Read-only, always
AIXray observes and reports. It does not make changes.
AIXray is our free, open-source assessment engine: nearly 100 checks across 9 categories, scored red, amber, green, in plain English. Open code you read line by line before it runs — it installs nothing, changes nothing, and sends nothing anywhere. We never see your systems or your data.
AIXray is deliberately small, local, and honest about what it could not see.
AIXray observes and reports. It does not make changes.
The assessment runs where you put it and sends nothing anywhere.
Read the code line by line before it runs.
An unprivileged run degrades loudly, never silently.
Anything AIXray could not read is reported “not assessed,” by name.
The score covers lifecycle, currency, capacity, resilience, hardening, and the operational fundamentals around them.
Read the full audit guideThis AIX security assessment separates implemented requirements from numeric cross-checks so a report never implies more than the evidence supports.
For a DISA STIG AIX security assessment, AIXray has 72 of 283 requirements known-covered. Its compliance view reports PASS, FAIL, or not assessed with evidence for each covered V-ID — per-V-ID reporting, not a claim of full compliance.
CIS L1-aligned checks use a numeric cross-check mapped to eight unique CIS L1 control IDs — a given report shows verdicts only for the controls actually assessed on that system; anything unreached stays not assessed. Eight is the unique control set, not a benchmark denominator. CIS's consolidated IBM AIX 7 Benchmark covers 7.3; AIXray's numeric cross-check is not that benchmark, and AIXray does not claim full or certified benchmark coverage.
Alongside the standards tags, the shipped v1 file covers FLRTVC/APAR exposure by wrapping IBM’s flrtvc when its local inputs are supplied; firmware/UAK/EOL lifecycle state; and reference-data currency attestation. Missing inputs stay visible as not assessed.
What it doesn’t check yet: HIPAA and NCUA are not mapped; roughly 25 documented STIG rules remain deferred where a check needs multi-path, wildcard, per-user, or other handling; and AIXray does not implement the CIS IBM AIX 7 Benchmark; its CIS check is a bounded numeric cross-check.
This is the real scored output from a sanitized AIX 7.3 LPAR: nearly 100 checks, not a marketing mockup.
| Category | Result | Verdict |
|---|---|---|
| A. Lifecycle & support | 3 pass · 2 warn · 0 fail | AMBER |
| B. Patch & vulnerability currency | 7 pass · 0 warn · 0 fail · 3 not assessed | INCOMPLETE |
| C. Storage & capacity | 19 pass · 0 warn · 1 fail · 1 not assessed | RED |
| D. Performance & sizing | 9 pass · 1 warn · 0 fail | AMBER |
| E. Errors & events | 6 pass · 2 warn · 1 fail | RED |
| F. Availability & resilience | 2 pass · 3 warn · 1 fail | RED |
| G. Security & hardening | 9 pass · 7 warn · 8 fail · 1 not assessed | RED |
| H. Config hygiene | 3 pass · 2 warn · 1 fail | RED |
| I. Monitoring & operational readiness | 0 pass · 5 warn · 0 fail | AMBER |
Real output from a sanitized AIX 7.3 LPAR.View the full sample report →
A real, unedited AIXray run on our AIX lab — read-only, with identifiers pseudonymized
Captured on AIX 7.3 with all nine stages and the real score intact. Replayed at quarter speed so the output is easy to follow.
One current AIXray run from our own disposable AIX 7.3 lab. Every infrastructure identifier is fictional; the findings, scores, counts, and software levels are the run’s real output.
Open the scrubbed HTMLAIXray is open source under the Apache License 2.0 — download it, read every line, and run it anywhere. If it earns a place in your toolkit, star the repo, open an issue, or suggest the next check we should add.
Want these findings fixed and monitored 24/7? Start with twenty minutes with Tanner; if it is a fit, one of our engineers walks your findings with you from there. Or star the repo and suggest a check.
Coming soon · run AIXray from your AI agent (MCP)