Free & open source · Apache-2.0

Ask your own system.

AIXray is our free, open-source assessment engine: nearly 100 checks across 9 categories, scored red, amber, green, in plain English. Open code you read line by line before it runs — it installs nothing, changes nothing, and sends nothing anywhere. We never see your systems or your data.

Trust boundaries

The safest script is the one you can inspect.

AIXray is deliberately small, local, and honest about what it could not see.

01

Read-only, always

AIXray observes and reports. It does not make changes.

02

No network calls, ever

The assessment runs where you put it and sends nothing anywhere.

03

One inspectable script

Read the code line by line before it runs.

04

Least privilege

An unprivileged run degrades loudly, never silently.

05

Never a false clean

Anything AIXray could not read is reported “not assessed,” by name.

What it checks

9 categories. One posture.

The score covers lifecycle, currency, capacity, resilience, hardening, and the operational fundamentals around them.

Read the full audit guide
  1. ALifecycle & support
  2. BPatch & vulnerability currency
  3. CStorage & capacity
  4. DPerformance & sizing
  5. EErrors & events
  6. FAvailability & resilience
  7. GSecurity & hardening
  8. HConfig hygiene
  9. IMonitoring & operational readiness
What it checks against

Named standards, bounded claims.

This AIX security assessment separates implemented requirements from numeric cross-checks so a report never implies more than the evidence supports.

01 / DISA

DISA STIG for IBM AIX 7.x

For a DISA STIG AIX security assessment, AIXray has 72 of 283 requirements known-covered. Its compliance view reports PASS, FAIL, or not assessed with evidence for each covered V-ID — per-V-ID reporting, not a claim of full compliance.

02 / CIS

CIS Level 1 alignment

CIS L1-aligned checks use a numeric cross-check mapped to eight unique CIS L1 control IDs — a given report shows verdicts only for the controls actually assessed on that system; anything unreached stays not assessed. Eight is the unique control set, not a benchmark denominator. CIS's consolidated IBM AIX 7 Benchmark covers 7.3; AIXray's numeric cross-check is not that benchmark, and AIXray does not claim full or certified benchmark coverage.

03 / ADJACENT

Exposure, lifecycle, and data currency

Alongside the standards tags, the shipped v1 file covers FLRTVC/APAR exposure by wrapping IBM’s flrtvc when its local inputs are supplied; firmware/UAK/EOL lifecycle state; and reference-data currency attestation. Missing inputs stay visible as not assessed.

LIMITS

What it doesn’t check yet: HIPAA and NCUA are not mapped; roughly 25 documented STIG rules remain deferred where a check needs multi-path, wildcard, per-user, or other handling; and AIXray does not implement the CIS IBM AIX 7 Benchmark; its CIS check is a bounded numeric cross-check.

Real output

Red, amber, green — with the evidence underneath.

This is the real scored output from a sanitized AIX 7.3 LPAR: nearly 100 checks, not a marketing mockup.

AIXray — posture snapshotHOST: acme-prod-aix01 · READ-ONLY · NOTHING CHANGED
63%
Pass rate
58
Pass
22
Warn
12
Fail
5
Not assessed
RED — 12 findings need attention now (9 high, 3 med). 5 areas not assessed.
9 categories, scored on this system
CategoryResultVerdict
A. Lifecycle & support
3 pass · 2 warn · 0 fail
AMBER
B. Patch & vulnerability currency
7 pass · 0 warn · 0 fail · 3 not assessed
INCOMPLETE
C. Storage & capacity
19 pass · 0 warn · 1 fail · 1 not assessed
RED
D. Performance & sizing
9 pass · 1 warn · 0 fail
AMBER
E. Errors & events
6 pass · 2 warn · 1 fail
RED
F. Availability & resilience
2 pass · 3 warn · 1 fail
RED
G. Security & hardening
9 pass · 7 warn · 8 fail · 1 not assessed
RED
H. Config hygiene
3 pass · 2 warn · 1 fail
RED
I. Monitoring & operational readiness
0 pass · 5 warn · 0 fail
AMBER

Real output from a sanitized AIX 7.3 LPAR.View the full sample report →

Real terminal recording

Watch a real assessment run.

A real, unedited AIXray run on our AIX lab — read-only, with identifiers pseudonymized

Captured on AIX 7.3 with all nine stages and the real score intact. Replayed at quarter speed so the output is easy to follow.

Recorded timing · ¼-speed replay · no audio
Scrubbed lab report

See a real report.

One current AIXray run from our own disposable AIX 7.3 lab. Every infrastructure identifier is fictional; the findings, scores, counts, and software levels are the run’s real output.

Open the scrubbed HTML
AIXray report posture summary showing a RED result and the real pass, warn, fail, and not-assessed counts
Posture at a glanceThe real score and executive summary, before interpretation.
AIXray report Start here priorities showing the first five real risks and fixes
Start with what mattersFAIL before WARN, then severity and observed evidence.
AIXray report finding evidence for lifecycle, support, firmware, and Technology Level currency
Evidence underneathObserved state, status, severity, meaning, and the concrete fix.
Free & open

Yours to run. Yours to shape.

AIXray is open source under the Apache License 2.0 — download it, read every line, and run it anywhere. If it earns a place in your toolkit, star the repo, open an issue, or suggest the next check we should add.

Want these findings fixed and monitored 24/7? Start with twenty minutes with Tanner; if it is a fit, one of our engineers walks your findings with you from there. Or star the repo and suggest a check.

Coming soon · run AIXray from your AI agent (MCP)