Know Your Network. Secure Your Infrastructure.
Stop wondering what devices are connected to your network. Stop manually checking if they're secure. PyNetworkIntel automatically discovers everything on your network, finds security issues, and explains what matters—in plain English you can actually act on.
Works with: Any network size • Any industry • On-premises or cloud • Single scan or continuous monitoring
Status: v1.0.0 - Enterprise-Ready with AI Architecture Advisor
Latest Release: 2026-07-28
Used by: System Administrators • DevOps Teams • Security Teams • IT Managers • Cloud Architects • Startups to Enterprises
What's New in v1.0.0:
- Multi-cloud discovery (AWS, Azure, GCP)
- Kubernetes security analysis (RBAC, pod security, network policies)
- ML-powered anomaly detection & vulnerability forecasting
- Enterprise features (HA, multi-tenancy, SSO, compliance auditing)
- AI Architecture Advisor (pattern recognition, cost optimization, roadmap generation)
Before PyNetworkIntel:
- Manual checking: "Is device X online?"
- Blind spots: Not knowing what's actually connected
- Manual config review: SSH into each device individually
- Guessing: "Is this port supposed to be open?"
- Reactive: Finding security issues after something breaks
After PyNetworkIntel:
- Automatic discovery: Know everything connected to your network
- Security analysis: Find issues before they become problems
- Plain English: Explanations anyone can understand
- Continuous monitoring: Track changes automatically
- Actionable insights: Know exactly what to fix, in what order
Discover all your cloud resources automatically - AWS, Azure, GCP
# Find all resources across multiple clouds
pynetworkintel cloud-scan --aws --azure --gcp
# Get cross-cloud asset correlation
pynetworkintel cloud-analyze --correlate- Multi-cloud inventory (EC2, VMs, compute instances, databases)
- Security group analysis, firewall rule review
- Cross-cloud network path analysis
- Credential management (secure storage with 600-bit encryption)
Secure your Kubernetes clusters and containerized workloads
# Analyze K8s cluster security
pynetworkintel k8s-analyze --cluster my-cluster
# Check pod security, RBAC, network policies
pynetworkintel k8s-review --rbac --pods --network-policies- Full cluster discovery (nodes, pods, deployments)
- RBAC analysis with risk scoring
- Pod security context review
- Network policy coverage analysis
Predict vulnerabilities and detect anomalies before they're exploited
# Learn baseline behavior and detect anomalies
pynetworkintel ml-baseline --device-id server-01
pynetworkintel ml-detect-anomalies --device-id server-01- Behavioral baseline learning
- Anomaly detection (port scans, bandwidth spikes, unusual connections)
- Vulnerability discovery forecasting
- Attack surface growth prediction
Deploy at scale with HA, multi-tenancy, and enterprise authentication
# Start HA cluster
pynetworkintel cluster-start --nodes 3 --region us-east-1
# Create tenant for customer
pynetworkintel tenant-create --name "Acme Corp" --api-key mykey123- High availability (99.9% SLA, multi-node deployment)
- Multi-tenant isolation with per-tenant encryption
- Enterprise auth (LDAP, OAuth 2.0, SAML 2.0, MFA)
- REST API with rate limiting
- Compliance auditing (SOC 2, ISO 27001, PCI-DSS, HIPAA)
Get Principal Architect-level guidance on your infrastructure
# Analyze architecture and get recommendations
pynetworkintel architect-review --architecture myarch.json
# Generate implementation roadmap
pynetworkintel architect-roadmap --current state.json --target goals.json --months 12- Architecture graph modeling and SPOF detection
- Pattern recognition (serverless, microservices, multi-cloud)
- Reliability, security, scalability, cost reviews
- ROI-aware recommendations
- Phased implementation roadmaps
- Natural language Q&A about architecture
What You Need:
- Python 3.10+ (check with
python --version) - nmap (network scanning tool)
What's Optional:
- AI Summaries (pick any one):
- Anthropic Claude (cloud-based, no setup needed)
- Ollama (runs locally on your machine, completely private)
- Other LLM endpoints (any REST API)
- Or use without any AI (built-in analysis is powerful enough)
Note: PyNetworkIntel works perfectly fine without any AI! The AI just adds natural language explanations. All core security scanning works offline.
