A lightweight network security tool that scans your local network, evaluates devices against CIS benchmark controls, and reports findings through AWS to a live dashboard.
Built as part of a security engineering assignment — covers device discovery, firewall analysis, benchmark checks, cloud reporting, and a frontend dashboard.
- Scans your subnet and finds all active devices
- Checks open ports and grabs service banners (SSH, HTTP, Telnet, etc.)
- Reads a simulated Cisco firewall config and pulls out ACL rules
- Runs 10 CIS benchmark security checks and marks each as PASS or FAIL
- Sends all results to AWS (API Gateway → Lambda → DynamoDB)
- Shows everything on a clean dashboard — devices, firewall rules, benchmark results
network-posture-scanner/
│
├── scanner/
│ ├── scan.py # finds devices on the network, checks ports
│ ├── checks.py # runs CIS benchmark security checks
│ └── upload.py # sends results to AWS over HTTPS
│
├── cloud/
│ ├── lambda_handler.py # AWS Lambda function — receives and stores data
│ ├── server.py # local Flask server — reads from DynamoDB, serves APIs
│ └── requirements.txt
│
├── configs/
│ └── cisco.cfg # simulated Cisco firewall config (used for checks)
│
├── dashboard/
│ └── index.html # frontend dashboard
│
├── aws/
│ ├── dynamo.md # how to set up DynamoDB tables
│ ├── deploy lambda.md # how to deploy the Lambda function
│ └── gateway.md # how to set up API Gateway
│
├── .env # AWS endpoint and API key (not committed to git)
└── README.md
scan.py → checks.py → upload.py
│
▼ HTTPS + API Key
AWS API Gateway
│
▼
AWS Lambda
│
▼
AWS DynamoDB
│
▼
Flask server.py
│
▼
dashboard/index.html
| ID | Check | Severity |
|---|---|---|
| CIS-1 | Telnet should not be exposed | HIGH |
| CIS-2 | FTP should not be exposed | HIGH |
| CIS-3 | SSH should be the only remote management protocol | HIGH |
| CIS-4 | Weak SNMP community strings not allowed | MEDIUM |
| CIS-5 | Sensitive ports should not be open publicly | CRITICAL |
| CIS-6 | Egress traffic should be filtered | MEDIUM |
| CIS-7 | Logging must be enabled and pointing to remote server | MEDIUM |
| CIS-8 | HTTP management should be disabled | MEDIUM |
| CIS-9 | RDP should not be exposed on network | CRITICAL |
| CIS-10 | No ingress rule should allow 0.0.0.0/0 to sensitive ports | CRITICAL |
cd cloud
pip install -r requirements.txtAWS_ENDPOINT=https://your-api-id.execute-api.ap-south-1.amazonaws.com/prod
API_KEY=your-api-key
AWS_REGION=ap-south-1
aws configure
# Enter your Access Key ID, Secret Key, region (ap-south-1), output (json)cd scanner
python scan.pypython checks.pypython upload.pycd ../cloud
python server.pyOpen dashboard/index.html in your browser. That's it.
DynamoDB — create 3 tables, all with partition key id (String):
posture_devicesposture_firewall_rulesposture_cis_results
Lambda — create a function called network-posture-handler, runtime Python 3.11, paste the code from cloud/lambda_handler.py, attach AmazonDynamoDBFullAccess policy.
API Gateway — create a REST API, add 3 resources (/devices, /firewall-rules, /cis-results), each with a POST method pointing to the Lambda function. Deploy to a stage called prod.
Step by step guides are in the aws/ folder.
Once the Flask server is running:
| Endpoint | What it returns |
|---|---|
| GET /devices | All scanned devices with open ports |
| GET /firewall-rules | Firewall ACL rules from the config |
| GET /cis-results | Benchmark check results with PASS/FAIL |
- The firewall config in
configs/cisco.cfgis a simulated Cisco IOS file intentionally loaded with misconfigurations — it's the target for benchmark checks - MAC vendor lookup requires raw socket access (admin level) so it shows N/A on Windows — this is expected
- The scanner uses multithreading to check all IPs in parallel so it finishes in under a minute
- No real network lab needed — the tool runs against your local WiFi network
- Show
scan.pyrunning — explain how ping sweep works and how non-responsive hosts are skipped - Show
checks.pyoutput — walk through which checks passed and which failed, and why - Show
upload.py— explain HTTPS + API key auth, data going to AWS - Open the dashboard — show devices table, firewall rules, benchmark results
- Talk about design decisions — multithreading for speed, modular structure, simulated config for firewall analysis