
Local web app for conducting a Check Point Trusted Access Review. This scanner is built specifically to look for configuration issues around CVE-2026-16232, CVE-2026-62144 , and CVE-2026-62145. This tool is not created or supported by Check Point and should be used at your own risk.
PLEASE ALWAYS APPLY VENDOR PATCHES AS QUICKLY AS POSSIBLE
Local web app for conducting a Check Point Trusted Access Review with trusted Check Point Management API commands. Most checks are review-only. Any available remediation action requires explicit operator approval.
This scanner is built specifically to look for configuration issues around CVE-2026-16232 (https://support.checkpoint.com/results/sk/sk185169), CVE-2026-62144 (https://support.checkpoint.com/results/sk/sk185152), and CVE-2026-62145 (https://support.checkpoint.com/results/sk/sk185153)
It will allow you scan and remediate uses of ANY as well as scan logs looking for potential bad actors.
This tool is not created or supported by Check Point and should be used at your own risk.
Prebuilt versions are available under dist/ for users who do not want to install Node.js, npm, Git, or the source code:
dist/windows-x64/ contains the standalone .exe and a matching ZIP.dist/macos-apple-silicon/ contains the distributable .app ZIP, extracted app, and standalone arm64 executable.The self-contained releases include the Node.js runtime, web interface, backend, and direct PDF report generator. They bind only to 127.0.0.1, prefer port 4000, automatically try 4001, 4002, and higher ports when needed, and open the selected local URL in the default browser.
For GitHub, publish the platform ZIPs—and optionally the Windows .exe—as GitHub Release assets. Users should not download node_modules or the source tree merely to run a self-contained release. See dist/README.md for the artifact layout.
The current app is aligned to the Check Point Gateway and Management Hardening Administration Guide.
This tool is not created or supported by Check Point and should be used at your own risk.
The app runs locally, logs in to a Check Point Security Management Server or MDS, scans available Management API evidence, and presents guide-aligned hardening checks. Most checks are review-only; specific remediation actions are offered only when explicitly implemented and require operator approval. Checks that require network design review, Gaia Portal, Gaia API, SSH/Clish, identity provider settings, or out-of-band management inspection are marked for manual validation.
The scanner currently covers these hardening-guide areas:
For MDS environments, enable MDS Scan on the login form. This exposes two fields that matter:
run-script checks against the box itself. This is required when the login host is the MDS IP but the selected API domain is a CMA/domain, because commands such as run-script must target the MDS object name, not the MDS IP or the CMA/domain IP.When MDS Scan is enabled, the app creates two Check Point Management API sessions:
run-script commands that target the Global MDS Object Name. This is necessary for checks that inspect the MDS server operating system itself, such as management server interface/default-route discovery, Gaia administrator settings, Gaia password policy, SNMP, and management server syslog forwarding.In mgmt_cli terms, the domain checks behave like commands that include --domain "<Domain>", while MDS host checks behave like mgmt_cli -r true run-script targets.1 "<Global MDS Object Name>" ... executed in the global MDS context.
Some MDS checks intentionally evaluate more than one management plane. For example, Restrict Administrative Source IP Addresses evaluates both the MDS/global management host IP and the selected Domain/CMA IP. For each IP, it attempts to resolve the matching object in the selected domain, checks network objects and address ranges containing the IP, follows groups containing those objects, and then collects access rules that reference them. If the matching domain rule is under a Global Policy parent layer, the app reads the Global access rulebase up to Placeholder for domain rules and includes those Global rules in the same Policy Package evidence table with a GLOBAL RULES marker.
For Smart-1 Cloud, enable Smart-1 Cloud context URL on the login form and enter the Management host with its context path, for example:
tenant-name.maas.checkpoint.com/context-id/web_api
The app preserves that path and sends API requests to:
https://tenant-name.maas.checkpoint.com/context-id/web_api/<command>
This matches the mgmt_cli Smart-1 Cloud context structure:
mgmt_cli -m tenant-name.maas.checkpoint.com --session-id <sid> --context context-id/web_api <cli_command>
When Smart-1 Cloud context URL is enabled, checks that require direct access to a customer-owned Management Server Gaia object are skipped. In practice, this removes the Management Plane Protection checks such as Protect Management Server Behind A Firewall and Restrict Administrative Source IP Addresses, because the management server is hosted by Check Point and does not exist as a normal customer-managed Gaia object in the tenant domain.
The scan summary shows the current scan time and the previous scan recorded by the local app, including the Management API username that ran it. This history is kept in memory and resets when the local Node process restarts.
The login form includes Large environment mode for MDS or large multi-gateway environments. This mode does not skip checks or change evidence collection. It lowers scan pressure against the Management API by throttling concurrent API requests and Gaia run-script tasks during a full scan.
Default standard scan behavior: