NSAuditor AI

Security Intelligence Without Data Exposure.

A modular, AI-assisted network security audit platform that scans, understands, prioritizes, and tracks vulnerabilities — without ever requiring your data to leave your infrastructure.

npm MIT License Node.js 20+ Tests


NSAuditor AI is the open-source core of a privacy-first security intelligence platform built by Nsasoft US LLC. It orchestrates 27 specialized scanning plugins against target hosts, fuses their results through an intelligent concluder, and optionally produces AI-powered vulnerability reports — all running entirely on your machine.

Zero Data Exfiltration by design. NSAuditor AI works fully offline. AI analysis, CVE correlation, and continuous monitoring all happen locally. External calls (to AI APIs, NVD, etc.) are opt-in and use your own API keys. We never see your scan data.

What's New

Network-scan false-negative closures on the analysis agents (CE 0.2.31 / Enterprise 0.32.6). No CE code change this cycle — a paired bump for Enterprise 0.32.6, a matrix-neutral false-negative-hardening release on the EE analysis-agent (network-scan) path: cleartext transport is now flagged where before only weak-TLS-where-TLS-exists was — a service that should be encrypted but offers no TLS at all used to read clean (→ SOC 2 CC6.7); SMB-alone exposure is now its own HIGH finding rather than being silenced by an SMB && RDP conjunction — SMB without RDP is the higher-risk case (→ CC6.6); and WinRM 5985/5986 · Elasticsearch 9300 · MSRPC 135 · a new aggregate open-port-count rule are new exposure signals (→ CC6.6). Routed SOC 2-first with drift-detector coverage; SOC 2 routing only this cycle — cross-framework mappings (HIPAA §164.312(e)(1) · CIS · NIST) deferred. Plugin count UNCHANGED at 28; all seven coverage matrices UNCHANGED. See CHANGELOG.md for the full per-release history.

Marketplace registration in CLI help + report-quality / routing-integrity release (CE 0.2.30 / Enterprise 0.32.5). CE now surfaces AWS Marketplace license registration in --help and in nsauditor-ai license --status, so a Marketplace buyer can find the registration step without leaving the CLI. Paired with Enterprise 0.32.5, a matrix-neutral report-quality release: nine API Gateway (plugin 1050) mapping rules matched zero findings — eight were re-sourced, and the ninth (a HIPAA §164.312(c)(1) Integrity mapping) was removed on doctrine rather than repaired, because a WAF integration that fails closed alters no ePHI. Routing was never broken and no finding was ever missed: correctly-sourced catch-all rules already failed the same controls, verified by ablation. The real defect was report prose — first-match-wins surfaced a stale auditor-facing rationale while the accurate per-class rationale sat unreachable. Also: six auditor-facing rationales in that API-Gateway cohort were rewritten (a cohort fix, not a class fix — other rationales across the framework files still carry internal-development-history wording), the JSON report artifact no longer serializes raw routing regexes or rule sources, a genuine CI/CD false-clean was closed (a codebuild:ListProjects AccessDenied was warning-only, and warnings route to zero controls, so CI/CD controls could read clean over an un-enumerated inventory — now fail-closed into the existing evidence gap), and three compliance guards were hardened (one had been suppressed by a factually false comment; another had silently become a tautology; a third adds an expected-unmapped equality table). Plugin count UNCHANGED at 28; all seven coverage matrices UNCHANGED.

RDS false-negative depth pass, part 2 (CE 0.2.29 / Enterprise 0.32.4). No CE code change this cycle — a paired bump for Enterprise 0.32.4, a matrix-neutral RDS false-negative-and-report-quality depth pass on plugin 1140: RDS Proxy client↔proxy TLS (a proxy with RequireTLS off accepts cleartext client connections — a transit leg distinct from the DB-engine SSL parameter — now a fail-closed HIGH), a new retained / cross-region-replicated automated-backup at-rest surface (an unencrypted automated backup that survives instance/cluster deletion, invisible to the live-resource and snapshot scans, is now caught), the Aurora cluster-member double-audit closure (a provisioned Aurora cluster's members no longer double-report the cluster-scoped SSL / Multi-AZ settings as instance-level false positives), and a cross-framework report-quality leak closure (a renderer backstop strips foreign framework control-ids out of the violation prose that renders into every framework report). No new plugins, all seven coverage matrices unchanged. See CHANGELOG.md for the full per-release history.

