deadband logodeadband

CLI documentation

Everything you need to install, configure, and run the open-source deadband CLI.

Cloud product docs live inside the dashboard at app.deadband.org.

Installation

deadband compiles to a single static binary with no CGO dependencies. Requires Go 1.25+ and Make.

terminal
$ git clone https://github.com/jmeltz/deadband.git
$ cd deadband

# CLI only
$ make deadband

# CLI + embedded web UI
$ make deadband-web

# Output: ./bin/deadband

Quick Start

1. Fetch the advisory database

$ ./bin/deadband --update
[OK] Fetched 3,647 advisories from CISA CSAF (512 vendors)

2. Discover devices on your network

$ ./bin/deadband --cidr 10.0.1.0/24

3. Check an inventory for vulnerabilities

$ ./bin/deadband -i devices.csv --min-cvss 7.0 --out-format json -o report.json

CLI Reference

FlagDefaultDescription
--inventory, -i(required)Device inventory file (CSV, JSON, or flat text)
--formatautoInput format: csv, json, flat
--db~/.deadband/advisories.jsonAdvisory database path
--output, -ostdoutOutput file path
--out-formattextOutput format: text, csv, json, html, sarif
--min-confidencelowMinimum confidence: low, medium, high
--min-cvss0.0Minimum CVSS v3 score filter
--vendor(all)Filter results to a specific vendor
--cidrCIDR range to scan for devices
--modeautoDiscovery protocol: auto, cip, s7, modbus, melsec, bacnet, fins, srtp, opcua
--timeout2sPer-host TCP/UDP scan timeout
--http-timeout5sHTTP scrape timeout
--concurrency50Number of concurrent scan workers
--dry-runfalseParse inventory only, emit counts
--updatefalseFetch latest advisories from CISA
--statsfalseShow advisory database metadata
--compareSecond inventory file for diff mode
--prioritizefalseSort results by composite risk score (KEV + EPSS)
--complianceCompliance frameworks: iec62443, nist-csf, nerc-cip, all
--save-baselinefalseSave device inventory as baseline after scan
--compare-baselinefalseCompare against saved baseline for drift detection
--baseline~/.deadband/baseline.jsonCustom baseline file path

Discovery Modes

Use --mode to select which protocol(s) to scan. The default auto mode scans all 8 protocols simultaneously.

discovery modes
$ deadband --cidr 10.0.1.0/24                  # auto (all protocols)
$ deadband --cidr 10.0.1.0/24 --mode cip       # CIP/EIP (Rockwell)
$ deadband --cidr 10.0.1.0/24 --mode s7        # S7comm (Siemens)
$ deadband --cidr 10.0.1.0/24 --mode modbus    # Modbus TCP
$ deadband --cidr 10.0.1.0/24 --mode melsec    # MELSEC/SLMP (Mitsubishi)
$ deadband --cidr 10.0.1.0/24 --mode bacnet    # BACnet/IP
$ deadband --cidr 10.0.1.0/24 --mode fins      # Omron FINS
$ deadband --cidr 10.0.1.0/24 --mode srtp      # GE-SRTP
$ deadband --cidr 10.0.1.0/24 --mode opcua     # OPC UA (IEC 62541)

PCAP Analysis

Analyze packet captures from SPAN ports or network taps without sending any traffic. deadband extracts device identities from ICS protocol responses in the capture file.

terminal
# Analyze a pcap file for ICS devices
$ deadband pcap capture.pcap

# Analyze and check for vulnerabilities
$ deadband pcap capture.pcap --min-cvss 7.0 --out-format html -o report.html

Supported protocols in pcap: CIP/EIP, S7comm, Modbus TCP, MELSEC/SLMP, BACnet/IP, FINS, and GE-SRTP. Reads standard pcap format (not pcapng). Pure Go — no libpcap dependency.

Input Formats

deadband accepts device inventories in three formats. The format is auto-detected by default, or you can specify it with --format.

