Offline data handling
How to convert Nmap XML to CSV or Excel
An Nmap scan saved with -oX or -oA includes XML output. To put one open-port record on each spreadsheet row, the original guide transformed that XML into columns for hostname, IP address, protocol, port, service and state.
Historical Windows method
The original procedure used Microsoft's legacy msxsl.exe, an XSLT file and Excel. Use this only in a maintained, isolated environment where the binary came from a trusted publisher. Modern bounded XML tooling with network access disabled is preferable.
- Preserve the original Nmap XML read-only and make a working copy.
- Create
nmaptemplate.xslfrom the template below. - Place the reviewed XML, stylesheet and trusted transformer in one offline working directory.
- From Command Prompt, change to that directory.
- Run the transformer against the working copy and write a separate CSV output.
msxsl output.xml nmaptemplate.xsl -o nmap-out.csv
Original XSLT structure
This corrected reconstruction retains the six columns described in the backup. It is a structural example, not a complete CSV-safety layer: values containing commas, quotes, newlines or spreadsheet formula prefixes still require a CSV-aware post-processing step.
<?xml version="1.0" encoding="UTF-8"?>
<xsl:stylesheet version="1.0"
xmlns:xsl="http://www.w3.org/1999/XSL/Transform">
<xsl:output method="text" encoding="UTF-8"/>
<xsl:template match="/nmaprun">
<xsl:text>hostname,ip address,protocol,port,service,state </xsl:text>
<xsl:for-each select="host/ports/port">
<xsl:value-of select="../../hostnames/hostname/@name"/><xsl:text>,</xsl:text>
<xsl:value-of select="../../address[1]/@addr"/><xsl:text>,</xsl:text>
<xsl:value-of select="@protocol"/><xsl:text>,</xsl:text>
<xsl:value-of select="@portid"/><xsl:text>,</xsl:text>
<xsl:value-of select="service/@name"/><xsl:text>,</xsl:text>
<xsl:value-of select="state/@state"/><xsl:text> </xsl:text>
</xsl:for-each>
</xsl:template>
</xsl:stylesheet>
Validate the conversion
- Keep the original XML unchanged and hash it before conversion.
- Reject or safely quote unexpected commas, quotes and line breaks.
- Prefix spreadsheet formula-like fields with an apostrophe in a CSV-aware step.
- Compare host and port counts between XML and CSV.
- Store both files as sensitive network inventory.
The old error Invalid at the top level of the document usually indicates malformed XML/XSLT or the wrong input file. Do not repair it with blind character replacement; validate the working copy with a secure parser and inspect the exact line reported.
