Skip to main content

Reports

The Reports interface provides comprehensive insights into your Santa deployment, helping administrators understand security posture, rule effectiveness, and system health across the organization.

Overview​

The Reports dashboard offers several analytical views:

  • Top Blockables: Most frequently blocked binaries across your organization
  • Dangerous Entitlements: Binaries with potentially dangerous entitlements
  • Ready for Lockdown: Analysis of hosts that may be ready to transition to Lockdown mode

Top Blockables​

The Top Blockables report displays the most frequently blocked binaries across your organization:

  • Filename: Name of the blocked binary
  • Signing ID: The signing identifier of the binary
  • CDHash: The CodeDirectory hash of the binary
  • Entitlements: Any entitlements associated with the binary
  • Count: Number of times the binary has been blocked

This report helps identify patterns of blocked applications and potential security risks.

Dangerous Entitlements​

The Dangerous Entitlements report highlights binaries that contain potentially risky entitlements:

  • Displays binaries with entitlements that could pose security risks - Provides detailed information about each entitlement - Helps identify applications that may require additional scrutiny

Ready for Lockdown​

The Ready for Lockdown report shows which hosts would block software if they moved to Lockdown mode. It counts the binaries that each host ran with no matching rule. In Monitor mode, Santa allows these binaries. In Lockdown mode, Santa would block them.

  • Hosts: Only hosts that synced during the time window count. The default window is 7 days.
  • Buckets: Each host is Ready, Almost, or Not yet, based on its count of binaries with no rule. By default, Ready means 0 and Almost means 1 or 2. You can change the window and the thresholds in the report settings.
  • In Lockdown: Hosts that are configured for Lockdown mode appear in their own bucket.
  • New rules: The counts include rules that you create after the binaries ran. A new rule moves a host toward Ready without new executions.
  • Host-specific rules: A rule on a single host counts toward that host's bucket. It does not reduce the gap counts or the software table, which count only global rules and tag rules.