ios-hardening-audit
Offline security hardening audit for Cisco IOS and IOS-XE running-configs. Point it at one config or a folder of fifty and get, per device, every gap with severity, the evidence line and the exact fix.
pip install ios-hardening-audit
ios-harden configs/*.cfg --csv findings.csv
Rules
| ID | Severity | Check |
|---|---|---|
| H01 | high | enable password in use |
| H02 | high | no enable secret |
| H03 | medium | enable secret stored as MD5 (type 5) |
| H04 | high | local user stored with password instead of secret |
| H05 | medium | local user secret stored as MD5 (type 5) |
| H06 | low | service password-encryption not enabled |
| H07 | medium | AAA not enabled |
| H08 | medium | no AAA login authentication list |
| H09 | low | no AAA exec or command accounting |
| H10 | medium | SSH version 2 not explicitly set |
| H11 | medium | HTTP server enabled |
| H12 | medium | vty transport input not set |
| H13 | high | Telnet allowed on vty |
| H14 | medium | vty without access-class |
| H15 | medium | exec-timeout 0 0 on console or vty |
| H16 | high | default SNMP community (public / private) |
| H17 | high | SNMP read-write community |
| H18 | medium | SNMP community without an ACL |
| H19 | medium | no remote syslog |
| H20 | low | log timestamps not set |
| H21 | medium | no NTP server |
| H22 | low | no login banner |
| H23 | low | no login block-for brute-force protection |
The rules follow common baseline items from CIS Cisco IOS benchmarks and vendor hardening guides. A missing line is reported as "not found in config". Some defaults vary by IOS release, so confirm against the client's version before calling a finding.
Safety
Text parsing only, standard library only, never connects to a device. Passwords, secrets and community strings are redacted from the evidence column, so reports are safe to share. The one exception is the literal default communities public and private, which are shown because they are the finding.
Usage
ios-harden sw1.cfg
ios-harden "configs/*.cfg" --min-severity medium --json findings.json
Exit codes: 0 no high findings, 1 high findings present, 2 error, so it gates a CI pipeline or a scheduled job cleanly.
Pairs with cisco-config-drift: pull the configs read-only, then audit them offline.
Tests
pip install pytest && python -m pytest
License
MIT. See LICENSE. Security reports: see SECURITY.md.
Metadata
Release files for ios-hardening-audit 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| ios_hardening_audit-0.1.0.tar.gz | 6.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| ios_hardening_audit-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 14.0 kB
Release files / ios_hardening_audit-0.1.0.tar.gz
| Download URL | ios_hardening_audit-0.1.0.tar.gz |
|---|---|
| Size | 6.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
07a8b63aedad3c9265253e596276533e636ce76a80bd32a6d9daa323c0f43ed3
|
|
BLAKE2b-256 checksum How to use checksums |
96b7858dbb43a73859cad4688d9761fafe2a1fa9e008e932f0ccf5e3684bbe21
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 7, 2026.
Transparency logRelease files / ios_hardening_audit-0.1.0-py3-none-any.whl
| Download URL | ios_hardening_audit-0.1.0-py3-none-any.whl |
|---|---|
| Size | 7.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
07a67c5be46f6e07f30fc1e3ca462060b293bb23b7957a504ba875033ac88c76
|
|
BLAKE2b-256 checksum How to use checksums |
91e582b136505f8e600f35cb3cc2216ee1b8faab0872d1e2412dc6f041b99880
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 7, 2026.
Transparency log