NEWFleet Operations: audit, search and safely change 1,000 devices at once

Every weakness in your running-config, found in seconds.

Paste a Cisco show running-config. SHOWRUN-PRO reads it like a senior engineer, flags what an attacker would find first, and maps every issue to NIST SP 800-53, ISO 27001, ITIL and real Cisco CVEs. One device, or every device in the data center.

0+
built-in security checks
0
curated Cisco CVEs, platform-aware
0
frameworks mapped per finding, plus CVEs
0
devices collected and analyzed in one job
0%
self-hosted: configs stay on your network
Live analysis

Watch a real ASA get audited

This is the actual output for the ASA sample config that ships with the product: the same findings, mappings and score you get when you click Load Sample ASA.

EDGE-ASA-01 — show running-config
100
SCANNING
0critical
0high
0medium
0passing
Parsing 3 interfaces, objects, NAT, ACLs, MPF, IKEv2 proposals, crypto maps, tunnel-groups…

Highlighted: 12 of the 30 checks run on this config. Final score and counts are the real totals.

From discovery to change

One workflow, end to end

Find every device, pull its config, score it, keep watching it, and fix what you found. No spreadsheets, no copy-paste between tools.

Discover

SNMP subnet sweep plus CDP/LLDP neighbor crawl maps devices without a full IP list.

Professional

Pull

SSH in and retrieve show running-config, handling paging, enable mode and prompts.

Professional

Analyze

35+ checks, a 0–100 score with a letter grade, and framework mapping for every finding.

All tiers

Monitor

Scheduled pulls diff each config against the last copy and re-score it automatically.

Enterprise

Alert

Drift or an unreachable device fires a webhook, an email, a PagerDuty incident or a Jira issue.

Enterprise

Change

Push the fix to every affected device: approved, canary first, verified, and saved only when proven.

Fleet add-on
What's inside

Built by a network engineer,
for network engineers

Every check knows the platform it runs on. An IOS-only rule never fires on a firewall, and a firewall-only CVE never lands on a router.

Deep Cisco ASA analysis

Real ASA parsing, not a reskinned IOS parser: nameif and security levels, objects and NAT, named ACLs with access-group bindings, management access, tunnel-groups and group-policies.

MPF: class-map / policy-map type inspect
Global service-policy activation
IKEv2 ipsec-proposal strength
Flat & indented crypto-map styles
DPD / keepalive on site-to-site peers
Split-tunnel and PSK remote access

Fleet dashboard

Roll any set of devices into one view. Worst devices first, and the findings that hit the most boxes surface as one row.

Enterprise

Drift monitoring & alerting

Point a schedule at a device once. Every change, or a device that stops answering, alerts the channels you pick per schedule. Credentials are encrypted at rest with your installation's own key.

Webhook · Slack / Teams / DiscordEmail · your SMTPPagerDuty Events v2Jira issues
Professional

Gate your CI/CD pipeline

Personal API tokens plus a ready-made gate script. Fail the build when a config change drops the score or adds a critical finding.

$ export SHOWRUN_URL=https://showrun.internal SHOWRUN_TOKEN=<token> $ python tools/ci_check.py edge-asa-01.cfg --min-score 80 SHOWRUN-PRO analysis: edge-asa-01.cfg Score: 55% (grade D) Critical: 3 | High: 4 | Medium: 6 | Low: 2 FAIL: score 55% is below the 80% threshold, or critical/high findings are present.
Enterprise

Your golden config

Add your own rules on top of the built-ins: a required NTP server, a banned VLAN, a hostname convention. Violations score like any finding.

Topology & config diff

An auto-drawn interface map for every device, and a line-by-line diff between any two configs.

Reports people read

PDF and Word reports for auditors, JSON and CSV for your tooling. Every finding comes with a suggested fix, most as ready-to-paste CLI.

RBAC & audit trail

Admin, Security Analyst and Read-Only roles. Every security-relevant admin action is logged with who, when and what changed. Credentials are never logged.

Runs where your configs live

Docker, plain Python or a Windows executable. No cloud upload and no agent: your configs are analyzed on your own server.

Platform coverage

Honest about what it covers

A report that looks complete but isn't is worse than no report. So every platform is labelled with its real coverage level.

Fleet Operations add-on

From one config to the whole data center

Collect, store, search and compare every device you run, and push changes to them the way a careful engineer would: a few first, then the rest, and never saved until proven.

300 devices0 / 300
Scroll here to watch a collection and a rollout.
What a change goes through
  1. A guard reads every line. reload, erase and write are never sent. Lines that can cut your access need a second look.
  2. A second administrator approves. Approval freezes the lines and the exact device list.
  3. One canary per platform goes first. Then it waits for you.
  4. A second login proves you still have access. If not, the change is undone through the session that is still open.
  5. Saved only after it is verified. Until then a reload brings the device back.
1,000

devices collected and analyzed in about a minute, 50 SSH sessions at a time, in a simulated-farm test

5

failed logins, not 1,000, when a service-account password is wrong. Then the job stops using it

0

false "config changed" alerts from timestamps that devices rewrite on every show run

AES-256

encryption of stored configs and device logins, with a key only your server holds. Not even the vendor can read them

Search every config

Which devices still have transport input telnet? Which have no logging host? Answered across the fleet in about a second.

