Port states. Nmap reports open, closed or filtered. Open means a service answered. Closed means the host replied that nothing listens there. Filtered means no useful reply came back because a firewall or filter ate the probe. The classic misread is treating filtered as closed.
Flags in the command. -sS is a SYN (half-open) scan, -sT a full TCP connect, -sU UDP, -sV version detection, -O OS detection, -Pn skips host discovery, -p- covers every port, and -A bundles OS and version detection, default scripts and traceroute (Nmap options summary). When a stem shows the command, check what it could not have found. Without -sV there is no version column, and without -sU no UDP service was tested.
Scanner findings. Nessus, OpenVAS and Nuclei report a finding with a severity, usually a CVE identifier, and evidence: a banner, a response, a matched template. A finding built on a version banner alone is weaker than one built on a response only the vulnerable code would give, because vendors often backport fixes without changing the version string. The gap between the two is where false positives and false negatives come from.
Severity labels. The severity a scanner prints comes from the Common Vulnerability Scoring System (CVSS). Check which version: a v4.0 vector has different metric groups from a v3.1 one, as laid out in CVSS 4.0 vs 3.1.
Cloud and container output. ScoutSuite audits configuration across cloud providers. Prowler runs best-practice and compliance checks on AWS, Azure and Google Cloud. Trivy scans container images and infrastructure as code (IaC) and can produce a software bill of materials. Checkov analyzes IaC files before deployment. Their output ties a failed check or a vulnerable package to a resource, an image layer or a line in a template, so you can see where the fix belongs.