Supported tools
The scanners and tools Dossier reads.
Nmap
Ports, services, versions, NSE scripts
Nessus
Vulnerabilities, plugins, CVSS, CVE, hosts
Trivy
CVE, packages, images, misconfig, secrets
Nuclei
Templates, matchers, severity, URL
OpenVAS
Vulnerabilities, hosts, OID
Burp Suite
Issues, severity, confidence, host and path
OWASP ZAP
Alerts, instances, risk, CWE, URL
Qualys
Vulnerabilities, hosts, QID
Acunetix
Web vulnerabilities, evidence
Nikto
Web server misconfigurations, outdated software, dangerous files
SQLMap
Injectable parameters, DBMS, techniques
ffuf
Discovered paths, parameters, status codes
Metasploit
Hosts, services, vulnerabilities, credentials
CrackMapExec / NetExec
Hosts, shares, sessions, credentials
BloodHound
AD attack paths, privileged relationships
Techniques & methodology
Tools and techniques your report documents as part of the engagement, even when they produce no parseable file.
OWASP-based web assessment
Web findings (ZAP, Burp, Nuclei, Nikto, SQLMap, ffuf) mapped to the OWASP Top 10 and referenced against the OWASP Testing Guide.
Wireshark
Traffic analysis documented as methodology and evidence. The pcap itself is not parsed.
Responder
LLMNR / NBT-NS / mDNS poisoning documented as technique, with captured material as evidence.
Browser DevTools
Manual web inspection documented as testing methodology.