First Name" and "Last Name" fields.&#x20;

<div align="left"><figure><img src="/files/fgZT7zuvjo7B7OQy2v2G" alt="" width="563"><figcaption></figcaption></figure></div>

After making the necessary changes, click **Update Settings** at the bottom of the page to save the updated information.&#x20;

{% hint style="info" %}
All changes to a user name must be confirmed by clicking **Update Settings**.\
![](/files/sYSFRaAesB9T8LzK83Bb)
{% endhint %}

The new name value may not appear immediately without a browser refresh. To confirm the change, an email will be sent to the address on file.

## Choosing Theme Mode

To switch between Light and Dark Mode on PlexTrac, adjust the toggle button under "Theme Mode."&#x20;

<div align="left"><figure><img src="/files/rPkm26rgtdbU7FkKTlTf" alt=""><figcaption></figcaption></figure></div>

## Choosing Date Format

The date format can be configured to display in one of three options: **YYYY-MM-DD**, **DD-MM-YYYY**, or **MM-DD-YYYY.**

<div align="left"><img src="/files/IBoGKErYoruCt7Fxp6BG" alt=""></div>


# Managing Password

Users can change their password in the **Personal Settings** section by navigating to the **Change Password** tab. This feature empowers users to maintain the security and integrity of their accounts by periodically updating their passwords.

<div align="left"><figure><img src="/files/Q26nV5oW8A4nL8VoShf6" alt=""><figcaption></figcaption></figure></div>

## Password Requirements

All of the listed requirements must be met to create an acceptable password.

* a minimum of 12 characters
* one lowercase character
* one uppercase character
* one number
* one special character

{% hint style="info" %}
Users can access the password requirements within the platform by clicking on the "?" next to the "Enter New Password" label.&#x20;
{% endhint %}


# Setting Up Two-Factor Authentication

PlexTrac enables two-factor authentication at the account level and is managed on the **Two-Factor Authentication** tab of the **Personal Settings** page. Two-factor authentication is a security measure that requires users to provide two forms of identification to access an account or system.

<figure><img src="/files/yWFIMnBZdsQ70QpK6PUB" alt=""><figcaption></figcaption></figure>

Two-factor authentication (2FA) is a security measure that significantly protects against unauthorized access to sensitive information and accounts. It works by adding an extra layer of verification to the traditional password or PIN login process. When users log in, they must provide their regular credentials, such as a username and password, and a second form of authentication.

The second authentication factor can take various forms, such as a unique code sent to the user's mobile device via SMS or generated by an authentication app, a fingerprint or facial recognition scan, a hardware token, or even a one-time password sent to an email address. The significance of 2FA lies in its ability to counteract the vulnerabilities of using passwords alone.

### Setting up Two-Factor Authentication

<mark style="background-color:yellow;">Step 1:</mark> Click the **Two-Factor Authentication** tab on the **Personal Settings** page.

<div align="left"><figure><img src="/files/9mUOBIwmmhZTP75jXQt7" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Click **Set up Two-Factor Authentication**.

<div align="left"><figure><img src="/files/oqNZP4ZU0rdB60mnIx3Z" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Scan the QR code with the phone and input the token provided on the device.

<div align="left"><figure><img src="/files/8Vg8Vsm66lJr43jkiPtA" alt="" width="399"><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 4:</mark> Click **Confirm**. The modal will disappear, and a message will confirm that Two-factor Authentication is enabled.

<div align="left"><figure><img src="/files/jcH2pNyGGVlILXXL5pLW" alt=""><figcaption></figcaption></figure></div>

### Resetting Token for Two-Factor Authentication

<mark style="background-color:yellow;">Step 1:</mark> Click the **Two-Factor Authentication** tab on the **Personal Settings** page.

<div align="left"><figure><img src="/files/9mUOBIwmmhZTP75jXQt7" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Click **Reset Token**.&#x20;

<div align="left"><figure><img src="/files/fckQQZverXrk7tk2UZoI" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> A confirmation modal appears. Click **Reset**.

<div align="left"><img src="/files/ro7JyOhhRalIocbDzAtI" alt="" width="363"></div>

<mark style="background-color:yellow;">Step 4:</mark> Scan the QR code and click **Confirm**.&#x20;

### Disabling Two-Factor Authentication

<mark style="background-color:yellow;">Step 1:</mark> Click the **Two-Factor Authentication** tab on the **Personal Settings** page.

<div align="left"><figure><img src="/files/9mUOBIwmmhZTP75jXQt7" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Click **Disable Two-Factor Authentication**.&#x20;

<div align="left"><figure><img src="/files/Q8b0ePOAJKczjN6dOBBu" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> A confirmation appears. Click **Disable**.

