vamp-windows-audit
Windows Security Configuration Auditor — 15 CIS-aligned checks for authorized security testing.
Overview
vamp-windows-audit analyzes Windows system configurations for common security misconfigurations. Data collection runs as a PowerShell script on the target; analysis can run on any platform (Linux, macOS, Windows) from the collected JSON.
Checks (WIN-001..015)
| ID | Title | Severity | CIS |
|---|---|---|---|
| WIN-001 | SMBv1 habilitado | CRITICAL | CIS 18.3.3 |
| WIN-002 | Cuenta Guest activa | HIGH | CIS 2.3.1.3 |
| WIN-003 | Cuenta Administrator sin renombrar | MEDIUM | CIS 2.3.1.1 |
| WIN-004 | Complejidad de contraseña desactivada | HIGH | CIS 1.1.5 |
| WIN-005 | Umbral de bloqueo de cuenta no configurado | HIGH | CIS 1.2.2 |
| WIN-006 | UAC desactivado | CRITICAL | CIS 2.3.17.1 |
| WIN-007 | Windows Firewall desactivado (algún perfil) | HIGH | CIS 9.1-9.3 |
| WIN-008 | RDP sin Network Level Authentication (NLA) | HIGH | CIS 18.9.52.1 |
| WIN-009 | Windows Defender / AV desactivado | CRITICAL | CIS 18.9.47.4 |
| WIN-010 | Actualizaciones automáticas desactivadas | MEDIUM | CIS 18.9.8 |
| WIN-011 | Auditoría de inicio de sesión no configurada | MEDIUM | CIS 17.5.1 |
| WIN-012 | PowerShell con política de ejecución irrestricta | MEDIUM | CIS 18.9.76.1 |
| WIN-013 | Servicio Remote Registry activo | MEDIUM | CIS 2.2.28 |
| WIN-014 | LAPS no desplegado | MEDIUM | CIS 2.3.1 (ext.) |
| WIN-015 | Null Session Pipes sin restringir | HIGH | CIS 2.3.10.3 |
Installation
pip install vamp-windows-audit
Usage
Two-step workflow (cross-platform)
Step 1 — collect on the Windows target (requires PowerShell, run as Administrator):
vamp-windows-audit --collect-script | Set-Content collect.ps1
powershell -ExecutionPolicy Bypass -File collect.ps1 > audit.json
Step 2 — analyze from any machine:
vamp-windows-audit --from-json audit.json
vamp-windows-audit --from-json audit.json --html report.html
vamp-windows-audit --from-json audit.json --json report.json
Collect and analyze locally (Windows only, as Administrator)
vamp-windows-audit --collect
Options
--from-json FILE Analyze pre-collected JSON (cross-platform)
--collect Collect and analyze locally (Windows + Admin)
--collect-script Print the PowerShell collection script to stdout
--json FILE Save JSON report
--html FILE Save HTML report
--case TEXT Case/engagement identifier
--analyst TEXT Analyst name
--severity ... Filter by severity (critical high medium low)
--quiet Exit code only, no output
--version Show version
Exit codes
| Code | Meaning |
|---|---|
| 0 | No findings |
| 1 | HIGH or MEDIUM findings only |
| 2 | At least one CRITICAL finding |
| 3 | Error (invalid input, file not found, etc.) |
License
AGPL-3.0-only — for authorized security testing only.
© VampSecure Studios — VampSecure Labs Security Research Division
Metadata
Release files for vamp-windows-audit 1.0.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| vamp_windows_audit-1.0.0.tar.gz | 24.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| vamp_windows_audit-1.0.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 47.1 kB
Release files / vamp_windows_audit-1.0.0.tar.gz
| Download URL | vamp_windows_audit-1.0.0.tar.gz |
|---|---|
| Size | 24.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
3c66e94cf19ab16cb7b2f3664800218821d432997c60638c5fa2f225ac3503c5
|
|
BLAKE2b-256 checksum How to use checksums |
fbdfca4b1f6f7627a8d91834be064b00b873d5368e14e5501268a0973e482652
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.9.6
|
Release files / vamp_windows_audit-1.0.0-py3-none-any.whl
| Download URL | vamp_windows_audit-1.0.0-py3-none-any.whl |
|---|---|
| Size | 22.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
9120ce347900c818ff690d8b8ca5e60456ca7e14f42b7ce87e1bcb376f2bb229
|
|
BLAKE2b-256 checksum How to use checksums |
a61c559582e892dd71d4d1415fd7eed01313f47e7aa68689c8bdf1b7094a882a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.9.6
|