WHAT THIS TOOL DOES — it is a reference and audit instrument. It looks up the published
factory-default credentials for gear you tell it you operate, and cross-checks that list against assets you
already know are exposed, producing a "confirm this was changed" checklist. IT NEVER CONTACTS A DEVICE.
It sends no login attempts, tries no passwords, and touches nothing on your network. Verifying a default was
changed is a manual step you perform against equipment you own. Default-credential data for non-core vendors is
fetched live from cirt.net on demand and
shown with attribution — nothing is rehosted.
1
Inventory
what do you operate?
Paste an inventory, or load a CSV/JSON export from Tool 49 (Exposure Intelligence) or Tool 50
(Netblock Watch) — any file with vendor/product/IP columns. Rows carrying an IP are treated as
internet-exposed and rise to the top of the checklist.
2
Audit Checklist
0
Exposed w/ known default
0
To verify
0
Marked remediated
0
Vendors resolved
No audit run yet. Enter an inventory above and press Run Audit. Core CI/OT vendors resolve instantly, offline. Others are fetched live from cirt.net.