// INTEGRATIONS

    Supported tools

    The scanners and tools Dossier reads.

    Nmap

    Formats: XML (nmap -oX)

    Ports, services, versions, NSE scripts

    Nessus

    Formats: .nessus (XML)

    Vulnerabilities, plugins, CVSS, CVE, hosts

    Trivy

    Formats: JSON

    CVE, packages, images, misconfig, secrets

    Nuclei

    Formats: JSON / JSONL

    Templates, matchers, severity, URL

    OpenVAS

    Formats: XML

    Vulnerabilities, hosts, OID

    Burp Suite

    Formats: XML export

    Issues, severity, confidence, host and path

    OWASP ZAP

    Formats: JSON / XML

    Alerts, instances, risk, CWE, URL

    Qualys

    Formats: XML

    Vulnerabilities, hosts, QID

    Acunetix

    Formats: XML / JSON

    Web vulnerabilities, evidence

    Nikto

    Formats: XML / CSV

    Web server misconfigurations, outdated software, dangerous files

    SQLMap

    Formats: Output / session

    Injectable parameters, DBMS, techniques

    ffuf

    Formats: JSON

    Discovered paths, parameters, status codes

    Metasploit

    Formats: db_export XML

    Hosts, services, vulnerabilities, credentials

    CrackMapExec / NetExec

    Formats: JSON / SQLite

    Hosts, shares, sessions, credentials

    BloodHound

    Formats: JSON

    AD attack paths, privileged relationships

    Techniques & methodology

    Tools and techniques your report documents as part of the engagement, even when they produce no parseable file.

    OWASP-based web assessment

    Web findings (ZAP, Burp, Nuclei, Nikto, SQLMap, ffuf) mapped to the OWASP Top 10 and referenced against the OWASP Testing Guide.

    Wireshark

    Traffic analysis documented as methodology and evidence. The pcap itself is not parsed.

    Responder

    LLMNR / NBT-NS / mDNS poisoning documented as technique, with captured material as evidence.

    Browser DevTools

    Manual web inspection documented as testing methodology.

    Intégrations Nmap, Nessus, Trivy, Nuclei · Dossier