→ See a sample EE scan output: walk-through with synthetic Acme Corp AWS account (no signup required)


What It Does

Scan → Verify → Prioritize → Track → Act
  • 27 scanner plugins probe networks across ICMP, TCP, UDP, HTTP, TLS, SNMP, DNS, SMB, RPC, mDNS, UPnP, WS-Discovery, MCP (Model Context Protocol), and more
  • Smart result fusion — the Result Concluder merges all plugin outputs into a normalized view with OS detection, service fingerprinting, and evidence linking
  • Structured finding format — all findings use a common schema with category, severity, evidence, and remediation — enabling consistent SARIF export and MCP integration
  • AI-powered analysis — send redacted scan results to OpenAI or Claude (your keys, your choice) for vulnerability assessments and remediation guidance
  • Verified vulnerabilities (Pro) — safe, non-destructive probes confirm findings are real, not just version-matched guesses. If it can't be verified, it's flagged as "potential" not "confirmed"
  • Continuous monitoring (CTEM) — watch mode rescans on a schedule, diffs against previous results, and fires webhook alerts on changes
  • MCP integration — expose scanning tools to AI assistants like Claude Code via Model Context Protocol
  • CI/CD ready — SARIF output with --fail-on severity gating for pipeline integration

Editions

NSAuditor AI is available in three editions: Community (free, MIT-licensed, no restrictions), Pro ($49/mo), and Enterprise ($2k+/yr).

Why upgrade to Enterprise?

If you're heading into a SOC 2, HIPAA, NIST CSF 2.0, PCI DSS, ISO 27001, CIS Controls v8, or GDPR Article 32 audit — or need to satisfy customer security questionnaires citing those frameworks, or an IG1 attestation for cyber-insurance renewal — Enterprise turns scan output into auditor-ready evidence packs that pass institutional scrutiny:

  • ☁️ 28 cloud plugins across AWS / Azure / GCP — find the configuration risks an auditor will flag, before they do (CloudTrail integrity, KMS custody, S3 Object Lock, IAM shadow-admin paths, GCP IAM impersonation chains, Azure RBAC sprawl, and more)
  • 📋 7 compliance frameworks shipped — generate any combination from a single scan:
    • SOC 2 (AICPA TSC 2017) — 10 fully-covered + 4 partial controls
    • HIPAA Security Rule §164.312 — 7 covered + 3 partial Technical Safeguards; Zero BAA required (ePHI never leaves your infrastructure)
    • NIST CSF 2.0 Core (NIST CSWP 29, Feb 2024) — 13 covered + 10 partial Subcategories across 106 of CSF 2.0's 107 Subcategories; Subcategory-level mapping (auditor-canonical, not high-level Function/Category claims)
    • PCI DSS v4.0.1 (PCI SSC, June 2024 errata; v3.2.1 retired March 31, 2024) — 19 covered + 9 partial + 39 OOS sub-requirements across 67 of ~250 (MVP-67); sub-requirement-level mapping for QSA Report on Compliance workflow; Defined-vs-Customized Approach discipline per Appendix E (15 Defined-only sub-requirements enforced at schema layer); CHD Scope operator-attested via CDE Data Flow Diagram per Req 1.2.4; Card-brand AOC enforcement priority view (Visa CISP / Mastercard SDP / Amex DSOP / Discover DISC)
    • ISO/IEC 27001:2022 (ISO + IEC, Oct 2022; 2013 edition retired Oct 31, 2025) — 17 covered + 14 partial + 62 OOS across 93 Annex A controls (the complete Annex A universe); per-Annex-A-code mapping auditor-canonical for ISO/IEC 17021-1 certification body assessors; Statement of Applicability per Clause 6.1.3.d discipline + ISMS Clauses 4-10 OOS-by-design with 7 Major Nonconformity classes
    • CIS Critical Security Controls v8 (CIS, May 2021; v8.1 errata June 2024) — 17 covered + 23 partial + 113 OOS across 153 Safeguards / 18 Controls; per-Safeguard mapping with the Implementation Group cumulative discipline (IG1=56 cyber-insurance baseline / IG2 cumulative=130 / IG3 cumulative=153); no-certification-body attestation discipline (INPUT to your CSAT / CIS-CAT Pro self-attestation, never "CIS certified"); Cloud Companion Guide v8 shared-responsibility + CIS-Hardened-Image substrate-evidence credit (4.1/4.2/4.6)
    • GDPR Article 32 (Security of Processing) (Regulation (EU) 2016/679) — 4 covered + 5 partial + 2 OOS across 11 Art. 32 sub-measure units; GDPR Article 32 infrastructure substrate only — NOT GDPR compliance (GDPR is a 99-article legal regime; Art. 32 security-of-processing is the only article an infrastructure scanner can substrate-evidence; the rest is operator-side, out of scope by design). Four-factor proportionality (substrate for your "appropriate to the risk" determination, never an absolute pass/fail); personal-data-scope attestation (pair with your Art. 30 records of processing); Art. 83(4) lower fine tier (€10M/2%, not the €20M/4% headline tier); Art. 32(3)/Art. 42 cloud-provider certification-inheritance
  • 🔐 Cryptographically signed evidence — SHA-256 chain-of-custody + RFC 3161 trusted timestamps + Ed25519 suppression signing. Non-repudiation, not just integrity. Auditors can verify offline.
  • 🏛️ Zero Data Exfiltration architecture — your scan data never leaves your infrastructure. Air-gapped deployment supported. AI analysis happens locally (Ollama) or via your own API keys. Important for PCI DSS CDE-isolation threat models.
  • 🔗 GRC connectors — Vanta + Drata + Secureframe (Enterprise) — map compliance findings to your GRC platform's evidence/test records and push them at scan time (opt-in). Suppression-aware outcome mapping (Vanta) / structured records (Drata + Secureframe), idempotent retries, rate-limit handling, token redaction, and Zero-Data-Exfiltration egress redaction. Early-access, single-workspace; live validation against production tenants is in progress. See GRC Connectors below.
  • 🗄️ WORM evidence storage — S3 Object Lock COMPLIANCE-mode for SEC Rule 17a-4(f) / FINRA 4511 retention compliance
  • 📊 SLA / MTTR tracking + recurring-scan attestation — the Type II operating-effectiveness evidence auditors actually demand (not just point-in-time snapshots)
  • 🎯 11 adversarial-audit Claude Code skills authored per the Per-Framework Adversarial-Audit Skill Pairing institutional pattern — Phase-4 Compliance/GRC chain 8-of-8 COMPLETE for all shipped frameworks (SOC 2 + HIPAA + NIST CSF + PCI DSS + ISO 27001 + CIS Controls v8 + GDPR Article 32 + GRC connector)

