Skip to content
AppClap
Noxen is unclaimed —
N

Noxen

Nightly security audits for your homelab. From your Mac. Without the SaaS.·noxen.app

Visit

Noxen is a Mac-native, agentless vulnerability scanner that runs nightly security audits against a user's Linux homelab and small VPS fleet over SSH. It matches installed packages against a signed daily CVE feed sourced from VulnCheck NVD++ and OSV.dev, performs SSH/TLS audits, and flags exposed admin surfaces from a catalog of 70+ services. Each report shows only what changed since the last scan, in a diff-style format rather than a full re-listing. All scan data stays local on the user's Mac, with no SaaS round-trip.

What it's for

Nightly automated security audits of remote Linux servers and VPS fleetsCVE matching against installed packages (dpkg/rpm)Detecting exposed admin panels and unauthenticated servicesSSH and TLS configuration auditingTracking config drift (sshd_config edits, TLS cipher changes, header regressions)Port scanning of top 1000 TCP portsExporting findings to SIEM toolsMapping findings to compliance frameworks (CIS v8, SOC 2, ISO 27001)Managing multiple client fleets via multi-tenant host catalogs

Features 19

  • Agentless SSH-based scanning of remote Linux hosts
  • Batch 'Scan all' with live progress banner
  • Command palette (⌘⇧P) for fuzzy-searchable actions
  • Compliance mapping to CIS Controls v8, SOC 2, ISO 27001:2022
  • Custom checks via JSON schema (HTTP/TCP probes)
  • CVE matching against dpkg/rpm package inventory
  • Diff-from-yesterday reporting showing only what changed
  • Exposed admin surface detection across 70+ services, flag-only (never authenticates)
  • HTTP security header checks (CSP, X-Frame-Options, Referrer-Policy, etc.)
  • LAN host discovery and SSH config import for onboarding
  • Local-first storage in SwiftData, with SSH keys in Keychain
  • Multi-tenant host catalogs (MSP tier)
  • PDF report export for client deliverables
  • Port scan of top 1000 TCP ports via Apple's Network framework
  • Scheduled nightly scans (survive sleep/wake, AC-power only by default)
  • SIEM export (NDJSON) for Wazuh / Splunk / ELK / Loki
  • Sparkle-based auto-update with Ed25519-signed release artefacts
  • SSH & TLS audit (weak ciphers, deprecated protocols, HSTS, OCSP stapling, cert expiry, sshd_config drift)
  • Webhooks to Slack / Discord / Teams / generic JSON

At a glance

free tierfree trial
TypeDesktop app
DeploymentInstalled (local)
PlatformsmacOS
LanguagesEnglish
Forhomelab operators, sysadmins, small consultancies, MSP consultants managing multiple client fleets
CompanyNoxen · 2026

Integrations

SlackDiscordMicrosoft TeamsWazuhSplunkELKLokiVulnCheckOSV.dev

Complianceself-reported

SOC 2ISO 27001CIS Controls v8

Resources

Pricing

Noxen 1.x is a $79 one-time purchase (not a monthly charge), including 1 year of updates; optional $39/year maintenance thereafter. Live Feed ($19/month) and MSP/Team ($149/month) are recurring subscriptions layered on top of the same app/license model.

FreeFree

No credit card required.

3 hosts

Noxen 1.xQuote

$79 one-time purchase, not a recurring charge. Optional $39/year maintenance for year 2+; app keeps working without it but stops getting feature/feed-format updates.

25 hosts

Live Feed$19/mo

Daily CVE feed updates, Same-day coverage of newly-disclosed CVEs, Slack / Discord / Teams webhooks, Everything in Noxen 1.x

100 hosts

MSP / Team$149/mo

Aimed at consultants managing multiple client fleets.

500 hosts

Last checked 29 days ago·