Skip to main content

vamp-windows-audit

Windows Security Configuration Auditor — 15 CIS-aligned checks for authorized security testing.

Overview

vamp-windows-audit analyzes Windows system configurations for common security misconfigurations. Data collection runs as a PowerShell script on the target; analysis can run on any platform (Linux, macOS, Windows) from the collected JSON.

Checks (WIN-001..015)

ID Title Severity CIS
WIN-001 SMBv1 habilitado CRITICAL CIS 18.3.3
WIN-002 Cuenta Guest activa HIGH CIS 2.3.1.3
WIN-003 Cuenta Administrator sin renombrar MEDIUM CIS 2.3.1.1
WIN-004 Complejidad de contraseña desactivada HIGH CIS 1.1.5
WIN-005 Umbral de bloqueo de cuenta no configurado HIGH CIS 1.2.2
WIN-006 UAC desactivado CRITICAL CIS 2.3.17.1
WIN-007 Windows Firewall desactivado (algún perfil) HIGH CIS 9.1-9.3
WIN-008 RDP sin Network Level Authentication (NLA) HIGH CIS 18.9.52.1
WIN-009 Windows Defender / AV desactivado CRITICAL CIS 18.9.47.4
WIN-010 Actualizaciones automáticas desactivadas MEDIUM CIS 18.9.8
WIN-011 Auditoría de inicio de sesión no configurada MEDIUM CIS 17.5.1
WIN-012 PowerShell con política de ejecución irrestricta MEDIUM CIS 18.9.76.1
WIN-013 Servicio Remote Registry activo MEDIUM CIS 2.2.28
WIN-014 LAPS no desplegado MEDIUM CIS 2.3.1 (ext.)
WIN-015 Null Session Pipes sin restringir HIGH CIS 2.3.10.3

Installation

pip install vamp-windows-audit

Usage

Two-step workflow (cross-platform)

Step 1 — collect on the Windows target (requires PowerShell, run as Administrator):

vamp-windows-audit --collect-script | Set-Content collect.ps1
powershell -ExecutionPolicy Bypass -File collect.ps1 > audit.json

Step 2 — analyze from any machine:

vamp-windows-audit --from-json audit.json
vamp-windows-audit --from-json audit.json --html report.html
vamp-windows-audit --from-json audit.json --json report.json

Collect and analyze locally (Windows only, as Administrator)

vamp-windows-audit --collect

Options

--from-json FILE    Analyze pre-collected JSON (cross-platform)
--collect           Collect and analyze locally (Windows + Admin)
--collect-script    Print the PowerShell collection script to stdout
--json FILE         Save JSON report
--html FILE         Save HTML report
--case TEXT         Case/engagement identifier
--analyst TEXT      Analyst name
--severity ...      Filter by severity (critical high medium low)
--quiet             Exit code only, no output
--version           Show version

Exit codes

Code Meaning
0 No findings
1 HIGH or MEDIUM findings only
2 At least one CRITICAL finding
3 Error (invalid input, file not found, etc.)

License

AGPL-3.0-only — for authorized security testing only.

© VampSecure Studios — VampSecure Labs Security Research Division

Metadata

Release files for vamp-windows-audit 1.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for vamp-windows-audit 1.1.0
File Size Uploaded
vamp_windows_audit-1.1.0.tar.gz 27.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for vamp-windows-audit 1.1.0
File Interpreter ABI Platform
vamp_windows_audit-1.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 50.9 kB

Release files / vamp_windows_audit-1.1.0.tar.gz

Download URL vamp_windows_audit-1.1.0.tar.gz
Size 27.4 kB
Tags Source
SHA-256 checksum
How to use checksums
9e367eaa32898d2985baf6c7eee598bd09c9b0425ff8d99b9d0d5d013db5d190
BLAKE2b-256 checksum
How to use checksums
6cc0b4d79e5f8f0176471921db2a648a43a007abb158f84465ea82072e7dfae6
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.9.6

Release files / vamp_windows_audit-1.1.0-py3-none-any.whl

Download URL vamp_windows_audit-1.1.0-py3-none-any.whl
Size 23.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
c95608f0ae39d63d0edfc0f657dbe54fb8b1bb7d46348af358e401050555bfb8
BLAKE2b-256 checksum
How to use checksums
b9db482d86dde62052ab11f14385d79e9485560c7c6fec7a73c9897bc1c38b74
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.9.6

Release history Release notifications | RSS feed

This release

1.1.0 This release

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page