See sample EE scan output — full evidence pack against synthetic Acme Corp AWS account (no signup required) → Buy NSAuditor AI Enterprise Edition — $2k / $5k / $10k+ per year for 5 / 25 / unlimited seats + custom SLA. Onboarding call included.

Prefer to buy through AWS Marketplace?

Enterprise Edition is also available as an AWS Marketplace container listing — same product, same local ES256 license key, billed through your AWS account (consolidated billing / EDP drawdown, procurement-friendly; custom Enterprise terms via AWS Private Offers). The listing is public. If it doesn't resolve in your AWS region or account, contact us and we'll extend a Private Offer directly.

How Marketplace fulfillment works (ZDE and air-gap preserved — no runtime AWS dependency at scan time):

  1. Subscribe on the listing (tiers base / growth / scale mirror the 5 / 25 / unlimited-seat plans).
  2. Register your email + AWS account ID at the URL shown in the listing's usage instructions — your ES256 license key arrives by email.
  3. Pull and run the Docker image from the Marketplace registry (commands in the listing's usage instructions and your license email) with NSAUDITOR_LICENSE_KEY=<your key>. One tier-agnostic image — upgrades are just a new license key, never a new image. The container runs fully offline after that; billing lives in AWS, enforcement is your local key.

Feature comparison

Community (Free) Pro ($49/mo) Enterprise ($2k+/yr)
Network scanning
27 scanner plugins (SSH, HTTP, TLS, DNS, SMB, RPC, mDNS, etc.)
AI analysis (OpenAI, Claude, Ollama — your keys) ✅ basic ✅ enriched ✅ enriched
Structured findings + SARIF + CSV export
CTEM watch mode ✅ basic ✅ advanced ✅ advanced
Pro features (vulnerability assessment)
CVE matching + MITRE ATT&CK mapping
Verified vulnerabilities (safe non-destructive probes)
Risk scoring + prioritization
Parallel analysis agents
Enterprise — cloud scanning
28 cloud plugins (AWS / Azure / GCP)
Zero Trust assessment
Enterprise — compliance (7 frameworks)
SOC 2 (AICPA TSC 2017) — 10 covered + 4 partial controls
HIPAA Security Rule §164.312 — Zero BAA required
NIST CSF 2.0 Core — Subcategory-level mapping (106 of 107 Subcategories)
PCI DSS v4.0.1 — Sub-requirement-level mapping for QSA RoC (MVP-67)
ISO/IEC 27001:2022 — per-Annex-A-code mapping + SoA discipline (93 Annex A controls)
CIS Critical Security Controls v8 — per-Safeguard mapping + IG-cumulative discipline (153 Safeguards / 18 Controls)
GDPR Article 32 (Security of Processing) — Art. 32 infrastructure substrate (4 covered + 5 partial + 2 OOS / 11 sub-measure units); not GDPR compliance · Art. 83(4) lower fine tier
Multi-framework --compliance soc2,hipaa,nist-csf,pci-dss,iso-27001,cis-v8,gdpr from one scan
Enterprise — auditor-grade evidence
Signed evidence packs (SHA-256 + RFC 3161 timestamps)
Ed25519 suppression signing
Chain-of-custody manifests
SLA / MTTR tracking + compensating controls
Recurring-scan attestation (Type II operating-effectiveness)
WORM evidence storage (S3 Object Lock — SEC 17a-4 / FINRA 4511)
Enterprise — integration + deployment
GRC connectors — Vanta + Drata + Secureframe push (scan-time, opt-in)
Tabletop simulation + SIEM correlation
Docker per-scan isolation
Air-gapped deployment

This repository is the Community Edition — fully functional, MIT-licensed, no restrictions, no telemetry. Pro and Enterprise features ship via the @nsasoft/nsauditor-ai-ee package and install alongside the CE binary once licensed.

Get Pro or Enterprise →


GRC Connectors (Vanta, Drata, Secureframe)

Enterprise feature. Requires @nsasoft/nsauditor-ai-ee.

