Metadata-Version: 2.4
Name: cybersecure-easy
Version: 0.3.0
Summary: A beginner-friendly facade for common defensive security tasks
License: MIT
Requires-Python: >=3.10
Description-Content-Type: text/markdown
Provides-Extra: network
Requires-Dist: scapy>=2.5; extra == "network"
Requires-Dist: python-nmap>=0.7; extra == "network"
Provides-Extra: web
Requires-Dist: requests>=2.31; extra == "web"
Requires-Dist: beautifulsoup4>=4.12; extra == "web"
Provides-Extra: crypto
Requires-Dist: pycryptodome>=3.19; extra == "crypto"
Provides-Extra: yara
Requires-Dist: yara-python>=4.3; extra == "yara"
Provides-Extra: ml
Requires-Dist: scikit-learn>=1.3; extra == "ml"
Provides-Extra: dns
Requires-Dist: dnspython>=2.6; extra == "dns"
Requires-Dist: python-whois>=0.9; extra == "dns"
Provides-Extra: passwords
Requires-Dist: argon2-cffi>=23.1; extra == "passwords"
Provides-Extra: images
Requires-Dist: Pillow>=10; extra == "images"
Provides-Extra: all
Requires-Dist: scapy>=2.5; extra == "all"
Requires-Dist: python-nmap>=0.7; extra == "all"
Requires-Dist: requests>=2.31; extra == "all"
Requires-Dist: beautifulsoup4>=4.12; extra == "all"
Requires-Dist: pycryptodome>=3.19; extra == "all"
Requires-Dist: yara-python>=4.3; extra == "all"
Requires-Dist: scikit-learn>=1.3; extra == "all"
Requires-Dist: dnspython>=2.6; extra == "all"
Requires-Dist: python-whois>=0.9; extra == "all"
Requires-Dist: argon2-cffi>=23.1; extra == "all"
Requires-Dist: Pillow>=10; extra == "all"

# Cybersecure Easy

A small beginner-friendly Python facade for common defensive security operations.
It gives common tasks readable names while keeping their underlying tools visible.
It is a starter wrapper, not a replacement for learning the tools or a claim that one
library covers every item in a security stack.

## Install

From this folder:

```powershell
python -m pip install -e ".[network,web,crypto]"
```

Install all supported optional Python dependencies with `python -m pip install -e ".[all]"`.
Some tasks also need external tools: Nmap for `scan_ports`, Bandit for `audit_python`,
and Node.js/npm for `audit_dependencies`. Socket, Snyk, Helmet, Express, bcrypt,
Argon2, JWT, Zod, CORS, Paramiko, Impacket, TensorFlow and similar ecosystems remain
their own tools/frameworks; this package does not silently install or wrap all of them.

## Examples

```python
from cybersecure import Cybersecure

# Sends a TCP SYN to a private or loopback address (may need administrator rights).
Cybersecure.send_packet(Ip="127.0.0.1", Port=80)

# Scan only your private/loopback host.
print(Cybersecure.scan_ports(Ip="192.168.1.10", Ports="22,80,443"))

print(Cybersecure.get_page(URL="https://example.com")["status"])
print(Cybersecure.Curl_Call(CURL='curl --url "https://example.com" -H "Accept: text/html"'))
print(Cybersecure.extract_links(URL="https://example.com"))
print(Cybersecure.extract_element(URL="https://example.com", Selector="h1"))
print(Cybersecure.extract_element(URL="https://example.com", Selector="p", All=True))

# Optional: choose one proxy from monosans/proxy-list, or pass one of your own.
proxy = Cybersecure.proxies()  # random HTTP proxy
print(Cybersecure.get_page(URL="https://example.com", Proxy=proxy)["status"])
# Or use Proxy="random" directly in get_page/extract_links/extract_element.
print(Cybersecure.sha256(File="download.bin"))

blob = Cybersecure.encrypt_text(Text="hello", Password="use a long unique passphrase")
print(Cybersecure.decrypt_text(Encrypted=blob, Password="use a long unique passphrase"))

print(Cybersecure.audit_python(PathToCode="./src"))
print(Cybersecure.audit_dependencies(PathToProject="./web-app"))
print(Cybersecure.express_security_template())  # starter code for a separate Express app

# Added network / DNS / password / file helpers:
print(Cybersecure.ping_host(Ip="192.168.1.1"))
print(Cybersecure.dns_lookup(Domain="example.com", RecordType="A"))
print(Cybersecure.check_security_headers(URL="https://example.com"))
print(Cybersecure.check_password_strength("a-long-example-passphrase"))
print(Cybersecure.hash_text(Text="hello", Algorithm="sha256"))
print(Cybersecure.get_file_metadata(File="sample.bin"))

# Print the complete command reference:
import cybersecure
cybersecure.help()

# Explain Python findings, preview/apply conservative fixes, and verify:
report = Cybersecure.audit("./myapp")
print(report.explain())
print(report.preview_fixes())
# Only deterministic literal-command B602 cases are auto-fixable.
report.apply_fixes(confirm=True)  # changes source files; inspect preview first
print(report.verify())

# Save a baseline, then compare future scans:
Cybersecure.snapshot("./myapp")
changes = Cybersecure.diff_snapshot("./myapp", FailOnNew="HIGH")
print(changes)
if changes["fail"]:
    raise SystemExit("New high severity findings")
```

`Cybersecure.audit()` currently uses Bandit for Python code. Findings share a
`Finding` interface (`severity`, `confidence`, `cwe`, `cve`, `location`, `evidence`,
`explanation`, `remediation`, `fix_available`, `explain()`, `preview_fix()`, and
`verify()`). The first automatic fix handles only Bandit B602 when the command is
a static string with no interpolation; other findings are guidance-only. Snapshots
are stored under `.cybersecure/snapshot.json` by default. Snapshot comparisons use
rule, basename, line, and evidence as an identity, so moving code can appear as a
new and fixed finding.

Network helpers accept loopback and private IPs by default. For an authorized public
target only, explicitly set `CYBERSECURE_ALLOW_PUBLIC_TARGETS=1`. Get written
authorization before sending traffic or scanning any system. HTTP helpers only fetch
pages and do not fuzz or exploit endpoints. Never use this package to access systems
without permission. Secret material and passwords are never logged by this package.

Optional extras: `[dns]` installs DNS and WHOIS support, `[passwords]` installs Argon2,
and `[images]` installs Pillow. `[all]` includes these extras. Reputation lookups may
need `ABUSEIPDB_API_KEY` or a VirusTotal API key. `check_pwned_password()` uses the
Pwned Passwords range API and sends only the first five characters of the SHA-1 hash.
Static code scanners are heuristic and do not replace a full security review.
