Deep Cisco ASA analysis
Real ASA parsing, not a reskinned IOS parser: nameif and security levels, objects and NAT, named ACLs with access-group bindings, management access, tunnel-groups and group-policies.
Paste a Cisco show running-config. SHOWRUN-PRO reads it like a senior engineer, flags what an attacker would find first, and maps every issue to NIST SP 800-53, ISO 27001, ITIL and real Cisco CVEs. One device, or every device in the data center.
This is the actual output for the ASA sample config that ships with the product: the same findings, mappings and score you get when you click Load Sample ASA.
Highlighted: 12 of the 30 checks run on this config. Final score and counts are the real totals.
Find every device, pull its config, score it, keep watching it, and fix what you found. No spreadsheets, no copy-paste between tools.
SNMP subnet sweep plus CDP/LLDP neighbor crawl maps devices without a full IP list.
ProfessionalSSH in and retrieve show running-config, handling paging, enable mode and prompts.
Professional35+ checks, a 0–100 score with a letter grade, and framework mapping for every finding.
All tiersScheduled pulls diff each config against the last copy and re-score it automatically.
EnterpriseDrift or an unreachable device fires a webhook, an email, a PagerDuty incident or a Jira issue.
EnterprisePush the fix to every affected device: approved, canary first, verified, and saved only when proven.
Fleet add-onEvery check knows the platform it runs on. An IOS-only rule never fires on a firewall, and a firewall-only CVE never lands on a router.
Real ASA parsing, not a reskinned IOS parser: nameif and security levels, objects and NAT, named ACLs with access-group bindings, management access, tunnel-groups and group-policies.
Roll any set of devices into one view. Worst devices first, and the findings that hit the most boxes surface as one row.
Point a schedule at a device once. Every change, or a device that stops answering, alerts the channels you pick per schedule. Credentials are encrypted at rest with your installation's own key.
Personal API tokens plus a ready-made gate script. Fail the build when a config change drops the score or adds a critical finding.
Add your own rules on top of the built-ins: a required NTP server, a banned VLAN, a hostname convention. Violations score like any finding.
An auto-drawn interface map for every device, and a line-by-line diff between any two configs.
PDF and Word reports for auditors, JSON and CSV for your tooling. Every finding comes with a suggested fix, most as ready-to-paste CLI.
Admin, Security Analyst and Read-Only roles. Every security-relevant admin action is logged with who, when and what changed. Credentials are never logged.
Docker, plain Python or a Windows executable. No cloud upload and no agent: your configs are analyzed on your own server.
A report that looks complete but isn't is worse than no report. So every platform is labelled with its real coverage level.
Collect, store, search and compare every device you run, and push changes to them the way a careful engineer would: a few first, then the rest, and never saved until proven.
devices collected and analyzed in about a minute, 50 SSH sessions at a time, in a simulated-farm test
failed logins, not 1,000, when a service-account password is wrong. Then the job stops using it
false "config changed" alerts from timestamps that devices rewrite on every show run
encryption of stored configs and device logins, with a key only your server holds. Not even the vendor can read them
Which devices still have transport input telnet? Which have no logging host? Answered across the fleet in about a second.
Every version of every device, side by side, with the findings a change introduced or resolved and what it did to the score.
Collect a site every night and get one alert listing the devices whose configuration changed, by webhook, email, PagerDuty or Jira.
Read-only if you want it to be: one setting makes an installation unable to change devices at all. Tested against a simulated SSH device farm and PostgreSQL; a bundled check tool lets you prove it on your own hardware before the first full run. IOS-XR is not supported for changes.
Each issue arrives already mapped, so the audit evidence writes itself. Pick a finding to see exactly what it maps to.
No default password is shipped: first start prints a one-time admin password, and you set your own before anything else.
Production image with multiple workers and a persistent data volume.
Two commands on Linux, macOS or Windows.
Double-click SHOWRUN-PRO.exe. Data is kept next to the executable, and license keys are bound to that machine.
For an engineer checking a device or two.
For analysts who report to auditors and manage many devices.
For teams that need continuous assurance.
Inventory, encrypted config store, bulk collection, fleet-wide search, version compare, scheduled collection and guarded configuration push. Licensed by the number of devices in your inventory, so you pay for the network you have.
The analyzer is built from real configurations. The fleet engine is tested against a simulated farm of 1,000 SSH devices and on SQLite and PostgreSQL, not yet against every hardware and software train. That is why it ships with a field-check tool: point it at a few of your own devices and it reports, read-only, whether collection, analysis and change detection behave correctly on your software before you run the whole fleet.
No. SHOWRUN-PRO is self-hosted and analyzes configs on your own server. It only reaches out when you ask it to: refreshing the CVE database from NVD, updating NIST control metadata, or sending the alerts you configured.
Not from CLI output, and no tool can. FTD's real security policy (Access Control, Intrusion, SSL decryption) lives in FMC or FDM, not in show running-config. SHOWRUN-PRO analyzes the dataplane layer that is in the CLI, and every FTD report opens with a clear partial-coverage notice, on screen and in PDF and Word exports.
A curated set of 20 real Cisco CVEs, taken from the official CVE records with CVSS scores from NVD or Cisco. Each is tied to the config weakness that exposes you and to the platforms it actually affects. On Enterprise you can refresh the database live from NVD.
NIST SP 800-53 Revision 5. The control table comes from NIST's official machine-readable catalog, and every finding is mapped to specific control IDs. Refreshing control metadata never rewrites the finding-to-control mapping; a person decides that.
Only with the Fleet Operations add-on, only by an administrator, and only through a change that a second administrator approved. A change goes to a canary device per platform first, a second login proves it did not cut off access, and nothing is saved to startup-config until it is verified. If you want a guarantee instead, one setting makes the installation read-only towards devices.
Stored configs, findings and device logins are encrypted with a key generated on your server. It is separate from your license, so the vendor does not have it. A copied database or backup is unreadable without that key, which is why you back the key up separately.
Keys are signed and bound to the installation they were issued for, so a key can't be copied to a second server. If a key fails verification, the app safely falls back to the Free tier with a visible warning.
Yes. The backup tool exports users, schedules, custom policies, alert settings, API tokens and the audit log. Signing secrets and the license stay behind on purpose, because they are tied to the original machine, and the encryption key is left out unless you ask for it, so a backup alone cannot be read.