vamp-windows-audit
Windows Security Configuration Auditor — 15 CIS-aligned checks for authorized security testing.
Overview
vamp-windows-audit analyzes Windows system configurations for common security misconfigurations. Data collection runs as a PowerShell script on the target; analysis can run on any platform (Linux, macOS, Windows) from the collected JSON.
Checks (WIN-001..015)
| ID | Title | Severity | CIS |
|---|---|---|---|
| WIN-001 | SMBv1 habilitado | CRITICAL | CIS 18.3.3 |
| WIN-002 | Cuenta Guest activa | HIGH | CIS 2.3.1.3 |
| WIN-003 | Cuenta Administrator sin renombrar | MEDIUM | CIS 2.3.1.1 |
| WIN-004 | Complejidad de contraseña desactivada | HIGH | CIS 1.1.5 |
| WIN-005 | Umbral de bloqueo de cuenta no configurado | HIGH | CIS 1.2.2 |
| WIN-006 | UAC desactivado | CRITICAL | CIS 2.3.17.1 |
| WIN-007 | Windows Firewall desactivado (algún perfil) | HIGH | CIS 9.1-9.3 |
| WIN-008 | RDP sin Network Level Authentication (NLA) | HIGH | CIS 18.9.52.1 |
| WIN-009 | Windows Defender / AV desactivado | CRITICAL | CIS 18.9.47.4 |
| WIN-010 | Actualizaciones automáticas desactivadas | MEDIUM | CIS 18.9.8 |
| WIN-011 | Auditoría de inicio de sesión no configurada | MEDIUM | CIS 17.5.1 |
| WIN-012 | PowerShell con política de ejecución irrestricta | MEDIUM | CIS 18.9.76.1 |
| WIN-013 | Servicio Remote Registry activo | MEDIUM | CIS 2.2.28 |
| WIN-014 | LAPS no desplegado | MEDIUM | CIS 2.3.1 (ext.) |
| WIN-015 | Null Session Pipes sin restringir | HIGH | CIS 2.3.10.3 |
Installation
pip install vamp-windows-audit
Usage
Two-step workflow (cross-platform)
Step 1 — collect on the Windows target (requires PowerShell, run as Administrator):
vamp-windows-audit --collect-script | Set-Content collect.ps1
powershell -ExecutionPolicy Bypass -File collect.ps1 > audit.json
Step 2 — analyze from any machine:
vamp-windows-audit --from-json audit.json
vamp-windows-audit --from-json audit.json --html report.html
vamp-windows-audit --from-json audit.json --json report.json
Collect and analyze locally (Windows only, as Administrator)
vamp-windows-audit --collect
Options
--from-json FILE Analyze pre-collected JSON (cross-platform)
--collect Collect and analyze locally (Windows + Admin)
--collect-script Print the PowerShell collection script to stdout
--json FILE Save JSON report
--html FILE Save HTML report
--case TEXT Case/engagement identifier
--analyst TEXT Analyst name
--severity ... Filter by severity (critical high medium low)
--quiet Exit code only, no output
--version Show version
Exit codes
| Code | Meaning |
|---|---|
| 0 | No findings |
| 1 | HIGH or MEDIUM findings only |
| 2 | At least one CRITICAL finding |
| 3 | Error (invalid input, file not found, etc.) |
License
AGPL-3.0-only — for authorized security testing only.
© VampSecure Studios — VampSecure Labs Security Research Division
Metadata
Release files for vamp-windows-audit 1.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| vamp_windows_audit-1.1.0.tar.gz | 27.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| vamp_windows_audit-1.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 50.9 kB
Release files / vamp_windows_audit-1.1.0.tar.gz
| Download URL | vamp_windows_audit-1.1.0.tar.gz |
|---|---|
| Size | 27.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
9e367eaa32898d2985baf6c7eee598bd09c9b0425ff8d99b9d0d5d013db5d190
|
|
BLAKE2b-256 checksum How to use checksums |
6cc0b4d79e5f8f0176471921db2a648a43a007abb158f84465ea82072e7dfae6
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.9.6
|
Release files / vamp_windows_audit-1.1.0-py3-none-any.whl
| Download URL | vamp_windows_audit-1.1.0-py3-none-any.whl |
|---|---|
| Size | 23.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
c95608f0ae39d63d0edfc0f657dbe54fb8b1bb7d46348af358e401050555bfb8
|
|
BLAKE2b-256 checksum How to use checksums |
b9db482d86dde62052ab11f14385d79e9485560c7c6fec7a73c9897bc1c38b74
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.9.6
|