Every compliance scan already produces a GRC-ready JSON evidence artifact. The GRC connectors take the next step: they map each NSAuditor compliance finding to your GRC platform's own evidence/test records and push them at scan time — so your Vanta, Drata, or Secureframe workspace reflects the latest cloud posture without a manual export/import round-trip.

Opt-in, and Zero-Data-Exfiltration by default. The push is off unless you set the environment variables below. When it runs, egress is redaction-gated: resource identifiers can be hashed or removed, the persisted audit log stores a body fingerprint (never the raw payload), and your API token is never written to any artifact. Nothing leaves your infrastructure that you didn't opt into.

# Enable the scan-time push (Enterprise)
COMPLIANCE_GRC_PROVIDER=vanta        # or: drata | secureframe
COMPLIANCE_GRC_TOKEN=<your API key>  # never serialized to artifacts
# Optional:
# COMPLIANCE_GRC_REDACTION=hash      # off | hash | remove  (egress identifier redaction)
# COMPLIANCE_GRC_CONTROL_MAP=/path/to/config.json  # provider config: Vanta control→test map, Drata connection ({connectionId, resourceId, schemaMap}), or Secureframe ({workspaceId, collectionId, schemaMap})
Platform Status Model
Vanta Connector + scan-time activation shipped Maps findings to Vanta test results; suppression-aware outcome mapping (pass / fail / passed-with-compensating-control), framework-dimensioned idempotency keys, retry with rate-limit backoff, circuit breaker
Drata Connector library shipped Pushes structured records via Drata Custom Connections; your Drata Test Builder rules (Advanced/Enterprise plans) evaluate them — the connector delivers evidence, your rules do the evaluation
Secureframe Connector library shipped (early-access) Pushes structured records to a workspace evidence collection; your Secureframe rules evaluate them — the connector carries the control status verbatim, it does not compute pass/fail. API shape published-assumed; live-tenant validation deferred (partner intake)

Reliability + audit-integrity built in: idempotent retries (a network-timed-out push won't create duplicate records), per-attempt + total-duration timeout caps, a consecutive-failure circuit breaker, token redaction across every log and error path, and a durable per-control push audit log written next to your scan artifacts.

Honest status. The Vanta, Drata, and Secureframe connectors are shipped, opt-in, and covered by an extensive test suite. Live validation against production Vanta / Drata / Secureframe tenants is in progress as partner onboarding proceeds — until it completes, treat production use as early-access and validate against your own tenant first. This is a single-workspace, operator-configured connector; it is not a multi-tenant managed sync. (Secureframe's API shape is published-assumed pending partner intake; its idempotency keys are SENT but vendor-side dedup is unverified.)


Quick Start

# Install globally
npm install -g nsauditor-ai

# See all flags, subcommands, and worked examples
nsauditor-ai --help

# Configure (optional — scans work fully offline without AI)
cat > .env << 'EOF'
AI_ENABLED=true
AI_PROVIDER=ollama              # openai | claude | ollama
OLLAMA_MODEL=llama3             # For local AI (no API key needed)
# OPENAI_API_KEY=sk-...         # Or use OpenAI
# ANTHROPIC_API_KEY=sk-ant-...  # Or use Claude
OPENAI_REDACT=true
EOF

# Scan a host with all plugins
nsauditor-ai scan --host 192.168.1.1 --plugins all

# Scan a subnet in parallel
nsauditor-ai scan --host 192.168.1.0/24 --plugins all --parallel 10

# Start the MCP server for AI assistants
nsauditor-ai-mcp

Or run without installing:

npx nsauditor-ai scan --host 192.168.1.1 --plugins all

Or clone and run from source:

git clone https://github.com/nsasoft/nsauditor-ai.git
cd nsauditor-ai
npm install
node --env-file=.env cli.mjs scan --host 192.168.1.1 --plugins all

Results land in ./out/<host>_<timestamp>/:

File Contents
scan_conclusion_raw.json Full unredacted conclusion (admin reference)
scan_conclusion_raw.html Admin RAW HTML with filters and full detail
scan_response_ai_payload.json Redacted payload sent to AI
scan_response_ai.json Raw AI API response
scan_response_ai.txt AI conclusion (markdown)
scan_response_ai.html Styled HTML report with CVE links and badges
scan_results.sarif.json SARIF 2.1 — only with --output-format sarif (renamed scan_<host>.sarif.json for multi-host runs)
scan_results.csv CSV — only with --output-format csv
scan_report.md GitHub-flavored Markdown report — only with --output-format md (or markdown)

Works on Node 20+ (tested on Node 22).


