Agent Testing Logs

How to download agent testing logs for Hannibal findings to review the agent's reasoning and evidence trail.

Overview

When Hannibal runs a hunt against an asset, it produces a structured log of everything the agent tested, what it observed, and how it reached its conclusion. You can download this log directly from the finding drawer — without involving a Praetorian engineer.

Agent testing logs are available only for findings produced by Hannibal hunts. Non-Hannibal findings retain the standard one-click vulnerability export.

Downloading an Agent Testing Log

  1. Open the finding drawer for a Hannibal finding.
  2. Locate the Export menu in the drawer toolbar.
  3. Choose Agent testing logs from the export options.
    • The Vulnerability data option is also available here if you need the standard finding export.
  4. Guard queues a background job to assemble the log. You do not need to keep the drawer open — closing it does not interrupt the export.
  5. Monitor progress in the Exports panel in the top navigation bar. When the log is ready, download it from there.

What the Log Contains

The agent testing log is a complete record of the agent's activity for the finding, including:

  • Tests performed — Each action the agent took against the target asset.
  • Observations — What the agent found at each step.
  • Reasoning — How the agent interpreted the evidence and reached its conclusion.

This gives you full visibility into the agent's decision-making process and the evidence underlying each Hannibal finding.

Export Delivery

Log assembly runs asynchronously as a background job. Progress is tracked in the top-nav Exports experience — the same location used for other platform exports. Large or complex logs may take longer to assemble; the export panel will reflect the current status.

Support

If you have questions about agent testing logs or Hannibal findings, contact support@praetorian.com.