PLAYBOOKS NET HOST ATTRIB DETECT
← all playbooks
GENERATOR
Live Hunt Playbook Generator
Drop an nmap XML or host-port CSV export. This compiles a right-now hunt plan from what your scan actually exposed, routed into NET techniques and PLAYBOOKS exploits. It generates hypotheses to chase, never findings.
input: nmap XML or host-port CSV · engine: scan-correlation table · output: ranked if/then worklist · disposable, export to keep
[ + ]
Drop an nmap XML or scan CSV here, or click to choose
nmap -oX output, or a host-port CSV: ip_address, os_match, port_number, protocol, state, service, product, version
What this is. A plan compiled from one scan. Every lead below is a hypothesis with the queries pre-filled, not a detection. Exploit routing is based on nmap's best-effort banner, which is often blank or wrong, so a version match reads as reported, go confirm, never vulnerable. This is standing-state: it flags what is exposed now, not what changed. Your own validation is the filter for what is already known-good.
Your scan stays in your browser. This page parses the file locally with JavaScript and never uploads it. There is no server side to this tool, no fetch, no storage, no telemetry: view source and search for fetch, there isn't one. Note the honest caveat that this page is itself served over the network, so its integrity depends on the site hosting it. For scans of sensitive or classified estates, use the offline TONK kit, where nothing is served at all.