Skip to main content

Overview

Finding types group related finding classes to simplify filtering and scoping. Each finding type maps to one or more finding class patterns.

Finding Types Reference

Finding TypeFinding ClassesDescription
Cryptographic Materialcrypto/*Cryptographic assets: algorithms, certificates, keys
Secretsecret/*Embedded credentials: API keys, tokens, passwords
Secret Validatedsecret/leakedSecrets confirmed as valid/active
Mitigation Failuremitigation/*Missing security mitigations: stack canaries, CFI, ASLR
Weaknessweakness/*Code quality issues: unstripped binaries, RPATH issues
Unknown Vulnerabilityvulnerability/uefi/*Zero-day vulnerabilities discovered through deep analysis
Known Vulnerabilityvulnerability/known-vulnerabilityPublicly documented vulnerabilities with CVEs
Supply-Chain Failuresupply-chain/*Supply chain integrity issues
Dependency Vulnerabilityvulnerability/known-vulnerability (derived from dependency analysis)Vulnerabilities in external dependencies
Suspicious Codesuspicious/*Potential tampering or obfuscation patterns
Malicious Codemalware/*Confirmed malicious behavior