By Paul Snyman · Published 2026-04-14 · 6 min read

The Mac-native homelab vulnerability scanner

If you've ever searched for "Mac homelab vulnerability scanner" and come up with enterprise agents, Linux CLI tools, or SaaS dashboards - this post is the answer. Noxen is a native Mac app that scans your homelab the way you already work with it: over SSH, from the machine you sit in front of.

What "Mac-native" means, in practice

What it scans

  1. SSH inventory. Reads /etc/os-release, kernel, dpkg -l/rpm -qa/apk info, sshd_config, authorized_keys from every enrolled host.
  2. CPE → CVE matching. Every package maps to a CPE 2.3 string; every CPE is checked against a signed CVE feed derived from NVD and OSV.
  3. Port scan (a 40-port shortlist) with service names.
  4. TLS audit on any HTTPS / IMAPS / POP3S / MySQL-SSL port: cipher suite, protocol, cert expiry, signature algorithm, key size.
  5. HTTP security headers: CSP, HSTS, X-Frame-Options, Referrer-Policy, Permissions-Policy, server banners.
  6. Exposed admin surfaces: phpMyAdmin, Grafana, Portainer, Kibana, Traefik, Prometheus, unauthenticated Redis / MongoDB / Elasticsearch, .git/config leaks, .env leaks. Flag only - Noxen never authenticates.

Who it's for

Who it's not for

Weighing Noxen against a specific tool? The comparison pages cover Nessus, OpenVAS, Lansweeper, Action1 and Pareto, and each one starts with when the other tool is the better choice.

Pricing, unambiguous

TierPriceHostsFeed
Free$03Snapshot (per release)
Noxen$12/month or $120/year50Daily, signed

An MSP / Team tier with multi-tenant separation is in design and is not on sale - there is no price to quote and no way to buy it yet. What it is meant to become.

No per-seat pricing, no hidden tiers, no "contact sales."

Why not Linux or Windows?

Because the Mac is the operator machine for most homelabs - the MacBook open on the desk while the Proxmox cluster hums in the closet. Putting the scanner on the same machine the operator already uses removes a whole class of "where do we run this" problems. No scanner VM to keep patched, no SSH between the scanner and the management laptop, no split-brain about where findings live.

Noxen does not require you to run anything on Linux. Every probe is initiated from the Mac. The hosts themselves don't know they're being scanned, beyond the normal SSH log lines.

Scan your Linux fleet from your Mac

Noxen runs nightly agentless audits over SSH and shows only what changed since the last scan - new CVEs, config drift, newly exposed admin services. Mac-native control plane, no SaaS round-trip.

Download free Buy - $12/month