A security practitioner reviewing a live network vulnerability scan across multiple monitors.
Apache-2.0 Core Apache-2.0 Linux and macOS

Network Vulnerability Assessment, Done End to End

From host discovery to a boardroom-ready report, netvuln-tool automates the whole assessment: recon, port enumeration, vulnerability analysis, A-to-F risk scoring, compliance mapping, and branded reporting. The scanning engine is open-source. The portal, compliance mapping, and fleet management scale with you.

A-F
Risk grading with a dual score
5
Compliance frameworks mapped
1,600+
Automated tests behind every release
$0
To start with the open-source core

One tool, the whole assessment

Built by practitioners who got tired of stitching five tools together to produce one report. One pipeline takes you from target scope to a prioritized remediation plan.

Open-source core

The scanning engine, risk scorer, report generator, scheduling daemon, and Python orchestrator are Apache-2.0 licensed. Run it on your own infrastructure, source included.

Reports clients respect

Self-contained, white-labeled HTML reports with a one-page executive summary, CVSS-scored findings, and a step-by-step remediation playbook. Export to PDF, CSV, and JSON.

Scales from solo to fleet

Start as a single operator, then grow into scheduled scans, a hosted collection portal, and a managed fleet of scanner agents across many client networks.

How it works

Four automated phases, from target scope to remediation playbook, with no manual overhead.

1

Discovery

Live host detection, DNS and email-security enumeration (SPF, DKIM, DMARC), and WHOIS or OSINT across your target scope.

2

Enumeration

Port and service versioning plus web, SMB, SSH, and SNMP checks. Missing optional tools are skipped, never fatal.

3

Assessment

Vulnerability analysis with live CVE and CVSS lookups, severity classification, and A-to-F risk grading with a dual (standard and operational) score.

4

Reporting

A branded HTML report, one-page executive summary, remediation playbook, compliance mapping, and topology map, ready to share.

Open-source core, commercial when you scale

Run the scanner at no cost forever. Add the portal, compliance mapping, and fleet management when your engagements demand them.

Open Source, No Cost

The scanning engine

Everything you need to scan a network and produce a professional report, self-hosted and fully yours. The source ships under Apache-2.0, so you can audit and modify it.

  • Full multi-phase recon and vulnerability pipeline
  • A-to-F risk scoring with a dual model
  • Self-contained HTML report and executive summary
  • Scheduling daemon, Docker image, Python orchestrator
  • Runs standalone with no account or API key
Commercial Tiers

Portal, compliance, and fleet

Centralized management and the capabilities teams and MSPs need, hosted and maintained by Bullium Consulting.

  • Hosted collection portal with shareable report links
  • Compliance mapping, benchmarks, remediation tracking
  • Webhook integrations for PSA, RMM, and SIEM tools
  • Multi-agent fleet management and command dispatch
  • Multi-tenant client scoping and audit logging
Compare tiers and pricing

Built for security teams

Every capability is designed to cut time-to-remediation and communicate risk to the people who sign off on it.

CVSS and CVE lookups

Findings correlated to live CVE descriptions and CVSS scores, with color-coded severity so the urgent items surface first.

A-to-F risk grading

A composite risk score with letter grades, plus a dual model that separates raw risk from the post-exception operational score.

Remediation playbooks

Prioritized, step-by-step fixes with difficulty ratings, split into self-service items and guided professional work.

Compliance mapping

Automated mapping to CIS Controls v8, NIST CSF, PCI-DSS v4.0, SOC 2, and Ohio Revised Code 9.64, with gap analysis.

Network topology

An SVG topology map with subnet grouping and risk-graded host nodes, so exposure is visible at a glance.

Scheduled scanning

A persistent daemon runs recurring scans with retry and backoff, tracks drift over time, and installs as a systemd service.

White-label reporting

Per-engagement branding (colors, subtitle, footer) baked into the HTML so it survives portal upload and secure sharing.

Fleet and C2

Manage a fleet of authorized scanner agents from the portal: queue commands, group agents, and review an audit log.

Python orchestrator

A pip-installable, strict-typed CLI (recon, scan, upload, diff, daemon) that drops into the Bash pipeline or CI.

Alerting

Threshold evaluation on new critical or high findings. Email alerts ship in the open-source core, with Slack and webhook channels from the Business tier.

Scan diff and benchmarks

Cross-session new, persistent, and resolved tracking, plus percentile benchmark comparison across engagements.

Runs anywhere

macOS and Linux, including a low-power Raspberry Pi appliance you can drop on any network segment.

A netvuln-tool Network Vulnerability Assessment Report showing an executive summary with host, port, and finding counts by severity.

Reports built to be handed off

Every scan produces a professionally branded assessment report. The executive summary gives leadership an immediate read on scope and risk, while granular per-host findings give the technical team exactly what to act on.

Reports include host discovery, open-port enumeration, CVSS-scored findings, the composite risk grade, and a prioritized remediation playbook, all exportable and shareable through a secure link.

Acme Manufacturing Corp

15 Hosts|47 Open Ports|87 Findings
3 Critical 8 High 28 Medium 18 Low 30 Info

Risk Score: 100/100 (Grade F), Operational Score: 84/100 after 3 accepted exceptions

View a full sample report
The netvuln-tool collection portal dashboard showing assessment sessions with severity breakdowns and trends.

A portal for every engagement

Upload a scan and the collection portal tracks it: severity breakdowns, remediation progress, compliance panels, and trends across sessions, with multi-tenant client scoping for consultants and MSPs.

  • Severity breakdown and remediation progress tracking
  • Compliance panels with framework mapping
  • Historical trend tracking across engagements
  • Secure token-based report sharing with stakeholders
Open the portal

Pricing that scales with you

Start at no cost with the open-source core. Add a tier when you need the portal, compliance, or fleet management.

Open source

No cost

The full scanning, scoring, and reporting engine, self-hosted under Apache-2.0.

Pro

$99/mo

For independent consultants. Portal upload and shareable client reports.

Most Popular

Business

$349/mo

For in-house teams. Compliance mapping, benchmarks, and remediation tracking.

MSP

$599/mo

For MSPs and MSSPs. Multi-agent fleet, C2, and multi-tenant reporting.

The Bullium field appliance: a Raspberry Pi 5 with an RTL-SDR dongle in a custom two-part 3D-printed enclosure.
Hardware

The field appliance

A low-power scanning appliance you can drop on any network segment: a Raspberry Pi 5 with an RTL-SDR in a custom Bullium-built enclosure, running the scanning daemon and reporting straight back to the portal.

It pairs naturally with the MSP tier as a fleet of always-on field agents. Built and shipped by Bullium Consulting.

See appliance options

Common questions

Is netvuln-tool open source?

Yes. The core scanning engine, risk scoring, and report generation are Apache-2.0 licensed and available at no cost. Commercial tiers add the hosted collection portal, compliance mapping, multi-agent fleet management, and support.

Which compliance frameworks does it map to?

netvuln-tool maps findings to CIS Controls v8, NIST CSF, PCI-DSS v4.0, SOC 2, and Ohio Revised Code 9.64, with gap analysis for audit readiness. Compliance mapping is included from the Business tier.

How does licensing work?

Paid tiers use a license key. The gate is soft: a feature above your tier is skipped with a warning and scans never fail because of licensing. The core scanner always runs, with or without a key.

More pricing questions

See what is on your network

Start with the open-source core at no cost, or pick the tier that fits your practice. Clear risk scores, mapped compliance, and reports your clients will actually read.