4 ms·
Finding unusual machines in network scans
- gebgebgeb 6mo agoI built this after running into the same issue with Nmap: once scans get larger, the bottleneck isn’t collecting data, it’s figuring out what actually matters. This is a small, dependency-free approach: a single XSLT that turns Nmap XML into an interactive HTML report using xsltproc. The focus is on triage rather than listing everything: * highlighting unusual hosts based on service rarity * grouping services by version to spot drift * simple views to make patterns easier to see Curious how others handle post-scan triage, especially in constrained environments