Install nmap (if not already installed):
# macOS
brew install nmap
# Ubuntu/Debian
sudo apt-get install nmap
# Fedora/RHEL
sudo dnf install nmap
# Windows (Chocolatey)
choco install nmap
# Windows (Manual)
# Download from https://nmap.org/download.html and add to PATHInstall PyNetworkIntel:
pip install pynetworkintelVerify installation:
pynetworkintel --version
# Should show: cli.py 0.2.0Scan your local network:
pynetworkintel scan 192.168.1.0/24What you'll see:
Discovering devices... ✓
Found 12 devices
- 192.168.1.1 (router): SSH, HTTP, HTTPS
- 192.168.1.10 (laptop): SSH, RDP
- 192.168.1.50 (printer): HTTP
- 192.168.1.100 (server): SSH, MySQL, PostgreSQL
... and 8 more
Get security analysis:
pynetworkintel analyze 192.168.1.0/24 --summarizeWhat you'll see:
✅ GOOD NEWS:
- All 12 devices are responding
- Network connectivity is stable
⚠️ PROBLEMS TO FIX (in order of importance):
1. MySQL database exposed to entire network
→ Why: Anyone on network can attempt database access
→ Fix: Restrict port 3306 to server IPs only
2. SSH password authentication enabled on 5 devices
→ Why: Allows brute-force attacks
→ Fix: Disable password auth, use SSH keys only
3. Server running Windows 7 (unsupported OS)
→ Why: No security updates since 2020
→ Fix: Upgrade to Windows Server 2022
Situation: New server arrives, you need to know what's on it before putting it into production.
# Scan the new server
pynetworkintel scan 192.168.1.100 --ssh-user admin --ssh-key ~/.ssh/id_rsa
# Output tells you:
# - What services are running (SSH, HTTP, database, etc.)
# - Which versions (vulnerable or current?)
# - What configuration issues exist
# - What needs to be fixed before productionSituation: Managing multiple servers, workstations, and IoT devices. Need to know which ones have security issues.
# Scan your entire network
pynetworkintel analyze 10.0.0.0/16 --summarize
# Get a dashboard view of:
# - Total devices connected
# - Critical security issues (stop using these right now)
# - High-priority issues (fix within 30 days)
# - Medium-priority issues (track and plan fixes)
# - Compliant devices (no action needed)Situation: You want to know immediately if a security issue appears or a device goes offline.
# Set up automatic hourly scans with alerts
pynetworkintel init-config
# Edit ~/.pynetworkintel/config.yaml to enable Slack alerts
# Then start monitoring in the background
# Device goes offline? ➜ Slack alert
# New vulnerability detected? ➜ Slack alert
# New device appears? ➜ Slack alertSituation: Need to prove to auditors that you know what's on your network and it's secure.
# Generate compliance reports
pynetworkintel analyze 10.0.0.0/8 > scan_results.json
pynetworkintel report > compliance_report.md
# Reports include:
# - Complete device inventory
# - Security findings with evidence
# - Timeline of changes
# - Remediation status
# ➜ Perfect for audits and compliance checksSituation: Security alert fired, need to understand the attack surface right now.
