Skip to main content

CyberPlain

CyberPlain is a defensive cybersecurity toolkit for Python and the command line. It uses normal English in its names, output, errors, and documentation so beginners can understand what a check did and experienced practitioners can automate it.

Use active network checks only on systems you own or have explicit written permission to test. CyberPlain is designed for defense, education, inventory, and authorized assessment—not exploitation, evasion, credential theft, or disruption.

What is included

Area Command / API What it does
Ports cyberplain ports / scan_ports() Bounded TCP connect scan with service names
Packets cyberplain pcap / summarize_pcap() Offline PCAP/PCAPNG traffic inventory
TLS cyberplain tls / inspect_tls() Certificate, cipher, version, and expiry explanation
Web cyberplain headers / audit_headers() Reviews common HTTP security headers
DNS cyberplain dns Forward and reverse address lookups
Files cyberplain file SHA-256, size, and entropy clues
Integrity cyberplain hash, manifest Hashing and directory change detection
Passwords cyberplain password Local strength feedback; never sends the password
Indicators cyberplain iocs, defang Extracts and safely formats URLs, domains, IPs, emails, and hashes

Install

pip install cyberplain

For offline packet-capture analysis:

pip install "cyberplain[packets]"

Help and API overview

Show the available command-line checks, examples, and authorization guidance:

cyberplain help
cyberplain version

Version 0.2 adds more than 100 dependency-free defensive helpers for local file and log review, IOC handling, network metadata, web posture, password hygiene, cloud/container configuration review, privacy, and report scoring. They are available from the cyberplain.defensive module and can also be imported directly from cyberplain, for example:

from cyberplain import file_entropy, ioc_extract_ipv4, web_missing_headers

Quick examples

# You must explicitly confirm authorization for active port checks.
cyberplain ports 192.168.1.10 --ports 22,80,443,8000-8010 --authorized

cyberplain tls example.com
cyberplain headers https://example.com
cyberplain dns example.com
cyberplain file download.zip
cyberplain hash installer.exe
cyberplain password
cyberplain pcap capture.pcap
cyberplain iocs suspicious-email.txt
cyberplain defang https://example.com/path
cyberplain manifest ./important-files --create baseline.json
cyberplain manifest ./important-files --verify baseline.json

Python API:

from cyberplain import assess_password, hash_file, scan_ports

print(hash_file("download.zip"))
print(assess_password("a long example passphrase"))

result = scan_ports(
    "192.168.1.10",
    "22,80,443",
    authorized=True,  # only after you confirm permission
)
print(result["results"])

Design promises

  • Safe defaults and bounded concurrency.
  • No telemetry; checks run locally unless the feature obviously contacts the host you name.
  • Structured dictionaries/JSON for automation.
  • Plain-English context instead of unexplained security jargon.
  • Honest wording: a missing header or high-entropy file is a clue, not automatic proof of a vulnerability or malware.

Development and PyPI publishing

One-command publishing

From PowerShell inside the extracted project folder:

py publish.py

The script installs the official build/upload tools, deletes only the old local dist directory, builds fresh packages, validates them, asks for a final typed confirmation, and uploads to PyPI. Twine then prompts for the username __token__ and your complete pypi-... API token. The token is never stored by this project.

To test the complete workflow against TestPyPI first:

py publish.py --test

Manual publishing

python -m venv .venv
source .venv/bin/activate          # Windows: .venv\Scripts\activate
pip install -e ".[dev,packets]"
pytest
ruff check .
python -m build
twine check dist/*

# Test upload first
python -m twine upload --repository testpypi dist/*

# Final upload (requires your PyPI API token)
python -m twine upload dist/*

Before publishing, replace the placeholder GitHub URLs in pyproject.toml, confirm that the distribution name is available on PyPI, and choose your author/maintainer metadata.

Scope and roadmap

No responsible package can literally cover every cybersecurity topic in one safe, maintainable release. CyberPlain 0.1 focuses on a strong defensive foundation. Good future additions include SARIF output, YARA rule scanning, OSV dependency checks, richer packet protocol summaries, certificate transparency lookup, and optional integrations with reputable threat-intelligence services.

Metadata

Release files for cyberplain 0.2.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for cyberplain 0.2.1
File Size Uploaded
cyberplain-0.2.1.tar.gz 19.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for cyberplain 0.2.1
File Interpreter ABI Platform
cyberplain-0.2.1-py3-none-any.whl Python 3 none any Details

Total release size: 43.0 kB

Release files / cyberplain-0.2.1.tar.gz

Download URL cyberplain-0.2.1.tar.gz
Size 19.7 kB
Tags Source
SHA-256 checksum
How to use checksums
6e37a7ccb3bf6a13756491eecd2fd5a786d6e3a87621b7508e132583af478777
BLAKE2b-256 checksum
How to use checksums
d8149b0967766a033d4b272a0dba07ecdd5af0883cb85de23543b0b5c724466b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.1

Release files / cyberplain-0.2.1-py3-none-any.whl

Download URL cyberplain-0.2.1-py3-none-any.whl
Size 23.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
0586ec0b419d95ba770528188da6d2db2ecea8e6a9a8fb72130c122a6fdfecc0
BLAKE2b-256 checksum
How to use checksums
d8c24cfbf05a16595512386af1c30341653da0fc209871aab47c15e881893754
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.1

Release history Release notifications | RSS feed

0.3.2

2 release files

0.3.1

2 release files

0.3.0

2 release files

0.2.8

2 release files

0.2.7

2 release files

0.2.6

2 release files

0.2.5

2 release files

0.2.4

2 release files

0.2.3

2 release files

0.2.2

2 release files

This release

0.2.1 This release

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page