From Scanner Output to
Client-Ready Report in Minutes
Import vulnerabilities from Nessus, Burp Suite, NMAP, and common security tools, or any custom format. AttackForge's intelligent parsing engine normalizes and maps findings to your curated writeup library automatically.
Native Imports for the Tools You Already Use
Seamless integration with industry-standard vulnerability scanners and security tools
One-click file upload
No scripting or CLI required
Drag-and-drop interface parses files client-side; data never leaves your browser
Individual vs Grouped import
Choose granularity to match reporting style
Individual = 1 vuln per asset; Grouped = 1 unique vuln with all affected assets included
Severity filtering at import
Ignore noise before it enters your project
Pre-filter by Critical/High/Medium/Low/Info before committing
Automatic writeup creation
Never start from a blank page
If writeup doesn't exist in library, AttackForge creates it from scanner data
CVSS score inheritance
Consistent scoring without manual entry
CVSS vector strings imported; linked to Likelihood of Exploitation
Teams using Grouped import option report a 94% reduction in vulnerabilities to review without losing a single affected host. All asset data is preserved and attached to the consolidated finding.
Turn Reconnaissance into Ready-to-Test Scope
Import NMAP, Masscan, and custom scan results directly into your project scope
Direct-to-project import
Scope population in seconds
Upload scan file → select hosts → assets appear in project instantly
Hostname & port preservation
Full context for every target
Imported assets retain hostnames, open ports, services
Asset Module linkage
Single source of truth
Assets sync to centralised Asset Module for cross-project visibility
Pre-import editing
Fix errors before they propagate
Review and modify parsed data before committing to project
Use Case: Network Pentest Kickoff
Running a network pentest? Upload your NMAP XML at kickoff. In under 60 seconds, your project scope is populated with 500+ hosts, complete with ports and services, ready for testing. No manual data entry, no copy-paste errors, no spreadsheet juggling.
Your Data, Your Format: No Reformatting Required
Import from spreadsheets, legacy tools, or custom security solutions using generic CSV and JSON parsers
Generic CSV parser
Import from spreadsheets, legacy tools, or manual inventories
Generic JSON parser
Import from JSON or other AttackForge projects
Downloadable templates
Know exactly what fields AttackForge expects; no guesswork
Bulk writeup import - CSV or JSON
Migrate entire vulnerability libraries from other platforms
Bulk test case import - CSV or JSON
Bring your custom methodologies in one upload
Bulk asset import - CSV or JSON
Ingest assets from your CMDB, spreadsheets or oahter asset sources
Who This Is For
Stop Reviewing the Same Finding
50 Times
Other platforms import your data. AttackForge understands it.
Upload Scanner File
Drag & drop .nessus, .xml, or any supported format
Client-Side Parse
Extract findings locally in your browser
Map to Writeups
Match findings to your curated vulnerability library
Enrich
Inherit report-ready findings from your library
Report Ready
Client-ready findings with full context
Upload Scanner File
Drag & drop .nessus, .xml, or any supported format
Client-Side Parse
Extract findings locally in your browser
Map to Writeups
Match findings to your curated vulnerability library
Enrich
Inherit report-ready findings from your library
Report Ready
Client-ready findings with full context
Data Transformation: Before & After
Watch how raw scanner output becomes actionable intelligence
Input: Raw Scanner Output
Output: AttackForge Intelligence
Custom Import Mapping Expressions
Auto-match scanner findings to custom curated writeups using powerful expression syntax
Dynamic Parser Actions
Transform data during import: add/remove tags, modify titles, enrich fields
Predefined Rules Library
Admins create rules once; testers select and extend at import for consistency
Client-Side Privacy
All parsing happens in your browser—scanner data never leaves your machine
Flexible Configuration
Parse and normalize even the most complex scanner output formats
Instant Results
See normalized findings in real-time as you import and configure
Manual Approaches vs. AttackForge
Engineered by security professionals for penetration testing workflows
Purpose-built, not repurposed from vulnerability scanning tools.