Skip to content

Latest commit

Β 

History

12 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

Domain Security Console & Auditor

Live Demo Python Flask License: MIT

An enterprise-grade, high-performance Python Full-Stack web application that provides real-time threat intelligence, email authentication analysis, and external attack surface audits.

πŸš€ Live Deployment: https://domain-security-scanner.onrender.com/


Key Features

  • Email Spoofing Defense: Detailed analysis of SPF policies (-all, ~all), DMARC enforcement levels (reject, quarantine), and DKIM signature detection.
  • DNS & Routing Integrity: DNSSEC cryptographic chain verification and MX record route inspection.
  • Web & Transport Security: TLS/SSL certificate health, HTTPS redirection checks, and HTTP security headers (HSTS, CSP, X-Frame-Options).
  • External Attack Surface Audit: High-speed concurrent port scanning across 16 critical network services.
  • Multi-threaded Parallel Engine: Queries DNS, Web, and Ports concurrently via ThreadPoolExecutor (cutting scan duration from ~15s to < 2s).
  • Executive PDF Reporting: Automated server-side generation of styled PDF security assessment reports.
  • Interactive SOC Cyber UI: Responsive dark-mode dashboard with quick-test domain chips, real-time radar scan progression, remediation guides, and metric explanation modals.

Architecture Overview

Domain_Security_Scanner/
β”œβ”€β”€ backend/
β”‚   β”œβ”€β”€ app/
β”‚   β”‚   β”œβ”€β”€ __init__.py               # Flask Application Factory
β”‚   β”‚   β”œβ”€β”€ config.py                 # Central configuration
β”‚   β”‚   β”œβ”€β”€ routes/
β”‚   β”‚   β”‚   β”œβ”€β”€ web.py                # Web view blueprint (SSR / UI)
β”‚   β”‚   β”‚   └── api.py                # JSON REST API (/api/scan, /api/report/pdf)
β”‚   β”‚   β”œβ”€β”€ services/                 # Decoupled Domain Services
β”‚   β”‚   β”‚   β”œβ”€β”€ scanner_orchestrator.py # Concurrent multi-threaded task coordinator
β”‚   β”‚   β”‚   β”œβ”€β”€ dns_service.py        # MX, TXT, DMARC, DNSSEC lookups
β”‚   β”‚   β”‚   β”œβ”€β”€ email_security.py     # SPF/DMARC parsing & scoring algorithms
β”‚   β”‚   β”‚   β”œβ”€β”€ web_security.py       # HTTPS, SSL & HTTP security headers
β”‚   β”‚   β”‚   β”œβ”€β”€ port_scanner.py       # High-speed concurrent socket scanner
β”‚   β”‚   β”‚   └── report_service.py     # PDF report compilation & remediation logic
β”‚   β”‚   └── utils/
β”‚   β”‚       └── validators.py         # RFC domain sanitization and validation
β”‚   β”œβ”€β”€ tests/                        # Automated unit & integration tests
β”‚   β”‚   β”œβ”€β”€ test_validators.py
β”‚   β”‚   β”œβ”€β”€ test_email_security.py
β”‚   β”‚   └── test_api.py
β”‚   β”œβ”€β”€ dns_utils.py                  # Backward-compatibility facade
β”‚   └── app.py                        # Backend entrypoint
β”œβ”€β”€ frontend/
β”‚   β”œβ”€β”€ static/
β”‚   β”‚   β”œβ”€β”€ style.css                 # SOC cyber theme & animations
β”‚   β”‚   └── script.js                 # Async scan controller & UI interactivity
β”‚   └── templates/
β”‚       β”œβ”€β”€ index.html                # Main scanner & interactive dashboard
β”‚       └── report_pdf.html           # Print-optimized PDF template
β”œβ”€β”€ run.py                            # Project root launcher
β”œβ”€β”€ Procfile                          # Cloud process definition (Gunicorn)
β”œβ”€β”€ render.yaml                       # Render.com Blueprint deployment spec
β”œβ”€β”€ requirements.txt
└── README.md

Quick Start (Run Locally)

  1. Clone the repository:

    git clone https://github.com/Indraik/Domain_Security_Scanner.git
    cd Domain_Security_Scanner
  2. Install dependencies:

    pip install -r requirements.txt
  3. Run the application: You can start the app from the root or the backend folder:

    python run.py
    # or
    python backend/app.py
  4. Access the Console: Open your browser at:

    http://127.0.0.1:5000
    

Running Automated Tests

Execute the test suite to verify validators, scoring algorithms, and API endpoints:

python -m unittest discover -s backend/tests -p "test_*.py" -v

API Endpoints

  • GET / β€” Serves the interactive Security Console.
  • POST /api/scan β€” Accepts { "domain": "example.com" }, executes parallel scan, returns JSON payload.
  • POST /api/report/pdf β€” Accepts scan JSON data, compiles and streams a downloadable PDF report.

About

πŸ” Automated domain & network security scanner evaluating SPF/DMARC email posture, SSL/TLS certificates, HTTP security headers, and open ports with PDF reporting.

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages