Integrate Nmap with Vulnetix. Scan networks for open ports and vulnerabilities using NSE scripts, then export XML results for ingestion into Vulnetix.
Install & scan
$ # Ubuntu/Debian sudo apt-get install nmap # macOS brew install nmap # Verify nmap --version $ # Host discovery + service version + OS detection with XML output nmap -sV -sC -O -oX nmap-results.xml 192.168.1.0/24 # Vulnerability scan using vulners NSE script nmap -sV --script=vulners -oX nmap-vulns.xml 192.168.1.0/24
Run Nmap in CI
Scan on every push and upload the report as a workflow artifact:
- name: Install Nmap
run: sudo apt-get install -y nmap
- name: Run Nmap Scan
run: nmap -sV --script=vulners -oX nmap-vulns.xml ${{ vars.SCAN_TARGET }}
- name: Upload to Vulnetix
run: vulnetix upload --file nmap-vulns.xml
How Vulnetix compares: better together
Vulnetix does not replace Nmap. Keep running it. Vulnetix sits on top of Nmap (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.
| Capability | Vulnetix | Nmap |
|---|---|---|
| Security coverage | ||
| SAST (static code analysis) | ✓ Built-in rules + Semgrep augmentation | ✗ |
| SCA / dependencies | ✓ 40+ ecosystems, transitive graph | ✗ |
| DAST (dynamic testing) | ~ Ingests DAST results; no native dynamic engine | ✗ |
| Container & image | ✓ Image CVEs, base image, Dockerfile | ✗ |
| IaC / misconfiguration | ✓ Terraform, k8s, CloudFormation | ✗ |
| Secret scanning | ✓ 1,000+ rules, source + binary + git history | ✗ |
| Cloud / CSPM | ✓ Cloud-posture findings, compliance tab | ✗ |
| Mobile (MAST) | ~ Ingests mobile scanner output; no native mobile engine | ✗ |
| License compliance | ✓ SPDX, copyleft/AGPL/SSPL policy | ✗ |
| SBOM generation | ✓ CycloneDX 1.7 + SPDX 2.3, cosign-signable | ✗ |
| Malware / supply-chain | ✓ De-duplicated corpus + install-time firewall (25+ registries) | ✗ |
| Network / infra vuln | ~ Ingests network scanner output; no native network scanner | ✓ Core: host/port/service discovery plus NSE vuln-category and version-to-CVE detection |
| Fuzzing | ✗ Ingests fuzzing crashes; no native fuzzer | ✗ |
| Pentest / bug bounty | ✗ Ingests pentest/bug-bounty findings; not a testing service | ✗ |
| The Vulnetix orchestration layer | ||
| Cross-scanner dedup & one queue (ASPM) | ✓ Correlates every scanner into one prioritised queue with ownership routing | ✗ |
| Exploit-intel prioritisation | ✓ EPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV | ✗ |
| Reachability analysis | ✓ Tree-sitter + CVEAffected; direct/transitive/semantic | ✗ |
| Versioned VEX + audit trail | ✓ Immutable OpenVEX/CycloneDX, cosign-signable | ✗ |
| Safe Harbour autofix | ✓ Resolves + applies the nearest safe version | ✗ |
| End-of-life policy | ✓ Flags/blocks past-EOL runtimes & packages | ✗ |
| SSVC / risk-based policy | ✓ SSVC v2 + CISA/FedRAMP/Essential-8 presets | ✗ |
✓ full · ~ partial · ✗ not covered
What Nmap does well
- The definitive open-source host discovery, port and service/version detection tool, with the most widely supported XML output format for tool integration
- Nmap Scripting Engine (NSE) with 600+ Lua scripts, including a vuln category that flags services as VULNERABLE with CVE references
- Extensible via third-party scripts (vulscan, vulners) that map detected service versions to known CVEs using offline DBs or live APIs
- Fast, scriptable and ubiquitous, the de-facto reconnaissance primitive that feeds nearly every other scanner
Where Vulnetix adds to it: Vulnetix ingests and orchestrates Nmap/NSE output: it does not run network discovery or port scans itself. Nmap detects services and CVE candidates; Vulnetix takes those results into a deduplicated, cross-scanner queue and adds the entire prioritisation and governance layer Nmap has no concept of, EPSS/CISA KEV/ESS/LEV scoring, reachability, versioned VEX + audit, Safe Harbour autofix, EOL and SSVC policy.
No migration, no rip-and-replace. Nmap keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.
Centralise Nmap results in Vulnetix
Upload Nmap XML, JSON output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.