Security & privacy

Sec-Dashboard consolidates 52 security tools into a single local interface

A new self-hosted dashboard aggregates network recon, vulnerability scanning, and reporting tools for solo analysts without requiring cloud accounts.

Illustration of a secure local server monitoring dashboard
Illustration created for this article

Security analyst Sammi De Blas released Sec-Dashboard on October 8, 2026, a self-hosted tool designed to consolidate fifty-two distinct security utilities into one local web interface. The project targets solo analysts and small security operations centers that need to perform reconnaissance and vulnerability assessments without relying on scattered cloud services or manual data entry.

What happened

De Blas developed the application to solve the inefficiency of managing multiple browser tabs and copying output from various command-line tools into disjointed notes. The resulting platform runs entirely on the local loopback address, using a FastAPI backend and a vanilla JavaScript frontend contained within a single HTML file. This architecture ensures that no data leaves the machine, addressing privacy concerns and allowing operation in isolated or restricted network environments.

The dashboard organizes its capabilities into seven categories, including network reconnaissance, web security, vulnerability assessment, system audits, open-source intelligence, email security, and radio frequency hardware analysis. It features four scanning modes ranging from a quick one-minute check to a comprehensive seven-minute deep scan. Each mode chains specific tools together in phases, providing live updates via WebSocket connections as the analysis progresses.

Key details

  • The tool integrates 52 security utilities, with 13 specialized functions like hash checking and CVE search that do not require a specific target.
  • Scanning pipelines are configurable, with "fast," "deep," "full_depth," and "nuclear" modes that execute predefined sequences of tools.
  • Results are stored in a local SQLite database, enabling persistent history, search functionality, and comparison between different scan runs.
  • An AI layer named Jev classifies findings and generates plain-language explanations in Spanish using a local large language model that never accesses external URLs.
  • Export options include JSON, CSV, and PDF formats, with direct integration available for Splunk via REST API to index findings as queryable evidence.
  • The application supports offline analysis of WiFi packet captures and HackRF radio frequency files, ensuring sensitive artifacts remain on-premise.

Background

Self-hosted security tools are increasingly popular among professionals who manage their own infrastructure or work in regulated industries. These users often prefer local execution to maintain control over sensitive data and avoid the costs or compliance issues associated with third-party cloud platforms. Server-Side Request Forgery (SSRF) is a common vulnerability in such tools, where an attacker might trick the server into making requests to internal networks or cloud metadata endpoints. Proper validation of user inputs is critical to prevent these exploits.

SQLite is a lightweight, file-based database engine that requires minimal configuration. It is well-suited for single-user applications or local tools where concurrent write access from multiple instances is not required. By choosing SQLite over more complex database systems like PostgreSQL, developers can reduce deployment friction, though they sacrifice scalability for multi-user environments.

Why it matters

For teams running their own software, maintaining an up-to-date inventory of exposure surfaces is a foundational security task. Without accurate records of subdomains, DNS configurations, and TLS certificate status, detection systems cannot function effectively. Sec-Dashboard automates this inventory process, allowing analysts to quickly map their assets and identify changes over time. This historical context is vital for distinguishing between normal operational shifts and potential security incidents.

The ability to generate reports directly from scan data saves significant administrative effort. Instead of manually compiling findings from various sources, users can export executive summaries or detailed technical reports in standard formats. This streamlines the workflow from discovery to remediation, ensuring that critical vulnerabilities are documented and communicated clearly to stakeholders without redundant manual work.

What you can do

  • Clone the repository from GitHub and set up a Python virtual environment to test the tool in a controlled local setting.
  • Review the backend/validators.py code to understand how the application prevents SSRF attacks by blocking private IP ranges and metadata endpoints.
  • Configure the scanning pipelines in backend/config.py to match your specific reconnaissance needs, adjusting the tools included in each phase.
  • Use the "fast" mode for routine daily checks on new domains and reserve the "nuclear" mode for in-depth investigations when anomalies are detected.
  • Integrate the Splunk export feature to centralize security findings, making them available for correlation with other log sources in your SIEM.
  • Audit your own deployment if you expose the dashboard remotely, ensuring you implement strong authentication layers such as API keys and access proxies.

More news

All news