Skip to content

Reports & tabletop

Daedalus turns the findings it recorded during an engagement — hosts, services, vulnerabilities, footholds, flags — into a written deliverable, produced by the local model so nothing leaves your infrastructure.

Two outputs

  • Pentest report — an executive summary, per-host findings with evidence, exploited footholds with the access gained, and remediation guidance, all grounded in the recorded data rather than invented.
  • Tabletop exercise (TTX) — a facilitator-ready scenario built from the same findings: an incident narrative, injects, and discussion questions for a blue-team walk-through.

How it's generated

Report generation is a multi-pass, asynchronous pipeline rather than a single prompt:

  1. Analyze the recorded findings into a structured engagement picture.
  2. Draft each section independently against that picture.
  3. Stitch the sections into the final document.

It runs on a background worker and the console polls for progress, so a long generation doesn't hit request timeouts and the result is several times more thorough than a one-shot prompt.

Grounding and references

The report is grounded twice over: once in your findings (it cites the host, service, and evidence behind each claim), and once in a curated real-world reference library — ATT&CK techniques, vulnerability records, advisories, and reputable incident write-ups — matched to the findings' CVEs and services and cited in a dedicated references section. The tabletop variant leans on the same library to keep its scenario realistic.

Detection coverage

When BAS agents have run adversary-emulation in the target's zone, the report gains a Validation & detection coverage section: which ATT&CK techniques were exercised, which the defenses caught, and where the gaps are — cross-linked to the findings that motivated them.

Everything local

Reports are written by the on-GPU model. See Local inference for how the model is tuned to produce thorough output on modest hardware.