Plugins

Core Scanners

ID Name Protocols Purpose
001 Ping Checker ICMP/ARP Reachability + TTL-based OS hints
002 SSH Scanner TCP:22 Banner, version fingerprinting, timeout policy
003 Port Scanner TCP/UDP Bulk open port detection (populates context for downstream plugins)
004 FTP Banner Check TCP:21 FTP daemon version detection
005 Host Up Check TCP/UDP Quick multi-probe reachability confirmation
006 HTTP Probe TCP:80/443 Headers, server token, vendor hints
007 SNMP Scanner UDP:161 sysDescr, OIDs, serial/hardware/firmware extraction
008 Result Concluder Meta Fuses all plugin outputs (always runs last)
009 DNS Scanner TCP/UDP:53 version.bind CHAOS/TXT + A record lookup
010 Webapp Detector HTTP Technology stack fingerprinting via wappalyzer
011 TLS Scanner TCP:443+ TLS version + cipher enumeration per port
012 OpenSearch Scanner HTTP:9200+ OpenSearch/Dashboards version + Linux/Node.js hints
013 OS Detector Meta Derives distro/OS from all prior banners with TTL fallback
014 NetBIOS Scanner UDP:137/TCP:445 NetBIOS/SMB enumeration + SMB2 null session probe
015 SUN RPC Scanner TCP/UDP:111 RPC portmapper service discovery (NFS, mountd)
016 WS-Discovery UDP:3702 Multicast device discovery with XML metadata
024 TCP SYN Scanner TCP (Nmap) SYN half-open scan via Nmap wrapper (optional)
040 TLS Certificate & Cipher Auditor TCP:443+ Cert expiry, chain integrity, hostname mismatch, weak ciphers, deprecated protocols, key strength
050 TRIBE v2 Neural API Security Probe TCP/HTTP:8080 Debug leak detection, stack traces in errors, header security, CORS misconfiguration, unauthenticated routes
060 DNS Security Auditor DNS/UDP:53 SPF/DKIM/DMARC, dangling CNAMEs, DNSSEC, NS delegation, zone transfer exposure, MX security, CAA records
070 MCP Scanner TCP/HTTP+SSE Detects MCP (Model Context Protocol) servers on candidate ports (1967, 3000, 3005, 5173, 6274, 6277, 8000, 8090). Audits for cleartext transport (HTTP not HTTPS), missing/anonymous auth, anonymous tool enumeration, deprecated protocol versions, and Inspector exposure on non-loopback. Maps findings to CWE/OWASP/MITRE per the FindingSchema. STDIO-transport MCP servers are out of scope (no network port).

Discovery Plugins

Name Purpose
ARP Scanner MAC resolution + OUI vendor lookup + OS hints
mDNS/Bonjour Scanner Local service discovery + friendly names from TXT records
UPnP/SSDP Scanner Device discovery + description XML parsing
DNS-SD Scanner DNS Service Discovery announcements
LLMNR Scanner Link-local multicast name resolution
DB Scanner Database service detection (MySQL, PostgreSQL, Redis, etc.)

Pro/Enterprise Plugins (via @nsasoft/nsauditor-ai-ee)

28 enterprise plugins across AWS, GCP, and Azure substrate audits — all mapped to AICPA Trust Services Criteria 2017 (10 covered + 4 partial controls). EE plugins live in the disjoint 1000+ ID range; CE reserves 001-099. Once licensed, the EE package installs alongside the CE binary and discovers automatically.

Watch a sample scan run end-to-end — synthetic Acme Corp AWS account + home-office router. Real real scan output, no signup required. See the transitive SG chain reachability finding, the multi-region GuardDuty audit, the dnsmasq CVE detection, and what the signed evidence pack actually looks like.

Buy NSAuditor AI Enterprise Edition · $2k / $5k / $10k+ per year · 5 / 25 / unlimited seats · onboarding call included.

All EE plugins follow the same institutional plumbing pattern:

  • Thread H _instrumentSdkClient wrap — per-API AccessDenied counter + ZDE structural guard (verb-prefix denylist regex blocks Get* / Retrieve* / Read* value-reading APIs at SDK boundary) + idempotency sentinel
  • Throttle-retry — exponential-backoff retry on Throttling* / RequestLimitExceeded / TooManyRequestsException with per-command wall-clock budget
  • Thread F conclude() field-selection allowlist — structured-data ZDE: only AWS-public-namespace identifiers + integer counts flow through to findings; customer policy content / key material / encrypted payloads NEVER propagate
  • conservative_classifier_principle — emit INFO+evidenceGap with verification prompt when ARN-shape disambiguation needs a follow-up API call; vacuous PASS on partial substrate evidence is treated as the worst SOC 2 reporting outcome
  • aws_string_case_normalization — trim + lowercase AWS-returned strings at SDK-helper boundary; protects against the 7+ recurrent classes of case-sensitivity fail-open (IAM Condition keys, Lambda runtimes, KMS aliases, Effect/Action discriminators, FULL_ADMIN sentinel, S3 region)
ID Name Tier What it audits
1020 AWS S3 Security Enterprise Bucket hardening: public-access block, encryption at rest, versioning, Object Lock COMPLIANCE-mode, MFA Delete, access logging. CC6.1 / C1.1 / C1.2
1021 GCP Cloud Scanner Enterprise Firewall rules + IAM bindings + Storage bucket public-access. CC6.1 / CC6.6 / C1.1
1022 Azure Cloud Scanner Enterprise NSG rules + RBAC role assignments + Storage account hardening. CC6.1 / CC6.6 / C1.1
1023 Zero Trust Checker Enterprise Segmentation, encryption, identity, lateral-movement scoring across the network surface. CC6.1 / CC6.6
1024 GCP Cloud Storage Auditor Enterprise Multi-cloud parity sister of plugin 1020 AWS S3. 6 dimensions: bucket-level IAM public bindings (allUsers = CRITICAL, allAuthenticatedUsers = HIGH), Uniform Bucket-Level Access (closes legacy bucket-ACL false-PASS class), Object Versioning, Bucket Lock retention policy (SEC 17a-4 / FINRA 4511 WORM-alignment), CMEK via Cloud KMS (four-tier custody ladder), bucket-level access logging. CC6.1 / CC6.6 / CC7.1 / C1.1 / C1.2 / A1.2
1025 GCP IAM Project-Level Auditor (v2 — EE 0.7.1) Enterprise First plugin in the v0.7.x GCP-IAM-deep-audit cohort. Mirrors plugin 1030 AWS IAM Deep Auditor's shadow-admin discipline adapted to the GCP IAM data model. 7 dimensions (EE 0.7.1 v2 expansion): project-scope public-member bindings (allUsers = CRITICAL, allAuthenticatedUsers = HIGH at the project root), admin-equivalent role inventory across 12 predefined sensitive roles, IAM Conditions classifier on sensitive-role bindings (restrictive CEL = PASS, absent on sensitive = MEDIUM, vacuous = LOW + evidenceGap), custom-role permission audit (* wildcard = CRITICAL; admin-equivalent permission intersection across 16-entry allowlist = HIGH), SA key custody (user-managed long-lived keys = HIGH; 90-day rotation threshold uplift), SA impersonation graph BFS (transitive serviceAccountTokenCreator/User/OpenIdTokenCreator chains — 2-hop = HIGH, 3+ hop = CRITICAL; project-scope grants surface independently as CRITICAL), Organization Policy constraint enumeration (4 sensitive constraints incl. iam.disableServiceAccountKeyCreation). Honors GOOGLE_IMPERSONATE_SERVICE_ACCOUNT via utils/gcp_auth.mjs. CC6.1 / CC6.6 / C1.1
1030 AWS IAM Deep Auditor Enterprise Shadow-admin path detection via BFS over PassRole / AssumeRole / federated trust. Restrictive-Condition allowlist for Auth0 / Okta / Cognito OIDC patterns. CC6.1
1040 AWS CloudTrail Operational Integrity Enterprise Trail health + CloudWatch alarm coverage against CIS AWS Benchmark §3.1–3.14 + AWS Config + cross-account S3 trail-destination WORM verification (SEC 17a-4 / FINRA 4511). CC7.2 / CC7.3
1050 AWS API Gateway Assurance Enterprise Per-route authz classifier (NONE=CRITICAL), custom-domain TLS policy, stage-level access logging + WAF, public-endpoint exposure. Entry-point evidence for serverless deployments. CC6.1 / CC6.6 / CC6.7 / CC7.1 / A1.2
1060 AWS DynamoDB Audit Integrity Enterprise First "audit-the-auditor" plugin. PITR + deletion protection + KMS-CMK custody + resource-policy presence + CloudTrail data-event cross-reference. CC6.6 / CC7.1 / C1.1 / PI1.5
1070 AWS KMS Auditor Enterprise Per-key rotation + wildcard-Principal classifier across 5 severity tiers (covers Principal.AWS / Federated / Service / CanonicalUser + NotPrincipal-Allow + NotAction-Allow + glob actions). CC6.3 / C1.1
1080 AWS Lambda Security Enterprise Runtime EOL detection (CRITICAL on nodejs16.x / python3.7 etc.), public function URLs, resource-policy wildcards, env-var secret-name detection (ZDE-safe), VPC config, KMS custody, DLQ. CC6.1 / CC6.6 / CC7.1 / C1.1
1090 AWS Secrets Manager + SSM Parameter Store Enterprise Rotation cadence + KMS-CMK custody + SecureString classification + secret-name detection. ZDE-critical: never calls GetSecretValue / GetParameter — metadata only. Verb-prefix denylist blocks Get* / Retrieve* / Read* at the SDK boundary. CC6.1 / CC6.6 / C1.1
1100 AWS CodePipeline + CodeBuild Enterprise Source-stage encryption, privilegedMode detection, buildspec drift, secrets-via-env vs Secrets-Manager, IAM wildcard-Action, artifact-store encryption, stale-execution detection. CC6.1 / CC7.1 / CC8.1 / C1.1
1110 IAM Effective Decrypt-Path Auditor Enterprise Cross-plugin reconciler — walks IAM policies for kms:Decrypt / ReEncrypt* / GenerateDataKey grants and cross-references against KMS key policies to compute the effective decrypt path. Closes the NotAction-implicit-decrypt false-PASS class. CC6.1 / CC6.6 / C1.1 / C1.2
1120 AWS S3 Lifecycle + Cross-Region Replication Enterprise Lifecycle policy enumeration + cross-region replication topology. Cross-region destination-bucket reachability check closes silent-PASS where replication FAILED but emitted clean. C1.1 / C1.2 / A1.2
1130 AWS Backup Auditor Enterprise The flagship plugin — 12-dimension air-gapped vault attestation arc for LogicallyAirGappedBackupVault resources. Audits Plans + Vaults + Recovery Points + Frameworks + Restore Testing + Legal Holds + vault Access Policy. SEC 17a-4 / FINRA 4511 ransomware-defense substrate. CC6.3 / CC6.6 / CC7.1 / CC8.1 / C1.1 / C1.2 / A1.2
1140 AWS RDS Auditor Enterprise 10 dimensions: Multi-AZ, storage encryption + KMS custody, parameter-group SSL, backup retention, public accessibility, IAM database auth, snapshot encryption, pgAudit + SPL cross-check, CloudWatch Logs exports (engine-dispatched), log retention. A1.2 / CC6.1 / CC6.6 / C1.1 / CC7.2 / CC7.3
1150 AWS SQS/SNS Auditor Enterprise 7 dimensions across both services: encryption at rest + KMS custody, transit-encryption policy, topic-policy wildcards (CRITICAL on unconditional + NotPrincipal-Allow), DLQ presence, CloudWatch alarm coverage on ApproximateAgeOfOldestMessage + NumberOfNotificationsFailed. C1.1 / CC6.6 / A1.2 / CC7.1 / CC7.2
1160 AWS VPC Endpoints / PrivateLink Enterprise Endpoint-policy wildcards (CRITICAL on PrivateLink-breaking unconditional), PrivateDNS enabled (silent-bypass class), endpoint state (failed = silent failure), type substrate disclosure. CC6.6 / A1.2 / CC7.2
1170 AWS EC2 SG Perimeter Enterprise RESTRICTED_PORTS (23 ports per CIS AWS Foundations v3.0) wildcard ingress + IPv6 ::/0 + all-protocol-from-wildcard + orphan SG detection. SG→SG transitive chain reachability: BFS from public-CIDR roots through UserIdGroupPairs — 2-hop = HIGH, 3+ hop = CRITICAL. Catches the ALB → app → database exposure that per-SG audits silently miss. CC6.6 / CC6.2
1180 AWS ElastiCache Redis Enterprise 6 dimensions: transit encryption, at-rest + KMS custody (four-tier ladder), Redis AUTH / IAM user groups (Redis 7+ ACL), Multi-AZ, snapshot retention cadence, subnet placement. Cross-plugin sister to plugin 1170 for cache-tier perimeter. CC6.1 / CC6.2 / CC6.6 / A1.2 / C1.1
1190 AWS SES Email Integrity Enterprise 6 dimensions: DKIM enablement + CNAME DNS resolution + key-fingerprint pin, DMARC TXT parsing + alignment classifier, custom MailFrom alignment, config-set TLS enforcement, sending-auth policy wildcards, dedicated IP pool, suppression list (count-only — ZDE invariant: never reads addresses). CC6.1 / CC6.6 / C1.1 / CC7.1 / Privacy
1200 AWS Inspector2 / GuardDuty Enablement Enterprise 4 dimensions across all opted-in regions (17+ incl. GovCloud / ISO): GuardDuty Detector + protection features (S3 / EKS / EBS-malware / RDS-login / Lambda / RuntimeMonitoring), Inspector2 enablement, scan-target coverage. Plus alerting-destination dim (EventBridge or SecurityHub) and per-target liveness probes for Lambda / SNS / SQS / IAM / API destination / CloudWatch Logs. CC7.1 / CC7.2
1210 AWS EC2 Instance (EE 0.13.1) Enterprise Multi-region (DescribeRegions; single-region fallback emits an evidence-gap) EC2 instance audit: IMDSv1 enabled (IMDSv2-only enforcement; hop-limit > 1 container-escape) + EBS volume + account-default encryption + public-IP exposure (incl. IPv6 GUA + secondary-ENI/EIP) + instance-store evidence-gap. AMI inventory → CIS-Hardened-Image detection on CIS Safeguards 4.1/4.2/4.6 — the AWS producer; Azure (1022) + GCP (1021) feed the same cisImageInventory contract. CC6.1 / C1.1 / CC6.6