# Get immediate vulnerability snapshot
pynetworkintel analyze 192.168.1.0/24
# See:
# - Every device's security posture
# - Known vulnerabilities in each service
# - Configuration issues that might have been exploited
# - Which devices are most at risk$ pynetworkintel analyze 192.168.1.0/24 --summarizeOutput:
═══════════════════════════════════════════════════════════════
Network Analysis Results
Total Devices: 12
Critical Issues: 1
High Priority Issues: 4
Medium Priority Issues: 3
All Devices Online: ✓
═══════════════════════════════════════════════════════════════
TOP ISSUES TO FIX
1. [CRITICAL] MySQL Database Exposed to Network
Device: 192.168.1.50
Why it matters: Any computer on the network can access your database
How to fix it: Add firewall rule to restrict port 3306 to only the
web server (192.168.1.100)
Timeline: Fix TODAY (this is a critical security risk)
2. [HIGH] SSH Password Authentication Enabled
Device: 192.168.1.100 (web-server)
Why it matters: Hackers can attempt to guess SSH passwords
How to fix it: Disable password auth in /etc/ssh/sshd_config
Restart SSH service
Timeline: Fix within 1 week
3. [HIGH] Telnet Service Running (Unencrypted)
Device: 192.168.1.25
Why it matters: All Telnet traffic is sent in plain text (no encryption)
How to fix it: Disable Telnet, use SSH instead
Timeline: Disable immediately
4. [HIGH] Old Apache Version (2.2.15 - EOL 2018)
Device: 192.168.1.100 (web-server)
Why it matters: Running an outdated web server with known vulnerabilities
How to fix it: Upgrade Apache to version 2.4.54 or later
Timeline: Fix within 2 weeks
5. [MEDIUM] Default Credentials Detected
Device: 192.168.1.75 (printer)
Why it matters: Anyone can change printer settings or print sensitive data
How to fix it: Log in and change the default admin password
Timeline: Fix within 1 month
═══════════════════════════════════════════════════════════════
DEVICES THAT ARE FINE
✓ 7 devices with no critical issues
═══════════════════════════════════════════════════════════════
- Scans your network and finds every device
- Identifies what operating system each device runs
- Detects every service running (SSH, HTTP, databases, etc.)
- Gets version numbers for each service
- Reviews device configurations (SSH settings, firewall rules, etc.)
- Checks against 10+ built-in security best practices
- Explains why each setting matters
- Tells you exactly how to fix issues
- Compares service versions against known vulnerabilities
- Shows CVSS risk scores (how bad is it?)
- Explains if the vulnerability can actually be exploited
- Recommends which versions to upgrade to
- Tells you which issues to fix first
- Explains why in business terms (not technical jargon)
- Saves you time by eliminating guesswork
- Can automatically scan hourly/daily
- Detects when something changes
- Sends alerts (Slack, email) when issues appear
- Tracks your progress over time
- Automatic network device discovery (any network size)
- Service and version detection for every device
- SSH configuration analysis and review
- Support for Windows, macOS, Linux, BSD, IoT devices
- Firewall rule detection and analysis
- 10+ built-in security rules (SSH, protocols, credentials, etc.)
- CVE database integration (knows about known vulnerabilities)
- CVSS risk scoring (prioritize by severity)
- Explains vulnerabilities in plain English
- Configuration compliance checking
- Claude AI (via Anthropic) - For advanced AI summarization
- Ollama - Run LLMs locally (no cloud, completely private)
- Other endpoints - Works with any REST API LLM
- Fallback mode - Works great without any AI (built-in analysis sufficient)
- Continuous monitoring (hourly, daily, weekly scans)
- Change detection (new devices, vulnerabilities, config changes)
- Multi-channel alerts: Slack, Email, Webhooks
- Device status tracking (online/offline detection)
- Automatic report generation
- SQLite (local) or PostgreSQL (team deployments)
- Export to JSON, Markdown, or text
- Detailed compliance reports
- Historical tracking of changes
- Audit trail of all findings
- Local installation:
pip install pynetworkintel - Docker container: For scanning remote networks
- Python API: For custom integration
- CLI tool: For standalone scans
- Daemon mode: For background continuous monitoring
| Feature | PyNetworkIntel | Nmap | OpenSCAP | Lynis | Prometheus |
|---|---|---|---|---|---|
| Network Discovery | ✅ Full | ✅ Advanced | ❌ Limited | ❌ No | ❌ No |
| Service Detection | ✅ Yes | ✅ Yes | ❌ No | ❌ No | ❌ No |
| Configuration Analysis | ✅ Yes | ❌ No | ✅ Compliance-focused | ✅ Host-based | ❌ No |
| CVE Checking | ✅ Yes | ❌ No | ✅ Yes | ✅ Yes | ❌ No |
| Continuous Monitoring | ✅ Yes | ❌ One-time only | ❌ No | ❌ One-time only | ✅ Yes |
| AI Summaries | ✅ Optional | ❌ No | ❌ No | ❌ No | ❌ No |
| Multi-Channel Alerts | ✅ Slack, Email, Webhooks | ❌ No | ❌ No | ❌ No | ✅ Yes (basic) |
| Easy to Use | ✅ Plain English | ||||
| No Training Needed | ✅ Yes | ❌ Steep learning curve | ❌ Requires setup | ❌ Complex | ❌ Complex |
| All-in-One Solution | ✅ Yes | ❌ Scanning only | ❌ Compliance only | ❌ Audit only | ❌ Metrics only |
Why PyNetworkIntel is Different:
- Combines discovery, analysis, CVE checking, and monitoring in one tool
- Explains findings in plain English (no technical jargon)
- Works out-of-the-box (no complex setup)
- Suitable for non-experts (DevOps, IT managers, system admins)
- All open-source dependencies (or use your own LLM)
# Initialize configuration
pynetworkintel init-config
# Simple network scan
pynetworkintel scan 192.168.1.0/24
# Full analysis with AI summary
pynetworkintel analyze 192.168.1.0/24 \
--ssh-user admin \
--ssh-key ~/.ssh/id_rsa \
--summarize
# Scan with output to file
pynetworkintel scan 192.168.1.0/24 --output-file results.json
# Help and version
pynetworkintel --help
pynetworkintel --version# Build image
docker build -t pynetworkintel:0.2.0 .
