Skip to main content

ios-hardening-audit

Offline security hardening audit for Cisco IOS and IOS-XE running-configs. Point it at one config or a folder of fifty and get, per device, every gap with severity, the evidence line and the exact fix.

pip install ios-hardening-audit
ios-harden configs/*.cfg --csv findings.csv

Rules

ID Severity Check
H01 high enable password in use
H02 high no enable secret
H03 medium enable secret stored as MD5 (type 5)
H04 high local user stored with password instead of secret
H05 medium local user secret stored as MD5 (type 5)
H06 low service password-encryption not enabled
H07 medium AAA not enabled
H08 medium no AAA login authentication list
H09 low no AAA exec or command accounting
H10 medium SSH version 2 not explicitly set
H11 medium HTTP server enabled
H12 medium vty transport input not set
H13 high Telnet allowed on vty
H14 medium vty without access-class
H15 medium exec-timeout 0 0 on console or vty
H16 high default SNMP community (public / private)
H17 high SNMP read-write community
H18 medium SNMP community without an ACL
H19 medium no remote syslog
H20 low log timestamps not set
H21 medium no NTP server
H22 low no login banner
H23 low no login block-for brute-force protection

The rules follow common baseline items from CIS Cisco IOS benchmarks and vendor hardening guides. A missing line is reported as "not found in config". Some defaults vary by IOS release, so confirm against the client's version before calling a finding.

Safety

Text parsing only, standard library only, never connects to a device. Passwords, secrets and community strings are redacted from the evidence column, so reports are safe to share. The one exception is the literal default communities public and private, which are shown because they are the finding.

Usage

ios-harden sw1.cfg
ios-harden "configs/*.cfg" --min-severity medium --json findings.json

Exit codes: 0 no high findings, 1 high findings present, 2 error, so it gates a CI pipeline or a scheduled job cleanly.

Pairs with cisco-config-drift: pull the configs read-only, then audit them offline.

Tests

pip install pytest && python -m pytest

License

MIT. See LICENSE. Security reports: see SECURITY.md.

Metadata

Release files for ios-hardening-audit 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for ios-hardening-audit 0.1.0
File Size Uploaded
ios_hardening_audit-0.1.0.tar.gz 6.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for ios-hardening-audit 0.1.0
File Interpreter ABI Platform
ios_hardening_audit-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 14.0 kB

Release files / ios_hardening_audit-0.1.0.tar.gz

Download URL ios_hardening_audit-0.1.0.tar.gz
Size 6.9 kB
Tags Source
SHA-256 checksum
How to use checksums
07a8b63aedad3c9265253e596276533e636ce76a80bd32a6d9daa323c0f43ed3
BLAKE2b-256 checksum
How to use checksums
96b7858dbb43a73859cad4688d9761fafe2a1fa9e008e932f0ccf5e3684bbe21
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 7, 2026.

Transparency log

Release files / ios_hardening_audit-0.1.0-py3-none-any.whl

Download URL ios_hardening_audit-0.1.0-py3-none-any.whl
Size 7.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
07a67c5be46f6e07f30fc1e3ca462060b293bb23b7957a504ba875033ac88c76
BLAKE2b-256 checksum
How to use checksums
91e582b136505f8e600f35cb3cc2216ee1b8faab0872d1e2412dc6f041b99880
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 7, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page