Shadow and Shield / Reporting

Reporting and export outputs.

Shadow and Shield generates unified case-level reports and workflow-specific exports from supported case, evidence, and tool-execution records.

At a Glance

Current report outputs, included records, and integrity boundaries.

This page covers unified Case Summary and Tool Execution reports, available output formats, workflow-specific exports, translated content, and report integrity boundaries.

01 / Scope

Current report scope.

The reporting module generates Case Summary and Tool Execution reports from supported case, evidence, and operation records.

  • Case Summary reports combine supported case, evidence, session, and operation records
  • Tool Execution reports preserve operation-specific configuration, status, timing, actor, and results where recorded
  • Workflow-specific exports remain available for file listings and supported analysis results

02 / Outputs

Report outputs.

Case Summary and Tool Execution reports can be generated in HTML, PDF, CSV, and JSON. Completed reports can be downloaded through the dashboard or copied to mounted Destination media.

  • HTML, PDF, CSV, and JSON report formats
  • Dashboard download and copy-to-Destination workflows
  • File-listing and workflow-specific exports where supported

03 / Tool Records

Tool records.

Reports can draw from supported execution records: tool name, status, timing, actor, case context, configuration, and workflow-specific results where those records exist.

  • Tool execution records and status
  • Case and actor context where recorded
  • Hashes, verification records, acquisition records, keyword results, and hash comparison results where included by the validated report path

04 / Translation

Translated content.

AI-based filename translation can preserve original filenames alongside translated values where supported by the selected workflow and report path.

  • Original and translated filename values where supported
  • Translation model context where implemented

05 / Generation

Generation and storage.

Reports are generated on demand from selected case or operation records and stored locally for review, download, or copying to mounted Destination media.

  • On-demand generation through the dashboard
  • Local report storage with generation status and errors retained
  • Download through the dashboard or copy to mounted Destination media

06 / Integrity

Integrity boundaries.

Report content reflects the records available at generation time. Output hashing, signatures, and regeneration lineage are not represented as universal behavior unless enabled and validated for the selected report path.

  • Generation status, output paths, output sizes, and errors retained where available
  • Report content tied to the selected case or operation records
  • Output hashes and signatures only where the selected report path verifies them
  • Regeneration lineage only where implemented and validated

Report content and available sections depend on the selected report type and records available for the selected case or operation.