Before and after

Every version of every device, side by side, with the findings a change introduced or resolved and what it did to the score.

Scheduled collection

Collect a site every night and get one alert listing the devices whose configuration changed, by webhook, email, PagerDuty or Jira.

Read-only if you want it to be: one setting makes an installation unable to change devices at all. Tested against a simulated SSH device farm and PostgreSQL; a bundled check tool lets you prove it on your own hardware before the first full run. IOS-XR is not supported for changes.

Compliance mapping

One finding. Every framework.

Each issue arrives already mapped, so the audit evidence writes itself. Pick a finding to see exactly what it maps to.

Deploy

Running in under five minutes

No default password is shipped: first start prints a one-time admin password, and you set your own before anything else.

Recommended

Docker

Production image with multiple workers and a persistent data volume.

$ docker compose up -d --build
Anywhere Python runs

Local Python

Two commands on Linux, macOS or Windows.

$ pip install -r requirements.txt $ python app.py
No install

Windows executable

Double-click SHOWRUN-PRO.exe. Data is kept next to the executable, and license keys are bound to that machine.

SHOWRUN-PRO.exe + show_machine_id · backup_restore · ci_check · field_check
Pricing

Start free. Scale when it matters.

Free
$0

For an engineer checking a device or two.

  • Analyze any supported config
  • Full findings & compliance score
  • Interactive topology map
  • Load the IOS & ASA samples
Start free
MOST POPULAR Professional
Contact us/ user / month

For analysts who report to auditors and manage many devices.

  • Everything in Free
  • PDF, Word, JSON & CSV exports
  • NIST SP 800-53 & CVE mapping
  • Config diff & analysis history
  • Network discovery & SSH config pull
  • Fleet dashboard
  • API tokens for CI/CD
Get Professional →
Enterprise
Contact us

For teams that need continuous assurance.

  • Everything in Professional
  • Scheduled drift monitoring
  • Webhook, email, PagerDuty & Jira alerts
  • Custom policy profiles
  • Live CVE & NIST feed updates
  • User & license management
Talk to us
Add-on · Professional or Enterprise

Fleet Operations

Inventory, encrypted config store, bulk collection, fleet-wide search, version compare, scheduled collection and guarded configuration push. Licensed by the number of devices in your inventory, so you pay for the network you have.

Get a quote for your device count →
FAQ

Questions engineers ask

Has it been tested on real Cisco hardware?

The analyzer is built from real configurations. The fleet engine is tested against a simulated farm of 1,000 SSH devices and on SQLite and PostgreSQL, not yet against every hardware and software train. That is why it ships with a field-check tool: point it at a few of your own devices and it reports, read-only, whether collection, analysis and change detection behave correctly on your software before you run the whole fleet.

Do my configs leave my network?

No. SHOWRUN-PRO is self-hosted and analyzes configs on your own server. It only reaches out when you ask it to: refreshing the CVE database from NVD, updating NIST control metadata, or sending the alerts you configured.

Can it fully audit Firepower Threat Defense?

Not from CLI output, and no tool can. FTD's real security policy (Access Control, Intrusion, SSL decryption) lives in FMC or FDM, not in show running-config. SHOWRUN-PRO analyzes the dataplane layer that is in the CLI, and every FTD report opens with a clear partial-coverage notice, on screen and in PDF and Word exports.

Where do the CVE matches come from?

A curated set of 20 real Cisco CVEs, taken from the official CVE records with CVSS scores from NVD or Cisco. Each is tied to the config weakness that exposes you and to the platforms it actually affects. On Enterprise you can refresh the database live from NVD.

Which NIST revision is used?

NIST SP 800-53 Revision 5. The control table comes from NIST's official machine-readable catalog, and every finding is mapped to specific control IDs. Refreshing control metadata never rewrites the finding-to-control mapping; a person decides that.

Can SHOWRUN-PRO change my devices?

Only with the Fleet Operations add-on, only by an administrator, and only through a change that a second administrator approved. A change goes to a canary device per platform first, a second login proves it did not cut off access, and nothing is saved to startup-config until it is verified. If you want a guarantee instead, one setting makes the installation read-only towards devices.

Who can read the configs it stores?

Stored configs, findings and device logins are encrypted with a key generated on your server. It is separate from your license, so the vendor does not have it. A copied database or backup is unreadable without that key, which is why you back the key up separately.

How does licensing work?

Keys are signed and bound to the installation they were issued for, so a key can't be copied to a second server. If a key fails verification, the app safely falls back to the Free tier with a visible warning.

Can I back up and move an installation?

Yes. The backup tool exports users, schedules, custom policies, alert settings, API tokens and the audit log. Signing secrets and the license stay behind on purpose, because they are tied to the original machine, and the encryption key is left out unless you ask for it, so a backup alone cannot be read.

Your first audit is one paste away

Know what's in your configs before an attacker does.

$ docker compose up -d --build ✓ SHOWRUN-PRO running on http://localhost:5000