Skip to content

Offline config auditor · v1.4.2

Every misconfig.Surfaced.Before the breach.

Drop in a router or firewall config. Get a scored, compliance-mapped report without a single packet touching your network.

Reads 28 vendor formats

  • Cisco IOS
  • IOS-XE
  • NX-OS
  • Cisco ASA
  • Juniper Junos
  • Palo Alto PAN-OS
  • Fortinet FortiOS
  • Check Point
  • Huawei VRP
  • H3C Comware
  • F5 BIG-IP
  • HPE Aruba
  • Extreme
  • Sangfor
  • Forcepoint
  • Trellix
  • Trend Micro
  • Netskope
  • Proofpoint
  • BeyondTrust
  • IBM
  • Ericsson
Security rules
202
Vendor parsers
28
Compliance frameworks
6
Phone-home calls
0

01 · Engine

Watch a real config get torn apart.

No agents. No credentials. Export the config, drop it in, read the findings.

edge-fw-01.cfgSHA · 0xa3f4
Findings0 findings
    Scan 0%Lines 31 · Findings 0 · Critical 0

    02 · Scoring

    Four scores. One finding.

    Severity, DoD posture, the vendor's own rating, and a score weighted by where the device sits.

    • 01 / 04

      CVSS v3.1

      Base, temporal and environmental scores.

    • 02 / 04

      DISA STIG

      CAT I, II or III, ready for your RMF package.

    • 03 / 04

      Cisco SIR

      The vendor's own security impact rating.

    • 04 / 04

      Role-weighted

      Same misconfig scores higher on a border firewall.

    03 · Depth

    What a port scanner never sees.

    01 / 03

    Zero Trust scoring

    Segmentation, graded.

    Any-any rules, loose egress and flat zones surface as ranked findings.

    02 / 03

    Drift detection

    Every scan, compared.

    See what was fixed, what regressed and what's new since your golden baseline.

    03 / 03

    Tamper-evident audit

    Edited? You'll know.

    Each scan is hash-chained to the last. One altered byte breaks the chain.

    Nothing leaves the machine.

    04 · Compliance

    Audit evidence, pre-mapped.

    Pass or fail per control, with evidence your assessor already knows how to read.

    • CAT I · II · III

      DISA STIG

      12-rule pack mapped to Vul-IDs

    • Req 1 · 2 · 6 · 8 · 10

      PCI-DSS 4.0

      10-rule pack, QSA-ready evidence

    • Level 2 · 3

      CMMC 2.0

      14 rules on NIST 800-171 / 172

    • Rev 5

      NIST 800-53

      Control families on every rule

    • v8

      CIS Controls

      Cross-tagged for audit programs

    • Auth

      NIST 800-63B

      Grades Cisco password types 0–9

    05 · Compare

    NatMesh vs typical online auditors.

    The same feature list, side by side.

    NatMesh vs typical online auditors.
    CapabilityOnline toolsNatMesh
    Vendor parsers~1528
    Security rules~70202
    Runs fully offlineNoYes
    Risk by device roleNoYes
    Zero Trust scoringNoYes
    Offline CVE matchingNo22 + NVD
    CMMC 2.0 rule packNo14 rules
    DISA STIG rule packNo12 rules
    SARIF for CI/CDNoYes
    Drift detectionNoYes
    Tamper-evident audit logNoYes
    Custom rules, no codeNoYes
    White-label reportsPaid add-onIncluded
    LicensePer-device subscriptionOne-time, per machine

    06 · Who it's for

    One binary. Four mandates.

    • 01CMMC · STIG

      Defense & federal

      Air-gap ready, with STIG and CMMC packs built in.

    • 02PCI · QSA

      Financial services

      PCI-DSS 4.0 evidence and an audit log your QSA can trust.

    • 03MSSP

      MSSPs & consultancies

      Batch-scan 100+ configs and white-label every report.

    • 04CI/CD

      DevSecOps

      SARIF in your pull requests. Exit code 2 blocks the merge.

    07 · CI/CD

    Drop it in your pipeline.

    One static binary. SARIF out, straight into GitHub, Azure DevOps or your SIEM.

    • Single static binary
    • SARIF v2.1.0 output
    • Fails the build on critical or high
    .github/workflows/audit.ymlGitHub Actions
    # Audit every config on push and pull request
    name: network-config-audit
    on: [push, pull_request]
    
    jobs:
      audit:
        runs-on: ubuntu-latest
        steps:
          - uses: actions/checkout@v4
          - run: natmesh-cli scan ./configs/*.cfg \
              --format sarif --exit-on critical,high --out natmesh.sarif
          - uses: github/codeql-action/upload-sarif@v3
            with: { sarif_file: natmesh.sarif }

    Pipeline output

    ✓ scan complete · 1247 lines · 12 findings · 3 critical

    ✗ exit code 2 · build blocked by critical findings

    08 · License

    Pay once. Run it forever.

    The license file binds to a machine ID. No phone-home, no subscription meter.

    • Solo

      Analyst

      One workstation, one operator.

      Contact us

      One-time · per machine

      • All 202 rules and 28 parsers
      • All 6 compliance frameworks
      • PDF, HTML, Excel, CSV, SARIF, JSON
      • GUI and headless CLI
      Request license
    • TeamRecommended

      Field Unit

      For MSSPs and consultancies.

      Contact us

      One-time · 5 machines

      • Everything in Analyst
      • Five machine licenses
      • White-label reports
      • Scheduled batch scans, 100+ configs
      • Email support, 1 business day
      Request license
    • Fleet

      Command

      For defense primes, federal SIs and large banks.

      Custom

      Contact us for a quote

      • Everything in Field Unit
      • Unlimited machine licenses
      • Custom rule packs
      • Air-gap install guidance
      • One week of on-site enablement
      Talk to us

    09 · FAQ

    Questions we get often.

    Something missing? Ask us. Engineers answer.

    Q01Does NatMesh ever phone home?

    No. No telemetry, no license server, no update beacon. The license is checked locally, so it runs on air-gapped networks unchanged.

    Q02How does CVE matching work offline?

    A curated set of 22 high-impact CVEs ships in the binary, plus an offline NVD cache. Live NVD lookups are opt-in.

    Q03Can my team add custom rules?

    Yes. Rules are plain YAML: patterns to match, plus the text that flows into the report. No Python needed.

    Q04What's different about your scoring?

    Every finding gets four scores: CVSS, STIG CAT, Cisco SIR and a 0–100 score weighted by the device's role in the network.

    Q05How is the audit trail tamper-evident?

    Each scan event is hash-chained to the one before. verify_audit_integrity() flags any break, even a single changed byte.

    Q06What do the CLI exit codes mean?

    0 is clean, 1 means info or low findings, 2 means critical or high. Add --exit-on critical,high to block merges in CI.

    Q07Is it really a one-time license?

    Yes. It's perpetual on the licensed machine. Optional maintenance adds new rule packs and CVE updates.

    10 · Contact

    Start a 15-day evaluation.

    Tell us about your environment and we'll send a license file for one machine.

    We only use this to reply to you. See our privacy policy.