Every check Noxen runs
Agentless coverage over your existing SSH keys - no agent on the target, no new ports to open. Every check below runs against every enrolled host as an ordered pipeline; a typical host finishes in 10–60 seconds depending on open-port count. Findings diff against the previous scan, so the morning report is what changed, not the same alerts you read yesterday.
Inventory & CVEs
- SSH inventory - reads
/etc/os-release, kernel version, dpkg/rpm package list,sshd_config,authorized_keys. All read-only. - CPE → CVE matching - installed packages cross-referenced against a signed feed sourced from NVD (primary) and OSV.dev (Debian + Ubuntu + Rocky/AlmaLinux). See the live feed dashboard for current totals and top recent critical/high CVEs.
- Severity bucketing - distro-tagged labels first (Ubuntu / Debian triage), CVSS v3 vector parsed for the rest. Severity bucket and the numeric score both surfaced in the UI.
Network exposure
- Port scan - a 40-port shortlist of the services homelabs actually run, via Apple's Network framework. No
nmapbinary required. - TLS audit - weak ciphers, deprecated protocols (TLS 1.0/1.1, SSLv3), weak signature algorithms, undersized RSA/EC keys, self-signed certs, missing SANs, near-expiry certs. Runs against any TLS-capable open port.
- HTTP security headers - CSP, X-Frame-Options, Referrer-Policy, Permissions-Policy, HSTS, X-Content-Type-Options.
- Exposed admin surfaces - fingerprints 70+ services: Home Assistant, Plex, Jellyfin, Sonarr/Radarr, Pi-hole, pfSense, OPNsense, UniFi, Mikrotik, Proxmox, TrueNAS, Synology, QNAP, Gitea, Jenkins, Grafana, Prometheus, Uptime Kuma, Netdata, Portainer, Kubernetes, Docker, Consul, Vault, Traefik, phpMyAdmin, Kibana, unauth Elasticsearch / Redis / Mongo, Git config leaks, .env file leaks. Flag only - never authenticates against the surface.
Workflow
- Diff-from-yesterday - each scan compares to the previous scan; UI defaults to "what's new" rather than "everything we know about this host."
- Scheduled nightly scans - registered via
SMAppService; survive sleep / wake, run on AC power only by default. - Batch scan - "Scan all" toolbar button runs every enrolled host sequentially with a live progress banner. Cancellable.
- Local-first storage - host catalog + scan history live on your Mac in SwiftData. CloudKit sync is wired but disabled in v1.0; it'll re-enable in lock-step with the iOS view-only companion. SSH keys live in Keychain regardless.
The scheduled-scan helper is Noxen's own, built for this app. If you want the same always-on treatment for the network itself rather than the hosts on it, PingKit's Mac Agent is a separate product from the same maker that watches a home network continuously from the menu bar. Different codebases, same idea: the check that matters is the one you never have to remember to run.
Reporting & integration
- PDF report export - summary, per-host detail, remediation hints. Suitable for client deliverables.
- SIEM export (NDJSON) - JSON Lines for Wazuh / Splunk / ELK / Loki ingest. Supports global tags (
env,region, etc.). - Compliance mapping - CIS Controls v8, SOC 2, ISO 27001:2022 control references per scan. CSV export. Evidence supplement, not a compliance claim.
- Webhooks - Slack / Discord / Teams / generic JSON; payload auto-formatted per sink. Paid plan.
Customisation
- Custom checks - drop
*.jsonfiles into~/Library/Application Support/app.noxen/custom-checks/. HTTP path + markers, or TCP send + markers. Schema in the docs. - Multi-tenant host catalogs - group hosts by client / environment. Planned for the MSP plan, still in design.
- Command palette - ⌘⇧P opens a fuzzy-searchable action list. Every shortcut is discoverable here.
What Noxen does not do
- No default-credential testing. Noxen will flag an exposed admin surface; it will never try to authenticate against it. Why.
- No agent. Everything runs over SSH using a key you already have in
~/.ssh/config. - No SaaS round-trip. Scan results live in your local SwiftData store on your Mac. Noxen's servers only host the signed CVE feed.