OPEN SOURCE · WORK IN PROGRESS

From export to worklist in 10 minutes.

A free, open-source tool for vulnerability analysts, still being built. Upload your Tenable or Nessus export and get back the findings that actually matter, ranked by exploitability, exposure and business impact.

SCANNER FORMATS SUPPORTED

  • Tenable.io
  • Nessus
  • Qualys SOON
  • Rapid7 SOON

FEATURES

Built like an analyst would build it.

  • Reasoning, not regex.

    Claude reads each finding the way an analyst would: in the context of your assets, your exposure, your business. No score templates. No keyword rules.

  • Asset-aware out of the box.

    Bring your own asset context CSV. Every prioritization factors in environment, internet exposure, data sensitivity, and owner.

  • CVE-aware.

    Every CVE on every finding is parsed, deduped, and reasoned about — including chained vulnerabilities.

  • Multi-CVE per finding.

    We preserve every CVE on a finding, not the first one. The diff matters when a finding spans 4 chained issues.

  • Dashboard + PDF.

    Sortable web report for the team. Branded PDF for the board. Same prioritization, two surfaces.

  • Your data never trains a model.

    Built to run on your own infrastructure, so findings stay with you. The Claude API doesn't train on what you send it.

HOW IT WORKS

Three steps. About ten minutes.

  1. 01

    Upload.

    Drop your Nessus XML or Tenable.io CSV. Add your asset context CSV — hostname, environment, exposure, owner.

  2. 02

    Prioritize.

    Claude reads every finding against your asset context. Output: a ranked worklist with the reasoning behind each rank.

  3. 03

    Ship the fix.

    Sortable dashboard for the team. Branded PDF for the board. Show up to Monday's standup with the worklist already done.

WHAT IT PRODUCES

A worklist your team will actually work.

Not a 40,000-row CSV. Not a CVSS scatter plot. A ranked list of findings on your assets, each with a one-line "why this rank" you can defend in a standup.

  • ▸ Ranked by exploitability × exposure × business impact
  • ▸ Every rank has a single-sentence justification
  • ▸ Drill into affected assets without leaving the row
  • ▸ Export to PDF for the board, CSV for Jira

PROJECT STATUS

Still being built,
in the open.

araseca is a free, open-source side project, not a product. Here's where it stands.

  • DONE Nessus XML and Tenable.io CSV parsing
  • DONE Asset context import (environment, exposure, sensitivity, owner)
  • DONE Sortable dashboard with drill-down per finding
  • DONE PDF report
  • IN PROGRESS Claude-powered ranking, tested against real exports

Nothing to sign up for and nothing to buy.

FAQ

Questions people ask.

  • Where does my data go?

    araseca is built to run on your own infrastructure, so your scanner export and asset context stay in storage you control. The only outside service is the Claude API, which doesn't use API traffic to train models.

  • What scanner formats do you support?

    Today: Nessus XML and Tenable.io CSV. Next up: Qualys and Rapid7.

  • Is this an automated pentest?

    No. It never touches your systems. It reads scanner output you already have.

  • How accurate is the prioritization?

    Still being measured. The plan is to compare its rankings against findings an experienced analyst has triaged by hand, and publish the results once there's something worth showing.

  • Will the AI hallucinate CVEs?

    It's built not to. The model only ranks and explains; every CVE ID in the output comes straight from your scanner's input.

  • Can I export to Jira / ServiceNow?

    Not yet. PDF and CSV exports come first; ticketing integrations may follow.

  • Is it free?

    Yes. It's an open-source side project, not a product, so there's nothing to buy. You run it yourself with your own Claude API key.

  • Who's behind it?

    A security practitioner building it in spare time, with a lot of help from Claude Code. It started as a way to skip the part of vulnerability triage that doesn't need a human.

  • When can I use it?

    When v1 works end to end. The source code goes up on GitHub at that point; the status section above shows what's left.

Built in the open, one weekend at a time.

Source code coming to GitHub once v1 is ready.