# Run scan
docker run -it pynetworkintel:0.2.0 scan 192.168.1.0/24
# With SSH credentials mounted
docker run -v ~/.ssh:/root/.ssh:ro pynetworkintel:0.2.0 \
scan 192.168.1.0/24 --ssh-key ~/.ssh/id_rsaDiscovery Engine Analysis Engine Output
↓ ↓ ↓
Nmap Scanner ──→ Rule Checker ──→ LLM ──→ CLI/JSON
SSH Config ──→ CVE Checker ──→ Reports
Grabber ──→ Scoring ──→ Alerts
↓
Database (SQLite/PostgreSQL)
↓
Scheduler (APScheduler)
↓
Change Detection & Alerting
Required:
- Python 3.10+ (tested on 3.10, 3.11, 3.12, 3.13)
- nmap (for network scanning)
- ~100 MB disk space
Optional:
- SSH access to target devices (for config grabbing)
- Anthropic API key (for Claude summaries; fallback available)
- PostgreSQL (production deployments; SQLite works for testing)
nmap:
# macOS
brew install nmap
# Ubuntu/Debian
sudo apt-get install nmap
# Fedora/RHEL
sudo dnf install nmap
# Alpine
apk add nmap
# Windows
# Option 1: Chocolatey
choco install nmap
# Option 2: Download installer from https://nmap.org/download.html
# Then add nmap to PATH
# Verify installation (all platforms)
nmap -versionPython Dependencies:
Automatically installed with pip install pynetworkintel:
- paramiko (SSH)
- netaddr (IP utilities)
- requests (HTTP)
- anthropic (Claude API)
- rich (UI/progress)
- sqlalchemy (database)
- apscheduler (scheduling)
# Create default config file
pynetworkintel init-config
# Edit configuration (use your preferred editor)
# Linux/macOS: nano, vim, or VSCode
nano ~/.pynetworkintel/config.yaml
# Windows: PowerShell or Notepad
notepad $env:USERPROFILE\.pynetworkintel\config.yamlFor SSH Access to Devices (required for config grabbing):
Linux/macOS:
export PYNETWORKINTEL_SSH_USER="admin"
export PYNETWORKINTEL_SSH_KEY="~/.ssh/id_rsa"Windows (PowerShell):
$env:PYNETWORKINTEL_SSH_USER="admin"
$env:PYNETWORKINTEL_SSH_KEY="$env:USERPROFILE\.ssh\id_rsa"For AI-Powered Summaries (completely optional):
Option 1: Use Anthropic Claude (easiest):
export ANTHROPIC_API_KEY="sk-ant-..."Option 2: Use Ollama Locally (private, no cloud):
# First, install Ollama from https://ollama.ai
# Then start it: ollama run llama2
# Configure PyNetworkIntel:
export PYNETWORKINTEL_LLM_ENDPOINT="http://localhost:11434"
export PYNETWORKINTEL_LLM_MODEL="llama2"Option 3: Use Any Other LLM (OpenAI compatible):
export PYNETWORKINTEL_LLM_ENDPOINT="http://your-api.example.com"
export PYNETWORKINTEL_LLM_MODEL="gpt-4"
export PYNETWORKINTEL_LLM_API_KEY="your-api-key"No AI (works great, just simpler output):
# Don't set any LLM variables
# PyNetworkIntel will use built-in analysisssh:
username: root
key_path: ~/.ssh/id_rsa
password: null
timeout: 10
scan:
timeout: 300
nmap_args: "-sV"
grab_configs: true
retry_count: 1
analysis:
enable_cve_check: true
enable_llm_summary: true
cve_cache_ttl: 86400
output:
format: text
verbose: false
color: true# Automatically created on first run
pynetworkintel scan 192.168.1.0/24
# Creates: ./pynetworkintel.db# Create database
createdb pynetworkintel