<div align="left"><figure><img src="/files/2XT6idO13Ow6HdF8tkZc" alt=""><figcaption></figcaption></figure></div>


# Account Admin

The **Admin Dashboard** is reached by clicking the user name in the upper right of the page and then clicking **Account Admin**.&#x20;

<div align="left"><figure><img src="/files/NQAySwCUYwg6UTP12Vkh" alt=""><figcaption></figcaption></figure></div>

The **Admin Dashboard** includes the following sections:

<table data-view="cards"><thead><tr><th align="center"></th><th align="center"></th><th data-hidden data-card-target data-type="content-ref"></th><th data-hidden data-card-cover data-type="files"></th></tr></thead><tbody><tr><td align="center"><strong>Tenant Settings</strong></td><td align="center"><br>answer types, email templates, tags, SLAs, finding sub-statuses, short codes</td><td><a href="/pages/wnKDolnhPymuPrJygXMA">/pages/wnKDolnhPymuPrJygXMA</a></td><td><a href="/files/BgeFBOiVZraNWVmeDg9i">/files/BgeFBOiVZraNWVmeDg9i</a></td></tr><tr><td align="center"><strong>Customizations</strong></td><td align="center"><br>findings layouts, report templates, export templates, dark mode, theme color configuration</td><td><a href="/pages/BsoWdRXcUhemLQvejpqj">/pages/BsoWdRXcUhemLQvejpqj</a></td><td><a href="/files/78jQ5lSVCvpnEWD5h1TH">/files/78jQ5lSVCvpnEWD5h1TH</a></td></tr><tr><td align="center"><strong>Automations</strong><br></td><td align="center">configuration of contextual scoring and score equations for the Priorities module, parser actions</td><td><a href="/pages/HdsY2M2nofsPQt5miKfD">/pages/HdsY2M2nofsPQt5miKfD</a></td><td><a href="/files/Zx1Blunvl4ewEddaddfS">/files/Zx1Blunvl4ewEddaddfS</a></td></tr><tr><td align="center">I<strong>ntegrations &#x26; Webhooks</strong></td><td align="center"><br>integration set up and configuration for third-party solutions, filed mappings where applicable,  webhook configuration</td><td><a href="/pages/FEbwWcUjoLU6g3mczUBa">/pages/FEbwWcUjoLU6g3mczUBa</a></td><td><a href="/files/3lxBxaziiJMgTISnE57F">/files/3lxBxaziiJMgTISnE57F</a></td></tr><tr><td align="center"><strong>Security &#x26; User Management</strong></td><td align="center">authentication setup, RBAC, manage users, passwords, classification tiers, and audit logging for the platform</td><td><a href="/pages/Zk5TKrGS6AO0gkzGr7kT">/pages/Zk5TKrGS6AO0gkzGr7kT</a></td><td><a href="/files/dyJief8pn6zutTW7d8Yl">/files/dyJief8pn6zutTW7d8Yl</a></td></tr><tr><td align="center"><strong>Licensing</strong></td><td align="center"><br>license key entry, log of tenant licenses for modules and integrations, configure priority association at tenant or client level</td><td><a href="/pages/taIsctGuXqW6QJP3JaI3">/pages/taIsctGuXqW6QJP3JaI3</a></td><td><a href="/files/5LzI9YklhHMaa9V36PuT">/files/5LzI9YklhHMaa9V36PuT</a></td></tr><tr><td align="center"><strong>White Labeling</strong></td><td align="center"><br>menu item and white labeling, core platform white labeling</td><td><a href="/pages/NdkJzKDUvfAy9PrljMYt">/pages/NdkJzKDUvfAy9PrljMYt</a></td><td><a href="/files/aXXEwByf38btRzHZGmvJ">/files/aXXEwByf38btRzHZGmvJ</a></td></tr></tbody></table>


# Tenant Settings

In **Tenant Settings**, admins can manage different aspects of their tenant effectively. They can change the tenant name, activate dark mode for a personalized feel, view and add licenses, set default finding status, configure sub-status options, manage notification and server settings, create email templates, and set up short codes.

