Glossary
NSE Script
A script written in the Nmap Scripting Engine (Lua) that extends a scan beyond port/service detection — enumerating shares, checking default credentials, or testing for a specific known vulnerability.
NSE (Nmap Scripting Engine) scripts are small Lua programs bundled with Nmap — over 600 of them — that run against discovered hosts/ports to do something a plain port scan can't: enumerate SMB shares, grab an SSL certificate's details, check for anonymous FTP login, or actively test for a specific CVE.
Scripts are grouped into categories and run with --script <name-or-category>,
for example:
nmap -sV --script vuln,vulners -oX scan.xml 10.0.0.0/24
Categories worth knowing
vuln— actively tests for specific, named vulnerabilities (smb-vuln-ms17-010,ssl-heartbleed,http-vuln-cve2017-5638…) and reportsVULNERABLEor not.vulners/vulscan— look up the detected product/version against a CVE dataset and list every match with a CVSS score, without needing a specific exploit check per CVE.default(-sC) — a safe, general-purpose set: banner grabbing, title fetching, basic enumeration.auth— checks for things like default credentials or anonymous access (ftp-anon,mongodb-databases).
Each script's output is attached to the port (or the host, for scripts that
look at the whole machine rather than one service) in Nmap's XML. This
parser reads that output directly: it recognizes the vuln/vulners/vulscan
family to surface confirmed vulnerabilities, and a handful of others
(ftp-anon, redis-info, smb-protocols, …) to flag common
misconfigurations.