Powertrain

POWERTRAIN REPORT ENGINE

Generate a Security Report

Upload up to 32MB. Data is never saved. Wait for the PDF before closing the window.

AUTOMATED SECURITY REPORTING

Powertrain Report Engine

Per-use tokens for individual reports. Enterprise unlimited options are available.

Powertrain
AI analysis

Built for consultants, security firms, and practitioners who need consistent professional security reporting without rebuilding every assessment from scratch.

Powertrain supports forensic, PII, OSINT, CVE, penetration testing, vulnerability assessment, and web application reporting.

Monthly and annual subscriptions are available. Ask about Powertrain Pro for organizations and custom report template creation.

Powered by Tally™ technology. Patent pending. U.S. App. No. 19/368,097.

Supports: Nessus NMAP Burp Suite Nexpose
POWERTRAIN FOR BURP SUITE

Vulnerability Intelligence.
Right Inside Burp.

Powertrain Analyzer integrates Oxytis vulnerability intelligence directly into Burp Suite. Analyze published CVEs or assess scanner findings with no published CVE, calculate risk, enrich findings, and generate actionable security guidance without leaving your testing workflow.

Real-time CVE Analysis Instant access to detailed vulnerability intelligence for published CVEs.
No-CVE Finding Assessment Right-click a Burp Scanner issue to estimate CVSS 4.0 risk when no published CVE exists.
Accurate CVSS 4.0 Scoring Deterministic scoring using FIRST's official CVSS implementation rather than approximation.
EPSS Enrichment Exploit Prediction Scoring System data surfaced alongside CVSS during vulnerability analysis.
SOO Model Analysis Patent-pending Subject, Object, Opportunity analysis for contextual security risk.
HEXAD Security Primitives Comprehensive impact analysis across six security domains.
OWASP Top 10 Mapping Automatic categorization against current OWASP standards.
Context Menu Integration Right-click CVE IDs or scanner findings anywhere in Burp to analyze them.
Professional Reports Generate clean, formatted security reports directly from analysis results.
Background Processing Non-blocking API calls keep Burp responsive while Powertrain analyzes findings.
Powered by Tally™ vulnerability intelligence
INTEGRATED DIRECTLY INTO BURP SUITE
Powertrain CVE Analyzer context menu integration in Burp Suite
Oxytis Powertrain CVE Analyzer interface
Works Where You Test Analyze directly inside Burp.
More Than CVE Lookup Analyze scanner findings with no CVE.
Risk-Enriched Analysis CVSS, EPSS, OWASP and contextual intelligence.
Report the Result Move from analysis to professional output.

Description

Create professional looking reports with Powertrain. A report engine to generate PII (Oxidize), Forensic, OSINT, CVE, and Penetration/Assessment reports integrating Nessus, Nexpose, NMAP or Burpsuite output. Include an your own 'logo' image file or use Oxytis logo for all report types. Look at the examples for each report type to see how to customize the powertrain config. Include valid domain name for extra OSINT and surface web discovery to be added to your reports. Upload multiple Nessus, Nexpose and NMAP files into one report (collated and unique results are presented in detail). Uploaded files are not saved. A report is automatically served after submit! Choose a background 1, 2, or 3 for the cover page. Omit findings and recommendations files to have OpenAI author it for you!


Contact us for assistance with template creation or use the samples provided in each example.

Forensics and Incident Response (DFIR) Reports

Generate DFIR reports using the sample templates. Upload your own logo (logo required in filename), the config, and forensic findings text files to the report engine.

Example files: (sample report)
--Config
--Findings

Oxidize or PII Reports

Generate PII reports using the sample templates. Upload your own logo (logo required in filename), the config, and PII findings text files to the report engine.

Example files: (sample report)
--Config
--Findings

OSINT Reports

Use our OSINT to harvest emails, subdomains (typosquatting), leaked credentials, and find stolen credentials in the dark web. OSINT can be run directly from the form. Enter a valid token and domain name to generate a report, or enter a CVE-####-#####.

Example files: (sample report)
--Config

Internetwork Reports

Generate assessment reports using the sample templates. Upload your own logo (logo required in filename), the config, and findings, recommendations, summary text files to the report engine. Include a domain name to use Oxytis OSINT for email harvesting and leaked credential discovery.

Example files: (sample report)
--Config
--Findings
--Summary
--Recommendations
--Custom
--NMAP * (output from your NMAP command, use -oX)
--Nessus* (output from your Nessus console, save XML)
--Nexpose* (output from your Nexpose/InsightVM console, save XML 2.0)

*You can submit several XML and Nessus|Nexpose output files. Powertrain will properly fuse this data and collate the results.

Web Apps

Generate web app assessment reports using the sample templates. Upload your own logo, the config, and findings, recommendations, summary text files to the report engine. Include a domain name to use Oxytis OSINT for email harvesting and leaked credential discovery.

Example files: (sample report)
--Config
--Findings
--Summary
--Recommendations
--custom (Optional)
--Burpsuite* (save report from Burpsuite, save XML, base64)
To include an image for a finding, make filename.png|jpg the same as the finding title. For example, upload an image called "Cross-site scripting (reflected).png" to include it with that finding.
Cross-site scripting (reflected).png

Copyright 2026 Oxytis Forensics LLC. All Rights Reserved. Privacy Policy