Security evidence report
(unlicensed evaluation)
Generated 2026-08-24 10:57 by NetVane 1.2.0 · scope: 192.168.1.0/24, 192.168.2.0/24
· 5 active of 5 known devices
What this document is. Point-in-time evidence gathered by NetVane on the
network above: what was scanned, what was found, which risks were explicitly accepted and why,
and what was changed through NetVane's remediation with its audit trail. It supports an
assessment; it is not a certification, and it makes no claim of conformance with any
framework. A machine-readable copy of the same evidence, carrying the integrity hash below, is
available as the evidence pack export.
1. Method
| Policy / posture setting | Value |
|---|
| targets | ['192.168.1.0/24'] |
| default profile | standard |
| validation depth | safe |
| validation authorized | False |
| remediation enabled | True |
| scheduled scanning | False |
| schedule interval hours | 6.0 |
| behavior watch | True |
| flow collector | False |
| retention days | 180 |
2. Posture
Security score 67 (grade C).
| Assessed | Score |
|---|
| 2026-08-24 10:47 | 67 |
3. Findings register — 8 open
| Severity | Device | Endpoint | Category | Finding | Validation |
| high | fileserver.lan | 192.168.1.10:445 | Lock down Windows file-sharing (SMB/NetBIOS) | SMB file sharing (worm/ransomware target) | unverified |
| high | ws-eng-01.lan | 192.168.2.15:445 | Lock down Windows file-sharing (SMB/NetBIOS) | SMB file sharing (worm/ransomware target) | unverified |
| high | ws-eng-01.lan | 192.168.2.15:3389 | Put remote desktop behind a VPN | RDP remote desktop | unverified |
| medium | fileserver.lan | 192.168.1.10:3306 | Restrict database ports to the LAN | MySQL database | unverified |
| medium | ws-eng-01.lan | 192.168.2.15:135 | Keep Windows RPC off untrusted networks | MSRPC endpoint mapper | unverified |
| info | gateway.lan | 192.168.1.1:22 | Harden SSH if it's internet-reachable | SSH remote management | unverified |
| info | fileserver.lan | 192.168.1.10:22 | Harden SSH if it's internet-reachable | SSH remote management | unverified |
| info | printer.lan | 192.168.1.20:9100 | Keep printers on the LAN and patched | Printer raw/JetDirect | unverified |
4. Accepted-risk ledger — 0 entries
| Device | Endpoint | Accepted | Recorded reason | Current state |
| No accepted risks. |
5. Remediation activity — 0 events
| When | Action | Outcome |
|---|
| No remediation actions recorded. |
6. Inventory — 5 devices
| Device | IP | Vendor | Type | Status |
|---|
| gateway.lan | 192.168.1.1 | Ubiquiti | | new |
| fileserver.lan | 192.168.1.10 | Dell | | new |
| printer.lan | 192.168.1.20 | Hewlett Packard | | new |
| thermostat.lan | 192.168.1.30 | Espressif | | new |
| ws-eng-01.lan | 192.168.2.15 | Intel | | new |
Integrity
The matching evidence-pack JSON verifies against this hash (remove the
integrity block, re-serialize with sorted keys and no spaces, SHA-256):
5a940f6d643ded58b8c913e5e5a7c14cae1b222117e7cd319d79759a0b14644e