CSV

Matches the rockwell-discover output schema. Columns: Scanned IP, Device Name, MAC, IP Address, Product Revision, Serial Number, Status, Uptime.

devices.csv
Scanned IP,Device Name,MAC,IP Address,Product Revision,Serial Number,Status,Uptime
10.0.1.10,1756-L83E/B,00:1D:9C:xx:xx:xx,10.0.1.10,33.011,ABC123,Online,45d

JSON

Matches the rockwell-discover --format json output.

devices.json
[
  {
    "ip": "10.0.1.10",
    "name": "1756-L83E/B",
    "vendor": "Rockwell Automation",
    "firmware": "33.011"
  }
]

Flat Text

Manual format: IP,vendor,model,firmware per line.

devices.txt
10.0.1.10,Rockwell Automation,1756-L83E/B,33.011
10.0.1.22,Siemens,S7-1500,2.9.4

Output Formats

output examples
# Human-readable text (default)
$ deadband -i devices.csv

# CSV for spreadsheet analysis
$ deadband -i devices.csv --out-format csv -o report.csv

# JSON for programmatic use
$ deadband -i devices.csv --out-format json -o report.json

# HTML report for management and auditors
$ deadband -i devices.csv --out-format html --compliance all -o report.html

# SARIF for GitHub/GitLab security integration
$ deadband -i devices.csv --out-format sarif -o results.sarif

Compliance Mapping

Map findings to IEC 62443, NIST CSF 2.0, and NERC CIP controls. Compliance mappings are included in HTML and JSON output when the --compliance flag is set.

compliance examples
# Include all frameworks in HTML report
$ deadband -i devices.csv --compliance all --out-format html -o report.html

# Include specific frameworks
$ deadband -i devices.csv --compliance iec62443,nist-csf --out-format json -o report.json

# Available frameworks: iec62443, nist-csf, nerc-cip, all

Device Baseline

Save a snapshot of your device inventory and detect drift between scans. Useful for change management and NERC CIP-010 compliance.

baseline workflow
# Establish a baseline from your first scan
$ deadband --cidr 10.0.1.0/24 --save-baseline

# Later: detect drift and update the baseline
$ deadband --cidr 10.0.1.0/24 --compare-baseline --save-baseline

# Use a custom baseline path
$ deadband --cidr 10.0.1.0/24 --save-baseline --baseline /path/to/baseline.json

Default baseline location: ~/.deadband/baseline.json. The drift report shows added, removed, and changed devices with vulnerability impact.

Inventory Diff

Compare two device inventory snapshots to identify newly introduced vulnerabilities after updates or reconfigurations.

terminal
$ deadband --inventory base.csv --compare updated.csv --out-format json -o diff.json

Air-Gap Workflow

deadband requires internet only for the initial --update. After that, all checks run entirely offline using the locally cached advisory database.

air-gap deployment
# Step 1: On connected host, fetch latest advisories
$ deadband --update

# Step 2: Copy database to air-gapped host
$ scp ~/.deadband/advisories.json assessor@secured-host:~/.deadband/

# Step 3: Run assessment offline
$ ssh assessor@secured-host
$ deadband -i /tmp/devices.csv --min-cvss 7.0

Web UI

Build with make deadband-web to embed the Next.js frontend. The web UI provides a dashboard, advisory browser, vulnerability checker, network scanner, inventory diff viewer, and database management — all served from the single binary.

terminal
# Build with embedded frontend
$ make deadband-web

# Start the server
$ ./bin/deadband serve
Listening on :8484

# For development (hot reload)
$ go run ./cmd/deadband serve  # Terminal 1: API server
$ cd web && npm run dev         # Terminal 2: Next.js dev

Exit Codes

CodeMeaningUse Case
0No vulnerabilities foundCI gate passes
1Vulnerabilities foundCI gate fails, report generated
2ErrorMissing DB, bad input file, etc.