1220 Azure Storage Account Data-Protection (EE 0.13.2) Enterprise Dedicated Azure Storage Account encryption / transit / authorization auditor — orthogonal to the 1022 scanner's network-exposure dims (no double-emission; mirrors the AWS 1020 + 1120 two-plugin S3 split). HTTPS-only transit (enableHttpsTrafficOnly) + minimum TLS version + Shared Key authorization (allowSharedKeyAccess — bypasses Azure AD; absent = enabled, never silent-PASS) + infrastructure (double) encryption + encryption key source incl. customer-managed-key reachability + rotation (keyVaultProperties — a disabled/revoked/version-pinned CMK degrades, not silent-PASS). Conservative classifier: indeterminate field / AccessDenied → evidence-gap; single-subscription scope surfaced explicitly. CC6.7 / CC6.1 / C1.1
1221 Azure NSG Perimeter (EE 0.14.0; UDP lane EE 0.14.1) Enterprise The Azure analog of AWS 1170 — a CC6.6 network-segmentation perimeter auditor for Azure Network Security Groups. Evaluates each NSG's inbound rules in Azure priority order (first match wins; DenyAllInbound default): all-protocol public Allow + public-source (*/0.0.0.0/0/Internet) to a restricted TCP management/data-tier port (SSH/RDP/MSSQL/MySQL/Postgres/Redis/Mongo/SMB/WinRM/etc.) + ::/0 IPv6-wildcard to a restricted port (the dimension 1022's flat lint misses) + public-source / ::/0 to a restricted UDP service (SNMP/CLDAP/NTP/rpcbind/IPMI/IKE/Memcached etc. — Dim 2u/3u, EE 0.14.1) + public→non-restricted INFO + PASS substrate. Attachment-aware (attached → CRITICAL effective; orphaned → MEDIUM latent) + effective priority/deny-override resolution + 0.0.0.0/1 split-range coverage. Non-overlapping-by-depth with 1022's coarse per-rule NSG lint. Conservative classifier: denied/indeterminate → evidence-gap; one malformed NSG degrades per-resource. CC6.6
1222 Azure Key Vault Deep Auditor (EE 0.15.0) Enterprise The third dedicated Azure auditor (after 1220 storage + 1221 NSG) — the KV analog of how 1221 deepens 1022's flat NSG dim. Enumerates each vault's keys, role assignments, and diagnostic settings across 4 dims: (1) key auto-rotation policy + (2) key expiry (epoch-s/ms/Date/string coerced) + (3) diagnostic logging → Log Analytics (@azure/arm-monitor) + (4) privileged-access depth (RBAC roleAssignments admin/data-plane/scope-aware + legacy accessPolicies export/wide-crypto breadth). Orthogonal to 1022's vault-property dims (purge/soft-delete/network-ACL/RBAC-mode) — no double-emission. Secret/cert expiry is a deliberate data-plane scope boundary. Conservative classifier: indeterminate field / AccessDenied / arm-monitor absent → evidence-gap; one malformed vault degrades per-resource. CC6.3 / C1.1 / CC6.1 / CC7.2
SOC 2 Compliance Engine Enterprise AICPA TSC 2017 mapping (10 covered + 4 partial controls), chain-of-custody, RFC 3161 timestamps, suppression workflow with Ed25519 signing.
HIPAA Compliance Engine (EE 0.9.0) Enterprise HIPAA Security Rule §164.312 Technical Safeguards mapping (7 covered + 3 partial + 45 OOS within §164.312 + entire §164.308 + entire §164.310). HHS Required/Addressable discipline per control. Same institutional-grade evidence infrastructure as SOC 2 (chain-of-custody, RFC 3161 timestamps, Ed25519 suppression signing). Use --compliance hipaa or --compliance soc2,hipaa for dual-framework reports from a single scan. Zero BAA required — Zero Data Exfiltration architecture means ePHI never leaves customer infrastructure.
NIST CSF 2.0 Compliance Engine (EE 0.10.0) Enterprise NIST Cybersecurity Framework 2.0 Core mapping at the auditor-canonical Subcategory level — 13 covered + 10 partial + 83 OOS across 106 of CSF 2.0's 107 Subcategories. Govern function OOS-by-design (GV.SC-04 partial as substrate exception); Respond function OOS-entirely; Implementation Tiers 1-4 OOS as organizational-maturity claims. NIST SP 800-53 Rev. 5 + CIS Critical Security Controls v8 cross-references baked into informativeReferences. Use --compliance nist-csf or --compliance soc2,hipaa,nist-csf for triple-framework reports from a single scan.
PCI DSS v4.0.1 Compliance Engine (EE 0.11.0) Enterprise PCI DSS v4.0.1 (PCI SSC, June 2024 errata; supersedes v4.0 March 2022; v3.2.1 retired March 31, 2024) mapping at the auditor-canonical sub-requirement level for QSA Report on Compliance workflow — 19 covered + 9 partial + 39 OOS across 67 of ~250 sub-requirements (MVP-67 density) (Req 7.2.2 down-rated covered→partial in EE 0.19.4 — access-by-job-classification is process/HR-gated). Req 12 Information Security Program OOS-by-design entirely. Req 5 anti-malware + Req 9 physical OOS-entirely. Defined-vs-Customized Approach discipline per Appendix E — 15 Defined-only sub-requirements enforced at schema layer. Cardholder Data Environment (CDE) scope operator-attested via CDE Data Flow Diagram per Req 1.2.4 + Req 12.5.1. Card-brand AOC enforcement priority view (Visa CISP / Mastercard SDP / Amex DSOP / Discover DISC). **4 load-bear