NSAuditor AI EE 0.32.6 Update Enhances Network-Scan Detection Accuracy and Clarity
NSAuditor AI EE 0.32.6 Update Enhances Network-Scan Detection Accuracy and Clarity — NSAUDITOR AI EE 0.32.6 ENHANCEMENTS ADDRESS NETWORK-SCAN DETECTIONS In a
NSAuditor AI EE 0.32.6 Enhancements Address Network-Scan Detections
In a significant update, NSAuditor has released version 0.32.6 of its Enterprise Edition (EE), aimed at improving the accuracy of network-scan detections. This release addresses previously identified gaps in the detection of potential vulnerabilities, particularly in the realm of network security, without introducing new frameworks or plugins. The changes focus on enhancing the clarity of findings routed to the System and Organization Controls (SOC) 2 framework, specifically concerning Control Criteria (CC) sections 6.6 and 6.7.
Refined Cleartext Transport Assessment
One of the notable enhancements in this release pertains to the assessment of cleartext transport. Previously, the crypto agent assessed only the quality of encryption in scenarios where a TLS handshake was present. This meant that services that should be encrypted but lacked any TLS were given a clean bill of health, while services utilizing weak ciphers were flagged as problematic. The new version introduces a no-transport-encryption pathway that now correctly classifies these vulnerabilities under SOC 2 CC6.7. This adjustment enhances the accuracy of detection for services that fail to implement TLS effectively.
Additionally, the update ensures that servers using STARTTLS are not misclassified as false negatives. Furthermore, services that do not present identifiable fingerprints will now be judged based on open ports, enhancing the granularity of the detection process.
Independent SMB Risk Assessment
The update also introduces a crucial change to the detection of SMB (Server Message Block) vulnerabilities. In prior versions, the lateral movement rule mandated both SMB and RDP (Remote Desktop Protocol) to be open for a finding to be flagged. This led to the silencing of critical threats from SMB alone, particularly those akin to the EternalBlue exploit, which requires no RDP access for initial compromise.
In version 0.32.6, SMB alone is now recognized as a high-risk finding, subsequently routed to SOC 2 CC6.6. This adjustment acknowledges the significant risks associated with SMB exposure, allowing for a more proactive security posture. Notably, the MSRPC (Microsoft Remote Procedure Call) case on port 135 is not branded as EternalBlue, ensuring clarity in the reporting of findings.
New Vulnerability Exposures Introduced
The update also rectifies the absence of detection for four critical exposures that previously went unmonitored. These include:
- WinRM (Windows Remote Management) on ports 5985 and 5986
- Elasticsearch transport port 9300, with port 9200 already covered
- MSRPC on port 135
- An aggregate open-port-count rule
All four of these exposures are now properly routed to SOC 2 CC6.6, reinforcing the importance of comprehensive monitoring in network security assessments.
Validation and Future Developments
NSAuditor AI EE 0.32.6 has undergone rigorous validation, achieving a perfect score in unit suite tests (9012 passes, 0 failures, plus 24 additional tests) alongside a successful live network scan. It is crucial to note that cloud-scan prompts do not engage with these new features, focusing exclusively on network-scan capabilities.
While this release adds routing to SOC 2, it is important to clarify that cross-framework mappings—such as those relating to HIPAA 164.312(e)(1), CIS Controls 4.4/3.10/4.6, and NIST CSF PR.*—are deferred for a follow-up update. Customers should not confuse the routing enhancements with the introduction of new compliance frameworks.
Community Edition and Infrastructure Integrity
For users interested in leveraging these improvements, the Community Edition (CE) version 0.2.31 is available under the MIT license, providing free access to a robust network security tool. Both versions, EE and CE, are designed to run entirely on the user’s own infrastructure, ensuring zero data exfiltration and maintaining the integrity of sensitive information.
With NSAuditor AI EE 0.32.6, network security professionals can expect a more accurate assessment of their environments, enabling them to address potential vulnerabilities effectively and bolster their overall security posture.



