Skip to content

Feat/exposure explain - #17

Merged
NycolazSec merged 2 commits into
mainfrom
feat/exposure-explain
Oct 10, 2026
Merged

NycolazSec merged 2 commits into
mainfrom
feat/exposure-explain

Conversation

@NycolazSec

Copy link
Copy Markdown
Owner

Summary

Related issue

Checklist

  • I read CONTRIBUTING.md
  • gofmt -l . produces no output
  • go vet ./... passes
  • go test -race ./... passes
  • I added/updated tests for behavioral changes
  • I updated README.md/docs/ for user-facing changes
  • This change preserves the authorized-use guidance in NOTICE.md and does not add functionality whose primary purpose is unauthorized access, disruption, credential theft, persistence, or concealment of unlawful activity

Test plan

Any target containing "-" was sent to the IP range parser, so ordinary
host names such as my-server.example.com or tcpcat-dedicated failed with
"invalid range format" instead of being resolved. Only targets made of
digits, dots and a dash (10.0.0.1-20, 10.0.0.1-10.0.0.20) are now treated
as ranges; isHostname uses the same test so TLS SNI keeps the name.
`tcpcat inventory` (Linux, run on the host) lists every listening TCP
socket from /proc with its owner: process, systemd unit, Docker container
(docker-proxy attributed to the container publishing the port), Kubernetes
pod, plus NodePort/LoadBalancer Services. Secret-looking arguments are
redacted; nothing is sent on the network.

`tcpcat explain <inventory.json> <scan.json>` joins it with a scan taken
from outside and classifies each port:
- EXPOSED: reachable and owned by a local listener, with the owner and a
  concrete fix (Redis, PostgreSQL, MySQL/MariaDB, MongoDB, SSH, Docker,
  Node/Python/Java apps, ...)
- FORWARDED: reachable with no local listener for that address (DNAT,
  Docker/Kubernetes mapping, cloud load balancer); a matching Kubernetes
  Service takes precedence over a local listener on the same port, since
  external traffic is redirected before local delivery
- SHIELDED: listens on every interface but only the firewall blocks it
- LOCAL / UNTESTED

--expect declares intentionally public ports; exit 1 when anything else
is reachable, so it can gate CI. --target handles hosts behind 1:1 NAT.
@NycolazSec
NycolazSec merged commit fa0fdd1 into main Oct 10, 2026
4 checks passed
@github-actions github-actions Bot locked and limited conversation to collaborators Oct 10, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant