SegIt!

A shell script for automating network segmentation tests. It scans the ranges that are supposed to be unreachable, verifies whatever answered back, and writes the result up as a report.

Bash Nmap PCI segmentation testing Two-pass verification
Source Download Install Usage
evanricafort/segit Public
Code

Download

evanricafort/segit 9 files, 64 KB. Clone it, or grab a ZIP from the green Code button.
Requirements
  • Bash and a Linux or macOS shell
  • nmap
  • Root, for the scan types that need raw sockets
  • A source host inside the segment you are testing from
  • No compilation, no build step

SegIt! is a multi-file project — segit.sh sources the rest of the tree at runtime, so saving that one file on its own will not work. Clone the repository, or download it as a ZIP and keep the directory intact. Browse every file above before you run it.

Install

1

Clone the repository

The entry script sources config/ and lib/, so keep the tree intact.

git clone https://github.com/evanricafort/segit.git
cd segit
2

Make the scripts executable

The entry point plus the modules it sources.

sudo chmod +x segit.sh config/* lib/*
3

Check the options

Confirms it runs and prints the full flag list.

sudo ./segit.sh -h
4

Run the test

Point it at the range that is supposed to be out of reach.

sudo ./segit.sh -T4 --open 192.0.2.0/24

All of it in one line

git clone https://github.com/evanricafort/segit.git && cd segit && sudo chmod +x segit.sh config/* lib/* && sudo ./segit.sh -h

Usage

Flag What it does
<target(s)>One or more targets or CIDR ranges to test against.
-f, --file <file>Read targets from a file, one per line.
--from <subnet>Declare the source subnet. Auto-detected when omitted.
--o <dir>Custom output directory name.
--cpRun the scan twice - nmap then verify - and compare both in the report.
-T<0-5>Nmap timing template, for example -T4.
--openShow only open ports in the nmap output.
--fastScan the 1000 most common ports only.
--keepKeep the temporary files after the scan finishes.
--discordSend the results to a Discord webhook.
-h, --helpShow the help text.

Standard segmentation check

sudo ./segit.sh -T4 --open 192.0.2.0/24

Targets from a file, custom output

sudo ./segit.sh -f targets.txt --o client_segtest

Scan twice and compare

sudo ./segit.sh --cp -T4 --open 10.0.0.0/24

What a pass looks like

A segment that is correctly isolated returns nothing - no open ports, no responses from the ranges under test. Anything SegIt! reports is a host that answered across a boundary it should not have crossed, which is the finding. Run it only against networks you are authorized to test.