NetEcho is security auditing and day-to-day network management on one dashboard. Below is the complete feature set, organized by category — auditing, config change tracking, device polling, remote access, automation, and the platform-level security it all runs on.
The categories below cover everything. These five are what a working day on NetEcho actually looks like.
A live, per-member operations dashboard built around one thing: the member's actual network topology, on screen, colored by real-time device status. Auto-refreshes every 15 seconds — this is the screen you leave open, not a report you pull up when something breaks.
Not a pass/fail checklist — every finding in the report explains itself, in a document you can actually hand to a customer.
Standalone topology discovery, separate from any single audit run — scans a member's live devices over SSH and builds the map from what's actually there.
Every polled interface gets its own utilization and throughput history — not just a current-state number.
Two dedicated tools for finding one thing across an entire fleet, instead of opening devices one at a time.
The same checks a real external assessment runs, so nothing in it surprises you when a customer's actual compliance audit happens — run as part of a full audit, or entirely on its own.
Analyzes Cisco IOS/NX-OS, JunOS, Arista EOS, and other device configs for security misconfigurations, scores every member, and delivers customer-ready reports automatically.
Weighted across Critical, High, Medium, and Low severity — each device scored individually, then averaged into a member-wide score.
Re-run audits on a timer from one day up to twelve months, set globally or overridden per member.
Self-contained, logo-branded customer reports — download, email, or render straight to PDF.
A score-over-time chart on every customer report, with a plain-English improvement or decline summary.
Auto-discovered L3/BGP topology diagrams you can drag, rewire, and save — or import your own from another tool.
Dual-homed redundancy checks, live RIPE/RouteViews visibility, and a per-provider coverage matrix for every owned prefix.
Build your own line-item checks with AND/OR word conditions — no regex required.
Delegate port scans to an external server so audits from inside the network don't produce false positives.
BGP prefix utilization visualization plus address geocoding with an embedded map, cached after first lookup.
Every full audit includes the external attack-surface / port-scan results and IP address utilization alongside the security findings, or run the same scan on its own — see below.
The same checks a real external assessment runs, so nothing in it surprises you when a customer's actual compliance audit happens. Runs as part of a full audit, or entirely on its own via a dedicated Run Pen Test report.
Management, database, file-sharing, industrial, and ISP/CPE-specific ports — MikroTik, TR-069/CWMP, and more — scanned against every public interface IP.
Live probes for NTP monlist, open DNS resolvers, memcached, SSDP, CLDAP, and chargen — the exact protocols abused in real-world reflection attacks.
Checks for well-known default community strings responding, not just whether the port is open.
Flags BGP reachable from the internet outright — something that should never happen for an ISP.
Attempts a short list of well-known logins against exposed SSH and HTTP management interfaces — off by default, gated behind an explicit warning and required acceptance step.
Zone transfer (AXFR), DNSSEC presence, and SPF/DMARC/DKIM mail-authentication records, checked against a supplied domain.
A dedicated scan and report, independent of a full audit — no config-compliance noise, just the external-facing findings.
Self-contained pen-test report, exportable the same way as a full audit report — download, email, or render straight to PDF.
A working NCCM system: every device config is version-controlled with full history, diffing, and an approval workflow — with noise filtered out automatically so real changes never get lost in false positives.
A background watcher hashes every device config every 30 seconds and snapshots anything that changed.
Diff any change against the approved baseline, or pick any two versions and compare them directly.
Mark a change as the new baseline that future diffs are measured against, one at a time or in bulk.
Weekly, bi-weekly, or monthly email of every unapproved change and its actual diff content — not just a device list.
Vendor save-banners, cosmetic formatting flips, and masked secrets are automatically excluded so they never trigger a false "changed" alert.
A drastically different or blank capture is automatically re-verified before it's ever recorded as a real change.
Grep-style search across every device's config, scoped to a member or, for admins, the whole fleet at once.
A dedicated syslog search tool — filter every device's logs by severity, device, and time range, or search message text directly.
Non-admin users see change history for their own assigned sites, with independent alert emails and schedules.
Inventories and pulls configs from devices directly — over SNMP, SSH, or a scheduled SFTP sync from a remote server — with broad support for older hardware.
Cisco IOS/NX-OS, Juniper JunOS, Arista EOS, Dell/Force10, FS.COM, and Nokia SR OS, with vendor and version detection.
Pull a members folder from a remote server on a schedule via SFTP, with SSH-key, password, or PuTTY .ppk auth.
Add many devices at once from a CSV or XLSX spreadsheet, with a per-row success/failure report.
Connects to older gear modern SSH libraries dropped by default — restoring support instead of failing outright.
Route every SSH connection, SNMP poll, and terminal session through one configured jump server, globally or per member. The jumpbox itself needs nothing installed — just SSH access and a network path to the managed devices.
