Metadata-Version: 2.5
Name: cyberplain
Version: 0.1.0
Summary: Plain-English defensive cybersecurity tools for Python and the command line
Project-URL: Homepage, https://github.com/fortnitecodedrop-cmyk/new
Project-URL: Repository, https://github.com/fortnitecodedrop-cmyk/new
Project-URL: Issues, https://github.com/fortnitecodedrop-cmyk/new/issues
Author: William J. Laurento II
License: MIT
License-File: LICENSE
Keywords: cybersecurity,defensive-security,dns,pcap,port-scanner,security,tls
Classifier: Development Status :: 3 - Alpha
Classifier: Intended Audience :: Developers
Classifier: Intended Audience :: System Administrators
Classifier: License :: OSI Approved :: MIT License
Classifier: Programming Language :: Python :: 3
Classifier: Programming Language :: Python :: 3.10
Classifier: Programming Language :: Python :: 3.11
Classifier: Programming Language :: Python :: 3.12
Classifier: Programming Language :: Python :: 3.13
Classifier: Topic :: Security
Requires-Python: >=3.10
Provides-Extra: dev
Requires-Dist: build>=1.2; extra == 'dev'
Requires-Dist: pytest>=8; extra == 'dev'
Requires-Dist: ruff>=0.6; extra == 'dev'
Requires-Dist: twine>=5; extra == 'dev'
Provides-Extra: packets
Requires-Dist: dpkt>=1.9.8; extra == 'packets'
Description-Content-Type: text/markdown

# CyberPlain

CyberPlain is a defensive cybersecurity toolkit for Python and the command line. It uses normal English in its names, output, errors, and documentation so beginners can understand what a check did and experienced practitioners can automate it.

> Use active network checks only on systems you own or have explicit written permission to test. CyberPlain is designed for defense, education, inventory, and authorized assessment—not exploitation, evasion, credential theft, or disruption.

## What is included

| Area | Command / API | What it does |
|---|---|---|
| Ports | `cyberplain ports` / `scan_ports()` | Bounded TCP connect scan with service names |
| Packets | `cyberplain pcap` / `summarize_pcap()` | Offline PCAP/PCAPNG traffic inventory |
| TLS | `cyberplain tls` / `inspect_tls()` | Certificate, cipher, version, and expiry explanation |
| Web | `cyberplain headers` / `audit_headers()` | Reviews common HTTP security headers |
| DNS | `cyberplain dns` | Forward and reverse address lookups |
| Files | `cyberplain file` | SHA-256, size, and entropy clues |
| Integrity | `cyberplain hash`, `manifest` | Hashing and directory change detection |
| Passwords | `cyberplain password` | Local strength feedback; never sends the password |
| Indicators | `cyberplain iocs`, `defang` | Extracts and safely formats URLs, domains, IPs, emails, and hashes |

## Install

```bash
pip install cyberplain
```

For offline packet-capture analysis:

```bash
pip install "cyberplain[packets]"
```

## Quick examples

```bash
# You must explicitly confirm authorization for active port checks.
cyberplain ports 192.168.1.10 --ports 22,80,443,8000-8010 --authorized

cyberplain tls example.com
cyberplain headers https://example.com
cyberplain dns example.com
cyberplain file download.zip
cyberplain hash installer.exe
cyberplain password
cyberplain pcap capture.pcap
cyberplain iocs suspicious-email.txt
cyberplain defang https://example.com/path
cyberplain manifest ./important-files --create baseline.json
cyberplain manifest ./important-files --verify baseline.json
```

Python API:

```python
from cyberplain import assess_password, hash_file, scan_ports

print(hash_file("download.zip"))
print(assess_password("a long example passphrase"))

result = scan_ports(
    "192.168.1.10",
    "22,80,443",
    authorized=True,  # only after you confirm permission
)
print(result["results"])
```

## Design promises

- Safe defaults and bounded concurrency.
- No telemetry; checks run locally unless the feature obviously contacts the host you name.
- Structured dictionaries/JSON for automation.
- Plain-English context instead of unexplained security jargon.
- Honest wording: a missing header or high-entropy file is a clue, not automatic proof of a vulnerability or malware.

## Development and PyPI publishing

### One-command publishing

From PowerShell inside the extracted project folder:

```powershell
py publish.py
```

The script installs the official build/upload tools, deletes only the old local
`dist` directory, builds fresh packages, validates them, asks for a final typed
confirmation, and uploads to PyPI. Twine then prompts for the username
`__token__` and your complete `pypi-...` API token. The token is never stored by
this project.

To test the complete workflow against TestPyPI first:

```powershell
py publish.py --test
```

### Manual publishing

```bash
python -m venv .venv
source .venv/bin/activate          # Windows: .venv\Scripts\activate
pip install -e ".[dev,packets]"
pytest
ruff check .
python -m build
twine check dist/*

# Test upload first
python -m twine upload --repository testpypi dist/*

# Final upload (requires your PyPI API token)
python -m twine upload dist/*
```

Before publishing, replace the placeholder GitHub URLs in `pyproject.toml`, confirm that the distribution name is available on PyPI, and choose your author/maintainer metadata.

## Scope and roadmap

No responsible package can literally cover every cybersecurity topic in one safe, maintainable release. CyberPlain 0.1 focuses on a strong defensive foundation. Good future additions include SARIF output, YARA rule scanning, OSV dependency checks, richer packet protocol summaries, certificate transparency lookup, and optional integrations with reputable threat-intelligence services.
