
A high-fidelity, read-only internal network security assessment toolkit for Linux and Windows infrastructure. Employs a zero-mutation, default-deny architecture to safely capture and structure risk telemetry without system modifications.
InfraPulse-Core is a unified, dual-platform security auditing architecture implementing single-file, zero-dependency engines for Linux (POSIX) and Windows (Win32).
Unlike traditional vulnerability scanners that rely on subjective risk metrics, InfraPulse-Core enforces an unyielding Evidence-Tuple Model, programmatically segregating static Configuration Evidence from Active Protocol Validation and Demonstrated Impact.
socket_gate / Test-TargetAllowed). This gate evaluates the operator-supplied scope against a default-deny policy before a socket is instantiated.InfraPulse-Core/
├── src/
│ ├── posix/
│ │ └── InfraPulse-LX.sh # Linux Native Bash Engine
│ └── win32/
│ └── InfraPulse-Win.bat # Windows Native Extraction/PowerShell Engine
├── LICENSE # MIT License terms
└── README.md # Main deployment guide
src/posix/InfraPulse-LX.sh)Ensure execution permissions are granted before deployment:
chmod +x InfraPulse-LX.sh
# Execute local hardening profile with absolute network containment
./InfraPulse-LX.sh --local-only
# Execute network discovery over tightly bounded, authorised CIDR limits
./InfraPulse-LX.sh --scope 10.10.20.0/24,!10.10.20.254
src/win32/InfraPulse-Win.bat)Run from an Elevated Command Prompt for maximum filesystem/LSA tracking accuracy.
:: Suppress outbound queries; audit loopback and local OS protections only
InfraPulse-Win.bat /localonly
:: Target a specific segment with an automated default-deny network stance
InfraPulse-Win.bat /scope:172.16.4.0/24,!172.16.4.10
The engine splits verification tasks across two discrete files dynamically dropped into the output directory:
*.csv): Formatted precisely to RFC4180 rules. Tracks entries using a 14-column layout mapping: Timestamp, Severity, Category, Source, Target, Port, Finding, Prerequisites, ConfigurationEvidence, ValidationMethod, ObservedResult, Exploitability, Impact, and Remediation.*.md): Generates an ordered, pipeline-style manual playbook. It provides the exact steps a human operator must perform to confirm or refute a vulnerability, along with a pre-calculated engineering blast radius for each check.