Agent Testing Logs
How to download agent testing logs for Hannibal findings to review the agent's reasoning and evidence trail.
Overview
When Hannibal runs a hunt against an asset, it produces a structured log of everything the agent tested, what it observed, and how it reached its conclusion. You can download this log directly from the finding drawer — without involving a Praetorian engineer.
Agent testing logs are available only for findings produced by Hannibal hunts. Non-Hannibal findings retain the standard one-click vulnerability export.
Downloading an Agent Testing Log
- Open the finding drawer for a Hannibal finding.
- Locate the Export menu in the drawer toolbar.
- Choose Agent testing logs from the export options.
- The Vulnerability data option is also available here if you need the standard finding export.
- Guard queues a background job to assemble the log. You do not need to keep the drawer open — closing it does not interrupt the export.
- Monitor progress in the Exports panel in the top navigation bar. When the log is ready, download it from there.
What the Log Contains
The agent testing log is a complete record of the agent's activity for the finding, including:
- Tests performed — Each action the agent took against the target asset.
- Observations — What the agent found at each step.
- Reasoning — How the agent interpreted the evidence and reached its conclusion.
This gives you full visibility into the agent's decision-making process and the evidence underlying each Hannibal finding.
Export Delivery
Log assembly runs asynchronously as a background job. Progress is tracked in the top-nav Exports experience — the same location used for other platform exports. Large or complex logs may take longer to assemble; the export panel will reflect the current status.
Support
If you have questions about agent testing logs or Hannibal findings, contact support@praetorian.com.