PwnScan
Project · IoT exposure · SFU CMPT 783
Finds every device on a network without agents, fingerprints the IoT ones, and ranks their CVEs by how likely they are to be exploited.
- Team Three; I built discovery, fingerprinting and risk scoring
- Discovery ARP · mDNS · SSDP
- Risk CVSS × EPSS × exposure
- Recognition Top 3, CMPT 783
Three methods, one inventory
ARP, mDNS and SSDP each see devices the others miss. A host agent runs discovery on the LAN and seeds results back to the API; a two-pass port scan then enumerates and version-probes only what is open.
Severity is not risk
IoT devices are matched to NVD CVEs, then ranked by CVSS × EPSS × exposure. A critical CVE nobody exploits drops below a moderate one being exploited in the wild on an exposed camera.