# Configure connection
export DATABASE_URL="postgresql://user:password@localhost/pynetworkintel"$ pynetworkintel scan 192.168.1.0/24
Discovered Devices:
- 192.168.1.1 (router): SSH, HTTP, HTTPS
- 192.168.1.100 (laptop): SSH
- 192.168.1.50 (printer): HTTP$ pynetworkintel analyze 10.0.0.0/24 --summarize
✅ GOOD NEWS:
- 24 devices discovered
- Connectivity stable
- No critical vulnerabilities
⚠️ PROBLEMS TO FIX:
1. SSH password auth enabled on 3 devices
2. Telnet service exposed on 1 device
3. Default credentials detected on 2 devices
Next Steps: Fix critical issues firstfrom pynetworkintel.scheduler import MonitoringScheduler
from pynetworkintel.alerts import AlertManager, SlackAlertChannel
# Setup database
from pynetworkintel.db import init_db
db = init_db("sqlite:///pynetworkintel.db")
# Create scheduler
scheduler = MonitoringScheduler(database_url="sqlite:///pynetworkintel.db")
# Add recurring scan
scheduler.add_scan_job(
job_id="production",
target="10.0.0.0/24",
schedule_type="interval",
hours=1 # Scan hourly
)
# Add alerts
alert_manager = AlertManager(db)
alert_manager.add_channel(
"slack",
SlackAlertChannel(webhook_url="https://hooks.slack.com/...")
)
# Start monitoring
scheduler.start()Phase 1-4 ✅ Complete
- Network discovery, vulnerability detection, continuous monitoring
Phase 5 📅 Planned (4-6 weeks)
- Cloud integration (AWS, Azure, GCP)
- Kubernetes discovery
- ML-powered analytics
Phase 6 📅 Planned (6-8 weeks)
- Enterprise HA (99.9% SLA)
- Multi-tenancy
- Advanced compliance
Phase 7 📅 Planned (8-12 weeks)
- AI-native architecture advisor
See Phase 5-7 Planning for details.
# Install nmap for your system (see Install Dependencies)
# macOS: brew install nmap
# Ubuntu: sudo apt-get install nmap# Test SSH connection manually first
ssh -i ~/.ssh/id_rsa admin@192.168.1.1
# Then try scan with verbose logging
pynetworkintel scan 192.168.1.0/24 --verbose --ssh-user admin --ssh-key ~/.ssh/id_rsa# NVD API allows ~1 request per 6 seconds (free tier)
# PyNetworkIntel automatically handles rate limiting
# Results are cached to minimize API calls
# Reset SQLite database
rm pynetworkintel.db
pynetworkintel scan 192.168.1.0/24Typical scan times (single /24 subnet):
- Discovery: 1-5 minutes (depends on device response times)
- Analysis: 30-60 seconds
- CVE checking: 1-3 minutes
- LLM summarization: 10-20 seconds
Database queries: <100ms for typical operations
- ✅ No data sent to external services (except NVD CVE API and Anthropic Claude)
- ✅ SSH credentials stored locally
- ✅ Configuration kept in ~/.pynetworkintel/
- ✅ Scan results stored in local database
⚠️ Requires API key for Claude summaries (optional)
License: Proprietary. All rights reserved.
Distribution: Wheels only. Source code is proprietary and not published to PyPI.
For licensing inquiries, contact: mullassery@gmail.com
Issues & Questions: mullassery@gmail.com
GitHub: https://github.com/Mullassery/PyNetworkIntel
License: See LICENSE file
PyNetworkIntel v0.2.0 - AI-Powered Network Intelligence Platform
From network scanner to infrastructure advisor