01 / 03
Zero Trust scoring
Segmentation, graded.
Any-any rules, loose egress and flat zones surface as ranked findings.
Offline config auditor · v1.4.2
Drop in a router or firewall config. Get a scored, compliance-mapped report without a single packet touching your network.
Reads 28 vendor formats
01 · Engine
No agents. No credentials. Export the config, drop it in, read the findings.
02 · Scoring
Severity, DoD posture, the vendor's own rating, and a score weighted by where the device sits.
01 / 04
Base, temporal and environmental scores.
02 / 04
CAT I, II or III, ready for your RMF package.
03 / 04
The vendor's own security impact rating.
04 / 04
Same misconfig scores higher on a border firewall.
03 · Depth
01 / 03
Zero Trust scoring
Any-any rules, loose egress and flat zones surface as ranked findings.
02 / 03
Drift detection
See what was fixed, what regressed and what's new since your golden baseline.
03 / 03
Tamper-evident audit
Each scan is hash-chained to the last. One altered byte breaks the chain.
Nothing leaves the machine.
04 · Compliance
Pass or fail per control, with evidence your assessor already knows how to read.
12-rule pack mapped to Vul-IDs
10-rule pack, QSA-ready evidence
14 rules on NIST 800-171 / 172
Control families on every rule
Cross-tagged for audit programs
Grades Cisco password types 0–9
05 · Compare
The same feature list, side by side.
| Capability | Online tools | NatMesh |
|---|---|---|
| Vendor parsers | ~15 | 28 |
| Security rules | ~70 | 202 |
| Runs fully offline | No | Yes |
| Risk by device role | No | Yes |
| Zero Trust scoring | No | Yes |
| Offline CVE matching | No | 22 + NVD |
| CMMC 2.0 rule pack | No | 14 rules |
| DISA STIG rule pack | No | 12 rules |
| SARIF for CI/CD | No | Yes |
| Drift detection | No | Yes |
| Tamper-evident audit log | No | Yes |
| Custom rules, no code | No | Yes |
| White-label reports | Paid add-on | Included |
| License | Per-device subscription | One-time, per machine |
06 · Who it's for
Air-gap ready, with STIG and CMMC packs built in.
PCI-DSS 4.0 evidence and an audit log your QSA can trust.
Batch-scan 100+ configs and white-label every report.
SARIF in your pull requests. Exit code 2 blocks the merge.
07 · CI/CD
One static binary. SARIF out, straight into GitHub, Azure DevOps or your SIEM.
# Audit every config on push and pull request
name: network-config-audit
on: [push, pull_request]
jobs:
audit:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- run: natmesh-cli scan ./configs/*.cfg \
--format sarif --exit-on critical,high --out natmesh.sarif
- uses: github/codeql-action/upload-sarif@v3
with: { sarif_file: natmesh.sarif }Pipeline output
✓ scan complete · 1247 lines · 12 findings · 3 critical
✗ exit code 2 · build blocked by critical findings
08 · License
The license file binds to a machine ID. No phone-home, no subscription meter.
One workstation, one operator.
Contact us
One-time · per machine
For MSSPs and consultancies.
Contact us
One-time · 5 machines
For defense primes, federal SIs and large banks.
Custom
Contact us for a quote
09 · FAQ
Something missing? Ask us. Engineers answer.
No. No telemetry, no license server, no update beacon. The license is checked locally, so it runs on air-gapped networks unchanged.
A curated set of 22 high-impact CVEs ships in the binary, plus an offline NVD cache. Live NVD lookups are opt-in.
Yes. Rules are plain YAML: patterns to match, plus the text that flows into the report. No Python needed.
Every finding gets four scores: CVSS, STIG CAT, Cisco SIR and a 0–100 score weighted by the device's role in the network.
Each scan event is hash-chained to the one before. verify_audit_integrity() flags any break, even a single changed byte.
0 is clean, 1 means info or low findings, 2 means critical or high. Add --exit-on critical,high to block merges in CI.
Yes. It's perpetual on the licensed machine. Optional maintenance adds new rule packs and CVE updates.
10 · Contact
Tell us about your environment and we'll send a license file for one machine.