Documentation Index

Fetch the complete documentation index at: https://help.scrut.io/llms.txt

Use this file to discover all available pages before exploring further.

Step 4: Take Actions on Scan Findings

Prev Next

For each scan finding, you can take the following actions:

#1: Remediation

Once Scrut identifies a vulnerability, you can find the relevant details on the individual Findings page. This page includes a helpful section on how to fix the identified vulnerability. Refer to the remediation steps to resolve the issue.

Once fixed correctly, Scrut will not surface the finding in subsequent scans.

#2: Create a Project Management Ticket

You can also assign the finding to the relevant resource owner, developer, engineer, or any other team member for remediation. You can create a work ticket for the remediation task directly in your project management tool from the Findings page in Scrut. To do this, you must have integrated Scrut with any of the supported Project Management tools.

Note:

Scrut currently only supports Jira tickets from the Findings page.

Once done, follow the steps below:

  • You can create a ticket at the finding or resource level.

  • To create a ticket for the finding, click the Create Ticket button at the top of the finding details page.

  • To create a ticket at the resource level, scroll to the Scan Finding Table, select the resource(s) for which you want to create tickets and click the Create Tickets button. Scrut will create a separate ticket for each resource you’ve selected.

  • Enter the ticket details. Scrut auto-fills the ticket’s title and description to provide the required context. You can edit these details if required.

  • Select the assignee, due dates, project/board, and other details. Add optional details if required.

  • Click Create.

Scrut automatically creates the ticket in your project management tool and assigns it to the selected assignee. You can find all linked tickets under the Tickets tab on the Finding Details page. Once the status is updated in your project management tool, it is automatically reflected in Scrut.

Important

If you create a Jira or Linear ticket for a vulnerability and close it after fixing the issue, the vulnerability will NOT automatically move from the open to the closed stage in Scrut.

Instead, Scrut will detect the fix during the next scan. If the vulnerability is no longer present, it will not appear in the scan findings. The vulnerability status is independent of the linked ticket status and depends on actual scan results.

#3: Create a Risk

If a finding is not major or does not impact your business landscape, you can add it to your organization’s Risk Register.  Follow these steps to mark a finding as a risk:

  1. Click the Create Risk button on the individual findings page.

  2. Scrut auto-fills the risk name and description. You can edit these fields if needed.

  3. Set assignees and select the risk category, department, and entities.

  4. Enter the application name, then select the assets affected by this vulnerability.

  5. Click Save.

Scrut directly adds the risk to the risk register, and you can manage it in the Risk module. Once you create a risk, the status of the finding changes from Open to Risk.

#4: Ignore Finding

This option is suitable for irrelevant or false-positive findings.

  1. Click the three-dot icon Three-dots icon.png on the individual findings page and select Ignore.

  2. Provide a valid justification and click Ignore to confirm your action.

  3. The status changes to Ignored.

Note:

If you mark a finding as ignored, Scrut will not surface it in subsequent scans of the target.