
NetLogic is an advanced network analysis and cybersecurity toolkit for traffic inspection, packet analysis, and threat detection
Cloud-Native Attack Surface Mapper & Vulnerability Correlator — v3.0
NetLogic is a network security platform combining active port scanning, CVE correlation (live NVD API), SSL/TLS analysis, HTTP security auditing, DNS/email security assessment, subdomain takeover detection, passive OSINT, active vulnerability probing, an AI-driven reasoning engine, cross-host attack chain discovery, and deep probe agent architecture — delivered as a web app (React dashboard + FastAPI). The core scan engine is pure Python 3.9+ stdlib with zero third-party dependencies.
| Module | Description |
|---|---|
| Port Scanner | TCP connect scan with 43/58 ports, 22 service probes, banner grabbing |
| CVE Correlator | Live NVD API v2.0 + EPSS enrichment via FIRST.org |
| TLS Analyzer | Protocol versions, weak ciphers, POODLE/BEAST/CRIME/DROWN, cert expiry |
| HTTP Header Audit | HSTS, CSP, X-Frame-Options, CORS, cookie flags; 0–100 score |
| Stack Fingerprint | CMS, framework, cloud provider, CDN, WAF detection from banner/header/body |
| DNS Security | SPF, DKIM, DMARC, DNSSEC, zone transfer, spoofability score |
| Passive OSINT | Certificate Transparency logs, DoH DNS, ASN lookup — no direct target contact |
| Service Prober | Unauthenticated Redis/Mongo/ES/Docker/K8s/etcd probes, 33 admin paths |
| Takeover Detector | CT log subdomain discovery + 25 cloud provider CNAME fingerprints |
| Nuclei Integration | Wrapper for 13k+ community templates (CVE, tech, exposure, misconfig) — MIT license |
| Fusion Pipeline | Multi-sensor signal gate → deterministic agreement → AI adjudication → attack graph → 6-section report |
| Web Fingerprint | Favicon hash (Shodan-compatible mmh3), JS secrets, version markers, exposed files, default lander detection |
| AI Analysis | OpenAI / Anthropic / OpenRouter / Ollama / Gemini / Groq / Kimi / Qwen — token-streaming SSE |
| Reasoning Engine | Adaptive observe→reason→act loop with EvidenceGraph, hypothesis engine, confidence decay, provenance, scheduler, playbooks, change detection, active validation |
| Deep Probe | Per-service agent architecture: ScoutAgent (recon), ProbeAgent (targeted CVE checks), Coordinator, Sandbox |
| AI Investigation Agent | ReAct-style loop: after baseline sensors, the AI drives a curated, scope-gated, audited tool surface (~35 tools) to verify leads and build attack chains — with opt-in aggressive tools (crash probes, freeform proof, freeform exploit) for authorized targets |
| Verifier Engine | AI-driven CVE re-verification: designs raw-HTTP probe plans from CVE context, executes via stdlib sockets |
| Multi-Host Orchestration | Full scan pipeline per host → cross-host context and reachability matrix → attack chain discovery |
| AI Sensor Directors | LLM decides which sensors to prioritise based on open ports, tech stack, and CVEs |
| Authenticated SSH | Credentialed ssh subprocess reads real installed package versions (60+ product mappings) |
| Service Enum | Protocol-level attribute extraction (SSH KEX, SMBv1, RDP NLA, SNMP community, HTTP auth state) |
| Topology Mapper | Reverse DNS, IPv6, traceroute, ASN/org/country via ip-api.com |
| Reachability Prober | Post-compromise lateral movement matrix from subnet adjacency |
| Network Prober | Active subnet sweep (/24 private neighbours) with two-phase discovery (live sweep → full port scan) |
| Scan Diff | Change-over-time: diffs current scan against most recent prior JSON report per target |
| License Management | Commercial license system with key activation (stub for Stripe/Paddle/Lemon Squeezy) |
| Per-Org AI Config | Each org stores its own LLM credentials encrypted at rest via Fernet |
| OIDC / Clerk | Human logins via Clerk-issued session JWTs verified against public JWKS with auto-provisioning |
| PostgreSQL | Full multi-tenant persistence with auto-applied migrations (scan jobs, org settings, reasoning state, audit) |
| Fusion Benchmark | Offline benchmark against recorded HTTP cassettes; precision/recall/critical-recall/FP-reduction metrics |
There are exactly two ways to run NetLogic:
| Mode | Command | What it does |
|---|---|---|
| Web app | netlogic --gui | Starts FastAPI + serves the React SPA + in-process scan agent, auto-generates secrets, and opens the dashboard in your browser. This is the only way to run the web app. |
| CLI | netlogic <target> [flags] | One-shot terminal scan (no server), prints/writes the report. |
The product surface is the web app (React dashboard + FastAPI). The scan engine under src/ powers jobs started from the UI.
