Skip to content
Nmap scan analysis · runs 100% client-side

Turn an Nmap scan into a map of your network.

Paste or upload an Nmap export — XML, normal or grepable — and get every host and service, a network map, and matched vulnerabilities and misconfigurations. Parsed entirely in your browser.

Paste or upload an Nmap scan

XML (-oX), normal (-oN) and grepable (-oG) output are all auto-detected.

XML · Normal · Grepable

What it does

From raw scan to actionable findings.

Point it at any Nmap export and get a readable map of the network, every open service, and what's worth fixing first.

Any Nmap export

XML (-oX), normal (-oN), grepable (-oG) or a raw paste — the format is detected automatically.

Vulnerability matching

Detected product/version strings are checked against a curated set of known CVEs, and Nmap's own vuln/vulners script output is parsed directly.

Misconfiguration checks

Anonymous FTP, SMBv1, open Redis/MongoDB/Elasticsearch, exposed Docker/etcd APIs, weak TLS and more — flagged by service and script output.

Network map

Every host grouped by subnet, sized by open ports and colored by its worst finding, so you can scan a whole scan at a glance.

How it works

Three steps, no install.

  1. 01

    Run your scan

    nmap -sV -O --script vuln -oX scan.xml <target> (or -oN / -oG, or just the default terminal output).

  2. 02

    Paste or drop it

    Paste the text or drop the file — the format is detected automatically.

  3. 03

    Read the findings

    Browse hosts, the network map, and vulnerabilities/misconfigurations ranked by severity.

Privacy

Your scan never leaves your browser.

Parsing, vulnerability matching and misconfiguration checks all run locally in WebAssembly. Nothing is uploaded to a server.

  • No upload, no server-side processing
  • Works offline once the page is loaded
  • Nothing is stored unless you export it

FAQ

Questions, answered.

Which Nmap output formats are supported?

XML (-oX), normal (-oN) and grepable (-oG), plus pasting any of those directly. XML carries the most detail (service versions, CPEs, full script output), so it gives the most accurate findings.

Is the vulnerability data complete?

No — it combines a small, hand-curated set of well-known CVEs matched by product/version with direct parsing of Nmap's own vulners/vulscan and *-vuln-* script output when you ran those scripts. It is not a live feed from the NVD. Treat matches as leads to verify, not a complete vulnerability scan.

Does this replace a vulnerability scanner?

No. It's a fast way to triage an Nmap scan you already ran. For authoritative results, run a dedicated scanner (e.g. Nessus, OpenVAS) against the same hosts.

Is my scan uploaded anywhere?

No. Parsing, matching and the network map all run in your browser via WebAssembly. The scan data never leaves your machine.

Found a host worth investigating further? Parse its $MFT to see every file, deleted entries and timestamps.
Pulled a disk image from a host after this scan? Browse E01/VMDK/VHD images and their partitions in the same way.
Need a timeline of file changes on a host you scanned? Parse its $UsnJrnl:$J to see activity in order.

Blog guides & write-ups.

Read the blog
A practical walkthrough of what to look for in Nmap output — service versions worth checking against CVEs, and the misconfigurations that show up again and again.

Ready to parse a scan?

Paste your Nmap output above and see the findings in seconds.

Analyze a scan