Skip to main content

vamp-windows-audit

Windows Security Configuration Auditor — 15 CIS-aligned checks for authorized security testing.

Overview

vamp-windows-audit analyzes Windows system configurations for common security misconfigurations. Data collection runs as a PowerShell script on the target; analysis can run on any platform (Linux, macOS, Windows) from the collected JSON.

Checks (WIN-001..015)

ID Title Severity CIS
WIN-001 SMBv1 habilitado CRITICAL CIS 18.3.3
WIN-002 Cuenta Guest activa HIGH CIS 2.3.1.3
WIN-003 Cuenta Administrator sin renombrar MEDIUM CIS 2.3.1.1
WIN-004 Complejidad de contraseña desactivada HIGH CIS 1.1.5
WIN-005 Umbral de bloqueo de cuenta no configurado HIGH CIS 1.2.2
WIN-006 UAC desactivado CRITICAL CIS 2.3.17.1
WIN-007 Windows Firewall desactivado (algún perfil) HIGH CIS 9.1-9.3
WIN-008 RDP sin Network Level Authentication (NLA) HIGH CIS 18.9.52.1
WIN-009 Windows Defender / AV desactivado CRITICAL CIS 18.9.47.4
WIN-010 Actualizaciones automáticas desactivadas MEDIUM CIS 18.9.8
WIN-011 Auditoría de inicio de sesión no configurada MEDIUM CIS 17.5.1
WIN-012 PowerShell con política de ejecución irrestricta MEDIUM CIS 18.9.76.1
WIN-013 Servicio Remote Registry activo MEDIUM CIS 2.2.28
WIN-014 LAPS no desplegado MEDIUM CIS 2.3.1 (ext.)
WIN-015 Null Session Pipes sin restringir HIGH CIS 2.3.10.3

Installation

pip install vamp-windows-audit

Usage

Two-step workflow (cross-platform)

Step 1 — collect on the Windows target (requires PowerShell, run as Administrator):

vamp-windows-audit --collect-script | Set-Content collect.ps1
powershell -ExecutionPolicy Bypass -File collect.ps1 > audit.json

Step 2 — analyze from any machine:

vamp-windows-audit --from-json audit.json
vamp-windows-audit --from-json audit.json --html report.html
vamp-windows-audit --from-json audit.json --json report.json

Collect and analyze locally (Windows only, as Administrator)

vamp-windows-audit --collect

Options

--from-json FILE    Analyze pre-collected JSON (cross-platform)
--collect           Collect and analyze locally (Windows + Admin)
--collect-script    Print the PowerShell collection script to stdout
--json FILE         Save JSON report
--html FILE         Save HTML report
--case TEXT         Case/engagement identifier
--analyst TEXT      Analyst name
--severity ...      Filter by severity (critical high medium low)
--quiet             Exit code only, no output
--version           Show version

Exit codes

Code Meaning
0 No findings
1 HIGH or MEDIUM findings only
2 At least one CRITICAL finding
3 Error (invalid input, file not found, etc.)

License

AGPL-3.0-only — for authorized security testing only.

© VampSecure Studios — VampSecure Labs Security Research Division

Metadata

Release files for vamp-windows-audit 1.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for vamp-windows-audit 1.0.0
File Size Uploaded
vamp_windows_audit-1.0.0.tar.gz 24.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for vamp-windows-audit 1.0.0
File Interpreter ABI Platform
vamp_windows_audit-1.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 47.1 kB

Release files / vamp_windows_audit-1.0.0.tar.gz

Download URL vamp_windows_audit-1.0.0.tar.gz
Size 24.6 kB
Tags Source
SHA-256 checksum
How to use checksums
3c66e94cf19ab16cb7b2f3664800218821d432997c60638c5fa2f225ac3503c5
BLAKE2b-256 checksum
How to use checksums
fbdfca4b1f6f7627a8d91834be064b00b873d5368e14e5501268a0973e482652
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.9.6

Release files / vamp_windows_audit-1.0.0-py3-none-any.whl

Download URL vamp_windows_audit-1.0.0-py3-none-any.whl
Size 22.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
9120ce347900c818ff690d8b8ca5e60456ca7e14f42b7ce87e1bcb376f2bb229
BLAKE2b-256 checksum
How to use checksums
a61c559582e892dd71d4d1415fd7eed01313f47e7aa68689c8bdf1b7094a882a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.9.6

Release history Release notifications | RSS feed

1.1.0

2 release files

This release

1.0.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page