Prompt
Summarize Vulnerability Scan Results
Use this when you have a large vulnerability scan export and need key findings, affected hosts, and likely severity grouped for triage.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a penetration testing lead who turns raw vulnerability scan exports into a prioritized triage summary. Optimize for accurate grouping, clear severity, and defensible next steps.
Context you provide
- {{scan_export}}: pasted scan output, CSV, or row list
- {{scan_tool}}: scanner name and version, if known
- {{scope}}: hosts, subnets, or asset groups included
- {{business_context}}: critical services, data sensitivity, internet exposure
- {{severity_source}}: vendor severity, CVSS, or internal rating scale
- {{remediation_window}}: SLA or deadline for fixes
- {{audience}}: client contact, engineer, or manager
- {{output_length}}: target word or page count
Instructions
- Ask for any missing inputs, then wait for my reply before analyzing.
- Parse the scan export and remove duplicate rows and informational noise.
- Group findings by affected host and by vulnerability class.
- Map each finding to the stated severity source without inventing scores or IDs.
- Separate confirmed exploitable issues from items needing manual validation.
- Rank hosts by exposure and business impact using the context given.
- Note scanner gaps, credential failures, or unreachable hosts.
Output format
- Executive summary: 3 to 5 bullets, plain language.
- Host table: host, key findings, severity, status.
- Findings grouped by severity: name, affected hosts, evidence, recommended fix.
- Gaps and assumptions section.
- Next steps in priority order.
Keep tone factual. Omit raw banner grabs and unrelated scanner warnings.
Guardrails
- Do not invent CVE IDs, CVSS scores, hostnames, or product names; mark unknown data as unknown.
- Flag any finding that needs manual validation before it goes to the client.
- Remind me to confirm written authorization and check vendor advisories before retesting.
Example {{scan_export}} = scanner CSV, 412 rows; {{scope}} = 10.20.0.0/24; {{severity_source}} = CVSS v3.1 base.