CLI documentation
Everything you need to install, configure, and run the open-source deadband CLI.
Cloud product docs live inside the dashboard at app.deadband.org.
Installation
deadband compiles to a single static binary with no CGO dependencies. Requires Go 1.25+ and Make.
$ git clone https://github.com/jmeltz/deadband.git
$ cd deadband
# CLI only
$ make deadband
# CLI + embedded web UI
$ make deadband-web
# Output: ./bin/deadbandQuick Start
1. Fetch the advisory database
$ ./bin/deadband --update
[OK] Fetched 3,647 advisories from CISA CSAF (512 vendors)2. Discover devices on your network
$ ./bin/deadband --cidr 10.0.1.0/243. Check an inventory for vulnerabilities
$ ./bin/deadband -i devices.csv --min-cvss 7.0 --out-format json -o report.jsonCLI Reference
| Flag | Default | Description |
|---|---|---|
| --inventory, -i | (required) | Device inventory file (CSV, JSON, or flat text) |
| --format | auto | Input format: csv, json, flat |
| --db | ~/.deadband/advisories.json | Advisory database path |
| --output, -o | stdout | Output file path |
| --out-format | text | Output format: text, csv, json, html, sarif |
| --min-confidence | low | Minimum confidence: low, medium, high |
| --min-cvss | 0.0 | Minimum CVSS v3 score filter |
| --vendor | (all) | Filter results to a specific vendor |
| --cidr | CIDR range to scan for devices | |
| --mode | auto | Discovery protocol: auto, cip, s7, modbus, melsec, bacnet, fins, srtp, opcua |
| --timeout | 2s | Per-host TCP/UDP scan timeout |
| --http-timeout | 5s | HTTP scrape timeout |
| --concurrency | 50 | Number of concurrent scan workers |
| --dry-run | false | Parse inventory only, emit counts |
| --update | false | Fetch latest advisories from CISA |
| --stats | false | Show advisory database metadata |
| --compare | Second inventory file for diff mode | |
| --prioritize | false | Sort results by composite risk score (KEV + EPSS) |
| --compliance | Compliance frameworks: iec62443, nist-csf, nerc-cip, all | |
| --save-baseline | false | Save device inventory as baseline after scan |
| --compare-baseline | false | Compare against saved baseline for drift detection |
| --baseline | ~/.deadband/baseline.json | Custom baseline file path |
Discovery Modes
Use --mode to select which protocol(s) to scan. The default auto mode scans all 8 protocols simultaneously.
$ deadband --cidr 10.0.1.0/24 # auto (all protocols)
$ deadband --cidr 10.0.1.0/24 --mode cip # CIP/EIP (Rockwell)
$ deadband --cidr 10.0.1.0/24 --mode s7 # S7comm (Siemens)
$ deadband --cidr 10.0.1.0/24 --mode modbus # Modbus TCP
$ deadband --cidr 10.0.1.0/24 --mode melsec # MELSEC/SLMP (Mitsubishi)
$ deadband --cidr 10.0.1.0/24 --mode bacnet # BACnet/IP
$ deadband --cidr 10.0.1.0/24 --mode fins # Omron FINS
$ deadband --cidr 10.0.1.0/24 --mode srtp # GE-SRTP
$ deadband --cidr 10.0.1.0/24 --mode opcua # OPC UA (IEC 62541)PCAP Analysis
Analyze packet captures from SPAN ports or network taps without sending any traffic. deadband extracts device identities from ICS protocol responses in the capture file.
# Analyze a pcap file for ICS devices
$ deadband pcap capture.pcap
# Analyze and check for vulnerabilities
$ deadband pcap capture.pcap --min-cvss 7.0 --out-format html -o report.htmlSupported protocols in pcap: CIP/EIP, S7comm, Modbus TCP, MELSEC/SLMP, BACnet/IP, FINS, and GE-SRTP. Reads standard pcap format (not pcapng). Pure Go — no libpcap dependency.
