Drop an nmap XML or scan CSV here, or click to choose
nmap -oX output, or a host-port CSV: ip_address, os_match, port_number, protocol, state, service, product, version
What this is. A plan compiled from one scan. Every lead below is a hypothesis with the queries pre-filled, not a detection. Exploit routing is based on nmap's best-effort banner, which is often blank or wrong, so a version match reads as reported, go confirm, never vulnerable. This is standing-state: it flags what is exposed now, not what changed. Your own validation is the filter for what is already known-good.
Your scan stays in your browser. This page parses the file locally with JavaScript and never uploads it. There is no server side to this tool, no fetch, no storage, no telemetry: view source and search for
fetch, there isn't one. Note the honest caveat that this page is itself served over the network, so its integrity depends on the site hosting it. For scans of sensitive or classified estates, use the offline TONK kit, where nothing is served at all.