Nmap Scan Viewer and Diff
Nmap results as tables you can sort, filter, compare and export, read on your device.
Scan files
Paste scan output instead
This page never scans anything: it reads files Nmap has already written, on your device. Scan only networks you are authorised to test.
Summary
| Notes | Scripts |
|---|
No ports match. Clear the search or show all listed ports.
| Host | Status | MAC and vendor | OS guess | Open | Open ports | Host scripts |
|---|
Open ports grouped by the service Nmap found, the most common first.
Open a second scan of the same network to compare them.
| Change | Host | Port | Before | After |
|---|
Export this scan
The reports include the changes when a comparison is open.
About the Nmap Scan Viewer and Diff
Nmap writes everything it finds into its output files, but reading a big XML file by eye is slow, and Zenmap and Ndiff need a desktop. Open the XML output (-oX) or the grepable output (-oG) of one or more scans here and you get every host with its addresses, names, MAC vendor and OS guess, and every port with its state, service, product and version, in tables you can sort, filter and search. NSE script output — ssl-cert, http-title, ssh-hostkey, smb-os-discovery and the rest — is shown under each port, expired certificates and page titles are pointed out, and the Services view groups hosts by what they run.
Open two scans of the same network and Compare lists what changed, as Ndiff does: hosts that appeared or went away, ports that opened or closed, and changed service versions, OS guesses and script output. Export the ports as CSV, or the scan as a Markdown or self-contained HTML report.
This page never scans anything itself: it only reads files you already have, on your device. Scan only networks you are authorised to test.
How to use it
- Save your scan as XML with
-oX scan.xml(or-oA nameto get the XML, grepable and normal output at once). - Choose the file, drop it on the page or paste its text. Open several files to switch between them or compare them.
- Read the summary, then use Ports, Hosts and Services. Sort by any column, search across hosts, services, versions and script output, and show closed and filtered ports when you need them.
- Open a port’s Scripts to read its NSE output.
- With two scans open, choose Compare to see what changed between the older and the newer scan.
- Export CSV, Markdown or HTML.
Examples
nmap -sV -sC -O -oX office.xml 192.0.2.0/24, run a week apart
Compare: 1 new host (a camera with Telnet on 23/tcp and a web login on 80/tcp), 3389/tcp no longer open on a desktop, OpenSSH upgraded on the intranet server, and a new backup console on 8080/tcp.
Press Example on the page to open these two scans; they use the documentation address range, so no real network is described.
nmap -sV --script ssl-cert -p 443 -oX tls.xml 192.0.2.1
The 443/tcp row says “Certificate expired” with the notAfter date the script reported, compared with the time the scan ran.
Common uses
- Reviewing a scan on a laptop or tablet without Zenmap.
- Spotting new open ports and new devices between two scheduled scans.
- Turning scan results into a CSV for a spreadsheet or a ticket.
- Writing up open services as findings for a penetration test report.
- Sharing a readable HTML report of a scan with people who do not use Nmap.
Which output to save
- XML (-oX) has everything: every port with its state reason, service detection with product, version, CPE and confidence, NSE script output (also in structured form), OS matches with their accuracy, uptime, distance and the scan’s own start time and statistics. The Nmap XML format is defined by its DTD.
- Grepable (-oG) has one line per host with the ports’ state, service and version, but no script output or OS accuracy, and Nmap’s reference guide calls it deprecated. It is read too, with a note about what it lacks.
- Normal output (-oN) is meant for people and has no fixed format, so it is not read: save XML as well (
-oAwrites all three).
How the comparison works
Hosts are matched by their IPv4 address (IPv6, or MAC, when there is none). A host is new when it is up in the newer scan and was not up in the older one, and gone the other way round. For each host in both scans, every port whose state differs is listed — “not listed” means the scan did not show the port, because Nmap folds closed or filtered ports into a count — followed by ports whose service or version changed and ports whose script output changed. When the files carry their start times, the older scan is used as “before” automatically; you can swap them.
What the notes in the Ports table mean
- Certificate expired or expires soon: the
ssl-certscript’s notAfter date was before the scan, or within 30 days of it. - Title: what
http-titlefound on a web port. - A port shown as
ssl/httpwas reached through TLS by service detection. open|filtered(usual for UDP) means Nmap got no answer and cannot tell an open port from a filtered one.
Limitations
- It reads Nmap’s XML and grepable output only; normal (-oN) and script kiddie (-oS) output have no fixed format.
- Files up to 120 MB each. A very large scan is read in the background and its tables show 200 rows at a time.
- A scan that was stopped or is still running, and a file that is cut short, are read up to their last complete host: hosts after it are missing, and the page says so.
- The notes are only as good as the scripts you ran: no ssl-cert script, no certificate note.
Privacy
Files are read in your browser, in a background worker, and never uploaded. Scan results can reveal a lot about a network, so nothing is stored either: closing the page forgets them.
Frequently asked questions
How do I save Nmap results as XML?
Add -oX filename.xml to the command, for example nmap -sV -oX scan.xml 192.0.2.0/24. -oA name saves name.xml, name.gnmap and name.nmap together. Zenmap’s Save Scan also writes Nmap XML.
Does this page scan my network?
No. It cannot send a single packet: it only reads files that Nmap has already written. Run Nmap yourself, only against networks you own or have written permission to test.
Can I compare more than two scans?
Open as many as you like and pick any two in Compare: the older one as before and the newer one as after. To follow a network over time, compare each new scan with the one before it.
Why are some ports “not listed”?
Nmap lists only the interesting ports and counts the rest (“Not shown: 996 closed ports”). A port that changed from open to one of those counted states has no row of its own in the newer scan, so the comparison shows it as not listed.
Is the HTML report safe to open?
Yes. It is a single file with no scripts, and every value from the scan is escaped, so text such as a page title from http-title can never run as code.