Caps how many SSH sessions can be open through the jumpbox at once; every sweep and bulk tool scales its own parallelism to that number automatically, and it's raisable once the jumpbox is confirmed to sustain more.
For gear with SSH disabled entirely — config pull, terminal, and automation all fall back to Telnet per credential.
Polls up to 5 devices at once with a live time-remaining estimate, instead of sweeping the fleet one device at a time.
Pulls license status and expiration per device from its own dedicated SSH session and schedule.
Every device's live interfaces, status, and utilization in one place, without opening a terminal to check.
A real interactive shell to any device, straight from its page in the browser — no PuTTY or terminal app required.
Connects and authenticates with the device's saved credentials, auto-entering enable mode automatically.
Every session's complete transcript is recorded with passwords redacted, reviewable per device, per member, or platform-wide.
Lock a limited or tenant account to read-only show commands — everything else is refused before it reaches the device.
A pop-out, multi-pane terminal to your own admin-defined infrastructure, with SFTP file browsing, scrollback search, and session logs.
Ping, traceroute, path monitoring, and a couple of everyday network-admin utilities — runnable from this server, a global jumpbox, or a member's own jumpbox.
Run any number of simultaneous tests, each with a live RTT graph and loss percentage.
ICMP-mode path tracing for reliable results against destinations that ignore classic UDP traceroute.
A PingPlotter-style view that continuously pings every hop along a route, color-coded by loss and latency.
Run any of the above against an already-polled device or an identified eBGP peer without typing an IP by hand.
Builds an ISC dhcpd.conf subnet snippet from a network, range, and gateway — optionally scoped to a shared network.
Builds BIND-style zone records — A, AAAA, CNAME, MX, TXT, NS, PTR, and SRV — manually or in bulk from an uploaded spreadsheet.
Scripted config changes across one device or an entire fleet, with a dry-run preview and pass/fail verification on every push.
A simple WAIT / SEND line-based script drives the session exactly as written — enable prompts, conf t, and beyond.
See exactly which devices are eligible and the resolved, secret-masked command sequence before anything sends for real.
Pulls the running-config before and after the script and shows a side-by-side diff, so a "pass" always comes with proof.
Push to up to 10 devices at once instead of one at a time, for large batches.
Real-time per-device log streamed to the browser, with an abort button that stops before the next device.
Recurring unattended pushes with an optional completion-summary email so a bad run doesn't go unnoticed.
Reusable, rotatable SSH credential sets — set once, link to any number of devices.
Save a username/password/enable-password once and link it across every device that uses it.
Rotating a password on the credential set updates every linked device immediately.
An optional scripted WAIT/SEND sequence (like the Cisco enable-mode dance) runs automatically before every push.
Download every device and its credential — including passwords — as an offline password reference.
Cross-references every polled device's platform and version against the National Vulnerability Database.
Cross-references each device's detected platform and version against the National Vulnerability Database — covering Cisco IOS/IOS-XE/NX-OS, Juniper JunOS, and Arista EOS.
Every CVE found across a member's fleet, sorted by severity with CVSS score and a link to the full NVD advisory.
Check a single device right now, or scan every device on a member at once with a live progress bar.
A CVE finding is purely informational — it never moves a member's audit score.
Score alerts, health reports, and a full multi-tenant model for handing each customer their own scoped view.
Score-drop notifications with a global default and per-member override, firing the moment a threshold is breached.
Tracks every device's reachability continuously, with a configurable grace period before it's marked down (and alerted) or recovered — this is what drives the Ops Center map's live status.
Full network summary, sorted best to worst score, delivered on a schedule.
Assign specific members to non-admin users, each with independent alert emails and report schedules.
Four independent toggles control whether a tenant can see audits, change history, devices, or config files.
Record how a member wants changes handled — view-only, contact before any change, or a Method of Procedure required — flagged before the terminal even opens.
Upload a member's own change-management documentation and surface it right on the dashboard.
Route device-down and threshold alerts straight into PagerDuty alongside email, so live monitoring plugs into an on-call rotation you already run.
Self-hosted on your own infrastructure, hardened by default, with no phone-home telemetry.
Opt-in TOTP with any authenticator app, plus one-time recovery codes downloadable as a PDF.
A one-hour, single-use reset link by email — never reveals whether an account exists, never resets 2FA.
Device credentials and 2FA secrets are encrypted in the database with a key stored outside it.
Per-session CSRF tokens app-wide, Secure/HttpOnly/SameSite cookies, and full security response headers.
Trust-on-first-use pinning for every device connection — rejects it outright if a key ever changes.
The only outbound call the app ever makes is an optional, user-triggered CVE lookup — no telemetry, ever.
Upload a new release in Settings to upgrade in place, with an automatic pre-upgrade backup.
The installer never requires the service itself to run as root, on Linux with systemd support.
The live demo uses the same build your customers would run — no cut-down trial, nothing staged.