Input Formats
deadband accepts device inventories in three formats. The format is auto-detected by default, or you can specify it with --format.
CSV
Matches the rockwell-discover output schema. Columns: Scanned IP, Device Name, MAC, IP Address, Product Revision, Serial Number, Status, Uptime.
Scanned IP,Device Name,MAC,IP Address,Product Revision,Serial Number,Status,Uptime
10.0.1.10,1756-L83E/B,00:1D:9C:xx:xx:xx,10.0.1.10,33.011,ABC123,Online,45dJSON
Matches the rockwell-discover --format json output.
[
{
"ip": "10.0.1.10",
"name": "1756-L83E/B",
"vendor": "Rockwell Automation",
"firmware": "33.011"
}
]Flat Text
Manual format: IP,vendor,model,firmware per line.
10.0.1.10,Rockwell Automation,1756-L83E/B,33.011
10.0.1.22,Siemens,S7-1500,2.9.4Output Formats
# Human-readable text (default)
$ deadband -i devices.csv
# CSV for spreadsheet analysis
$ deadband -i devices.csv --out-format csv -o report.csv
# JSON for programmatic use
$ deadband -i devices.csv --out-format json -o report.json
# HTML report for management and auditors
$ deadband -i devices.csv --out-format html --compliance all -o report.html
# SARIF for GitHub/GitLab security integration
$ deadband -i devices.csv --out-format sarif -o results.sarifCompliance Mapping
Map findings to IEC 62443, NIST CSF 2.0, and NERC CIP controls. Compliance mappings are included in HTML and JSON output when the --compliance flag is set.
# Include all frameworks in HTML report
$ deadband -i devices.csv --compliance all --out-format html -o report.html
# Include specific frameworks
$ deadband -i devices.csv --compliance iec62443,nist-csf --out-format json -o report.json
# Available frameworks: iec62443, nist-csf, nerc-cip, allDevice Baseline
Save a snapshot of your device inventory and detect drift between scans. Useful for change management and NERC CIP-010 compliance.
# Establish a baseline from your first scan
$ deadband --cidr 10.0.1.0/24 --save-baseline
# Later: detect drift and update the baseline
$ deadband --cidr 10.0.1.0/24 --compare-baseline --save-baseline
# Use a custom baseline path
$ deadband --cidr 10.0.1.0/24 --save-baseline --baseline /path/to/baseline.jsonDefault baseline location: ~/.deadband/baseline.json. The drift report shows added, removed, and changed devices with vulnerability impact.
Inventory Diff
Compare two device inventory snapshots to identify newly introduced vulnerabilities after updates or reconfigurations.
$ deadband --inventory base.csv --compare updated.csv --out-format json -o diff.jsonAir-Gap Workflow
deadband requires internet only for the initial --update. After that, all checks run entirely offline using the locally cached advisory database.
# Step 1: On connected host, fetch latest advisories
$ deadband --update
# Step 2: Copy database to air-gapped host
$ scp ~/.deadband/advisories.json assessor@secured-host:~/.deadband/
# Step 3: Run assessment offline
$ ssh assessor@secured-host
$ deadband -i /tmp/devices.csv --min-cvss 7.0Web UI
Build with make deadband-web to embed the Next.js frontend. The web UI provides a dashboard, advisory browser, vulnerability checker, network scanner, inventory diff viewer, and database management — all served from the single binary.
# Build with embedded frontend
$ make deadband-web
# Start the server
$ ./bin/deadband serve
Listening on :8484
# For development (hot reload)
$ go run ./cmd/deadband serve # Terminal 1: API server
$ cd web && npm run dev # Terminal 2: Next.js devExit Codes
| Code | Meaning | Use Case |
|---|---|---|
| 0 | No vulnerabilities found | CI gate passes |
| 1 | Vulnerabilities found | CI gate fails, report generated |
| 2 | Error | Missing DB, bad input file, etc. |