# One-time install
pip install -r requirements-api.txt
pip install -e .
# Run the web dashboard
netlogic --gui
# → Dashboard at http://localhost:8000, auto-generated secrets in ~/.netlogic/secrets.json
# (first run builds the dashboard automatically; requires Node.js)
# Or a one-shot CLI scan
netlogic scanme.nmap.org --full
netlogic [target] [flags]
The entry point is api.cli:main (defined in pyproject.toml), which delegates to netlogic.py:main(). All scan logic is in src/.
| Format | Example | Mode |
|---|---|---|
| Hostname | example.com | Single-host scan |
| IPv4 | 10.0.0.5 | Single-host scan |
| CIDR | 192.168.1.0/24 | CIDR sweep (scanner only, no fusion) |
| Comma-separated | target1,target2 | Multi-host orchestration (cross-host context) |
# Basic scan — 43 common ports + CVE correlation
netlogic example.com
# Full scan — all modules enabled
netlogic example.com --full
# Deep TLS + HTTP header audit
netlogic example.com --tls --headers
# Subdomain takeover detection
netlogic example.com --takeover
# Passive OSINT only
netlogic example.com --osint
# Technology stack + WAF fingerprinting
netlogic example.com --stack
# DNS/email security (SPF, DKIM, DMARC, DNSSEC)
netlogic example.com --dns
# Active service probing (unauthenticated access, default creds, CVE-specific checks)
netlogic 10.0.0.5 --probe
# Everything — all flags combined
netlogic example.com --full --probe
# Quick — 43 common ports (default)
netlogic example.com --ports quick
# Full — 58 extended ports
netlogic example.com --ports full
# Custom list
netlogic example.com --ports custom=22,80,443,8080,9200
# OpenRouter (default)
netlogic example.com --ai --ai-key $KEY
# OpenAI
netlogic example.com --ai --ai-provider openai --ai-key $KEY --ai-model gpt-4o-mini
# Anthropic
netlogic example.com --ai --ai-provider anthropic --ai-key $KEY
# Gemini
netlogic example.com --ai --ai-provider gemini --ai-key $KEY --ai-model gemini-2.0-flash
# Local Ollama
netlogic example.com --ai --ai-provider ollama
# Custom OpenAI-compatible endpoint
netlogic example.com --ai --ai-provider custom --ai-base-url https://... --ai-model model-name
| Provider | Default model | API style |
|---|---|---|
openrouter | anthropic/claude-sonnet-4 | OpenAI |
openai | gpt-4o-mini | OpenAI |
anthropic | claude-3-5-sonnet-20241022 | Anthropic Messages |
kimi (Moonshot) | kimi-k2.6 | OpenAI |
qwen (Alibaba) | qwen-plus | OpenAI |
groq | llama-3.3-70b-versatile | OpenAI |
gemini (Google) | gemini-2.0-flash | OpenAI |
ollama | llama3 | OpenAI |
custom | user-specified | OpenAI |