SAMPLE — generated from NetVane’s built-in demo network. No real network was scanned. About this sample · Run it on yours free

Security evidence report

(unlicensed evaluation)
Generated 2026-08-24 10:57 by NetVane 1.2.0 · scope: 192.168.1.0/24, 192.168.2.0/24 · 5 active of 5 known devices

What this document is. Point-in-time evidence gathered by NetVane on the network above: what was scanned, what was found, which risks were explicitly accepted and why, and what was changed through NetVane's remediation with its audit trail. It supports an assessment; it is not a certification, and it makes no claim of conformance with any framework. A machine-readable copy of the same evidence, carrying the integrity hash below, is available as the evidence pack export.

1. Method

Policy / posture settingValue
targets['192.168.1.0/24']
default profilestandard
validation depthsafe
validation authorizedFalse
remediation enabledTrue
scheduled scanningFalse
schedule interval hours6.0
behavior watchTrue
flow collectorFalse
retention days180

2. Posture

Security score 67 (grade C).

AssessedScore
2026-08-24 10:4767

3. Findings register — 8 open

SeverityDeviceEndpointCategoryFindingValidation
highfileserver.lan192.168.1.10:445Lock down Windows file-sharing (SMB/NetBIOS)SMB file sharing (worm/ransomware target)unverified
highws-eng-01.lan192.168.2.15:445Lock down Windows file-sharing (SMB/NetBIOS)SMB file sharing (worm/ransomware target)unverified
highws-eng-01.lan192.168.2.15:3389Put remote desktop behind a VPNRDP remote desktopunverified
mediumfileserver.lan192.168.1.10:3306Restrict database ports to the LANMySQL databaseunverified
mediumws-eng-01.lan192.168.2.15:135Keep Windows RPC off untrusted networksMSRPC endpoint mapperunverified
infogateway.lan192.168.1.1:22Harden SSH if it's internet-reachableSSH remote managementunverified
infofileserver.lan192.168.1.10:22Harden SSH if it's internet-reachableSSH remote managementunverified
infoprinter.lan192.168.1.20:9100Keep printers on the LAN and patchedPrinter raw/JetDirectunverified

4. Accepted-risk ledger — 0 entries

DeviceEndpointAcceptedRecorded reasonCurrent state
No accepted risks.

5. Remediation activity — 0 events

WhenActionOutcome
No remediation actions recorded.

6. Inventory — 5 devices

DeviceIPVendorTypeStatus
gateway.lan192.168.1.1Ubiquitinew
fileserver.lan192.168.1.10Dellnew
printer.lan192.168.1.20Hewlett Packardnew
thermostat.lan192.168.1.30Espressifnew
ws-eng-01.lan192.168.2.15Intelnew

Integrity

The matching evidence-pack JSON verifies against this hash (remove the integrity block, re-serialize with sorted keys and no spaces, SHA-256):

5a940f6d643ded58b8c913e5e5a7c14cae1b222117e7cd319d79759a0b14644e