**Tenant Settings** contains the following sections:

<table data-view="cards"><thead><tr><th align="center"></th><th align="center"></th><th data-hidden data-card-cover data-type="files"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td align="center"><strong>Account Information</strong></td><td align="center">manage tenant name, set dark mode, update tenant logo and icons, enter and view licenses</td><td><a href="/files/jl05Fgr4KMfaMNqfvMIa">/files/jl05Fgr4KMfaMNqfvMIa</a></td><td><a href="/pages/-MRvquQ4i_Auyb16XalP">/pages/-MRvquQ4i_Auyb16XalP</a></td></tr><tr><td align="center"><strong>General Settings</strong></td><td align="center">answer types, default findings status, sub-status configuration, rapid templating</td><td><a href="/files/jl05Fgr4KMfaMNqfvMIa">/files/jl05Fgr4KMfaMNqfvMIa</a></td><td><a href="/pages/-MRvuXHxeDJME3LQA5bW">/pages/-MRvuXHxeDJME3LQA5bW</a></td></tr><tr><td align="center"><strong>Email Settings</strong></td><td align="center">manage notification settings, server settings, email templates</td><td><a href="/files/jl05Fgr4KMfaMNqfvMIa">/files/jl05Fgr4KMfaMNqfvMIa</a></td><td><a href="/pages/-MRvxvwVbCuby88LbBKQ">/pages/-MRvxvwVbCuby88LbBKQ</a></td></tr><tr><td align="center"><strong>Tags Settings</strong></td><td align="center">manage the list of tags existing in a tenant</td><td><a href="/files/jl05Fgr4KMfaMNqfvMIa">/files/jl05Fgr4KMfaMNqfvMIa</a></td><td><a href="/pages/-MRvzi-XEDyNQxpOLgrE">/pages/-MRvzi-XEDyNQxpOLgrE</a></td></tr><tr><td align="center"><strong>Service-Level Agreements</strong></td><td align="center">manage the business rules for SLAs</td><td><a href="/files/jl05Fgr4KMfaMNqfvMIa">/files/jl05Fgr4KMfaMNqfvMIa</a></td><td><a href="/pages/EW4dD2T4ngoUHF9iHhkS">/pages/EW4dD2T4ngoUHF9iHhkS</a></td></tr><tr><td align="center"><strong>Short Codes</strong></td><td align="center">set up and configure short codes</td><td><a href="/files/jl05Fgr4KMfaMNqfvMIa">/files/jl05Fgr4KMfaMNqfvMIa</a></td><td><a href="/pages/-MadzY9DH8VsQS_A_DvH">/pages/-MadzY9DH8VsQS_A_DvH</a></td></tr></tbody></table>


# Account Information

The **Account Information** button under "Tenant Settings" in the **Admin Dashboard** provides configuration of tenant information, including changing the tenant theme (light or dark), uploading a tenant logo and icon, and changing tenant name.

<div align="left"><figure><img src="/files/YWRo8XjdpphuF6prmaQV" alt=""><figcaption></figcaption></figure></div>

## Changing Tenant Light/Dark Mode

To change the mode of the tenancy from light to dark, click the desired mode. The change is immediate.&#x20;

<div align="left"><img src="/files/4Bn4CzERJFH4iL94vq4O" alt=""></div>

Any images loaded light mode will disappear. Images will need to be reloaded for dark mode.

## Adding Tenant Images

{% hint style="info" %}
The Tenant logo and icon need to be updated in both light and dark mode.<br>

Dimensions of the tenant icon image file should have the same height and width.&#x20;
{% endhint %}

<mark style="background-color:yellow;">Step 1:</mark> Click **Upload Tenant Images**.

<div align="left"><figure><img src="/files/9KQK9aJgCqF1nDQbiokn" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 2:</mark> Click the box of the image to upload, and drag the file into the box or navigate to that image on the computer.

{% hint style="info" %}
The dimensions of the tenant icon image should have the same height and width (i.e., 500px x 500px).
{% endhint %}

<div align="left"><figure><img src="/files/hGDJHlqg2SCNcEqMIX5O" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step 3:</mark> Click **Submit**.&#x20;

<div align="left"><figure><img src="/files/fYlVs1pC5pYkoRVvRt7R" alt=""><figcaption></figcaption></figure></div>

The logo will appear at the top of the left navigation bar.

<div align="left"><figure><img src="/files/UcBwvRd2c9jVrkzDVfph" alt=""><figcaption></figcaption></figure></div>

## Editing Tenant Name

<mark style="background-color:yellow;">Step 1:</mark> Click **Edit Tenant Information.**

<div align="left"><figure><img src="/files/agk1KAlZlZrw46DZK5xB" alt=""><figcaption></figcaption></figure></div>

<mark style="background-color:yellow;">Step</mark> **2**<mark style="background-color:yellow;">:</mark> Enter the desired information and click **Submit.**

<div align="left"><figure><img src="/files/3SxMxHDuiiKmfugFxhLS" alt=""><figcaption></figcaption></figure></div>

The new value appears on the **Account Information** page. After refreshing page, the new value appears as the Tenant Administration value.&#x20;

<div align="left"><figure><img src="/files/S9ZAqVAciku5ejuCI0RX" alt=""><figcaption></figcaption></figure></div>




---

[Next Page](/plextrac-documentation/llms-full.txt/1)

