Skip to content

About

No description, website, or topics provided.

Resources

Stars

2 stars

Watchers

0 watching

Forks

Latest commit

 

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Network Posture Scanner

A lightweight network security tool that scans your local network, evaluates devices against CIS benchmark controls, and reports findings through AWS to a live dashboard.

Built as part of a security engineering assignment — covers device discovery, firewall analysis, benchmark checks, cloud reporting, and a frontend dashboard.


What It Does

  • Scans your subnet and finds all active devices
  • Checks open ports and grabs service banners (SSH, HTTP, Telnet, etc.)
  • Reads a simulated Cisco firewall config and pulls out ACL rules
  • Runs 10 CIS benchmark security checks and marks each as PASS or FAIL
  • Sends all results to AWS (API Gateway → Lambda → DynamoDB)
  • Shows everything on a clean dashboard — devices, firewall rules, benchmark results

Project Structure

network-posture-scanner/
│
├── scanner/
│   ├── scan.py          # finds devices on the network, checks ports
│   ├── checks.py        # runs CIS benchmark security checks
│   └── upload.py        # sends results to AWS over HTTPS
│
├── cloud/
│   ├── lambda_handler.py  # AWS Lambda function — receives and stores data
│   ├── server.py          # local Flask server — reads from DynamoDB, serves APIs
│   └── requirements.txt
│
├── configs/
│   └── cisco.cfg          # simulated Cisco firewall config (used for checks)
│
├── dashboard/
│   └── index.html         # frontend dashboard
│
├── aws/
│   ├── dynamo.md          # how to set up DynamoDB tables
│   ├── deploy lambda.md   # how to deploy the Lambda function
│   └── gateway.md         # how to set up API Gateway
│
├── .env                   # AWS endpoint and API key (not committed to git)
└── README.md

Architecture

scan.py → checks.py → upload.py
                           │
                           ▼ HTTPS + API Key
                     AWS API Gateway
                           │
                           ▼
                     AWS Lambda
                           │
                           ▼
                     AWS DynamoDB
                           │
                           ▼
                     Flask server.py
                           │
                           ▼
                     dashboard/index.html

CIS Benchmark Checks

ID Check Severity
CIS-1 Telnet should not be exposed HIGH
CIS-2 FTP should not be exposed HIGH
CIS-3 SSH should be the only remote management protocol HIGH
CIS-4 Weak SNMP community strings not allowed MEDIUM
CIS-5 Sensitive ports should not be open publicly CRITICAL
CIS-6 Egress traffic should be filtered MEDIUM
CIS-7 Logging must be enabled and pointing to remote server MEDIUM
CIS-8 HTTP management should be disabled MEDIUM
CIS-9 RDP should not be exposed on network CRITICAL
CIS-10 No ingress rule should allow 0.0.0.0/0 to sensitive ports CRITICAL

Setup & How To Run

1. Clone the repo and install dependencies

cd cloud
pip install -r requirements.txt

2. Fill in your .env file

AWS_ENDPOINT=https://your-api-id.execute-api.ap-south-1.amazonaws.com/prod
API_KEY=your-api-key
AWS_REGION=ap-south-1

3. Configure AWS credentials

aws configure
# Enter your Access Key ID, Secret Key, region (ap-south-1), output (json)

4. Run the scanner

cd scanner
python scan.py

5. Run security checks

python checks.py

6. Upload results to AWS

python upload.py

7. Start the local API server

cd ../cloud
python server.py

8. Open the dashboard

Open dashboard/index.html in your browser. That's it.


AWS Setup (One Time)

DynamoDB — create 3 tables, all with partition key id (String):

  • posture_devices
  • posture_firewall_rules
  • posture_cis_results

Lambda — create a function called network-posture-handler, runtime Python 3.11, paste the code from cloud/lambda_handler.py, attach AmazonDynamoDBFullAccess policy.

API Gateway — create a REST API, add 3 resources (/devices, /firewall-rules, /cis-results), each with a POST method pointing to the Lambda function. Deploy to a stage called prod.

Step by step guides are in the aws/ folder.


APIs

Once the Flask server is running:

Endpoint What it returns
GET /devices All scanned devices with open ports
GET /firewall-rules Firewall ACL rules from the config
GET /cis-results Benchmark check results with PASS/FAIL

Notes

  • The firewall config in configs/cisco.cfg is a simulated Cisco IOS file intentionally loaded with misconfigurations — it's the target for benchmark checks
  • MAC vendor lookup requires raw socket access (admin level) so it shows N/A on Windows — this is expected
  • The scanner uses multithreading to check all IPs in parallel so it finishes in under a minute
  • No real network lab needed — the tool runs against your local WiFi network

Demo Flow

  1. Show scan.py running — explain how ping sweep works and how non-responsive hosts are skipped
  2. Show checks.py output — walk through which checks passed and which failed, and why
  3. Show upload.py — explain HTTPS + API key auth, data going to AWS
  4. Open the dashboard — show devices table, firewall rules, benchmark results
  5. Talk about design decisions — multithreading for speed, modular structure, simulated config for firewall analysis

About

No description, website, or topics provided.

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages