Skip to content
CERNIS PRO Logo CERNIS PRO
DE
CERNIS PRO Logo

The network observer for the home

Your network. Your clarity. Your decision.

The home network is a small data centre today: TVs, voice assistants, cameras, thermostats, consoles, phones, NAS, printers — dozens of devices talking to the internet around the clock. CERNIS PRO scans the network, watches its traffic, investigates anything unusual and explains every finding in plain language. And the decisive difference: scans, histories and stored results remain on the user’s machine — no account, no cloud storage, no subscription.

It shows and puts things in context — but doesn’t judge. You decide.
  • Scans, histories and stored results remain on the user’s machine
  • Under the GPL-2.0-only, in the user’s hands
  • The source for every finding
The main window of CERNIS PRO with the situation overview: status, quick access, live metrics and new CVE findings.

What makes CERNIS PRO special

Radically local

There is no user account, no CERNIS cloud backend, no telemetry and no licence server. Scans, histories and stored results remain on the user’s machine — in local databases and files under the user’s control; nothing sits “somewhere”. They also remain after uninstalling until the user deletes them.

Passive observation

Capturing requested host names (SNI) only reads along instead of generating traffic of its own. The live data stays transient. The host names derived from it are stored permanently only once the user switches on the recording of external contacts.

Facts with their source

When CERNIS tells the user who is behind an IP address, it shows the source for every detail — name, network operator, country, certificate. No black box that simply says “dangerous” or “safe”.

The user defines “unusual”

The analysis rules belong to the user: defaults are there, but they are not binding.

Why CERNIS PRO

Between simple consumer apps and powerful professional tools there is a gap:

  • Simple network apps are quick to get going and beginner-friendly, but stay superficial, rarely put things in context (a traffic light instead of an explanation) and often move the essentials into cloud, account and subscription.
  • Professional and open-source kits can do a great deal, but demand expertise, several combined tools and sometimes dedicated hardware (a SPAN/TAP port, a second network card, a dedicated sensor).
  • Enterprise security is comprehensive, but expensive, complex and oversized for a home or small office network.

CERNIS PRO deliberately sits in between: the depth of a professional tool, the clarity of a consumer app and the data sovereignty of free software — in a desktop application that runs locally.

What that means in practice

Professional depth one can understand

Passive SNI capture (target host names even over encryption, attributed to the app), a network-wide DNS-bypass guardian, CVE cross-checks, routes with country/operator, a detailed FRITZ!Box read-out — in an understandable interface instead of several combined tools.

Passive, without hardware tinkering

No SPAN port, no second network card, no Raspberry Pi — an ordinary desktop application that needs no hardware of its own to read along.

What CERNIS PRO is NOT

  • Not a replacement for antivirus on the endpoint.
  • Not a firewall / intrusion-prevention system — CERNIS observes and explains, it does not block.
  • Not an enterprise SIEM for data centres with hundreds of hosts.
  • Not a packet-forensics tool for analysing individual bytes on the wire.

CERNIS is the honest, understandable observer for one’s own home and small office network — with plenty of depth, but without claiming to replace every specialised tool. Sold through clarity, not through fear.

A look inside the application

Four central views of CERNIS PRO — real screenshots from the running application.

The result table of a scan: for each device IP, MAC, vendor, host name, open ports, operating system, response time and further columns.
Network scan
Reachability and response time of preset and user-added targets as a live chart, showing outages immediately.
Live monitoring
The outbound contacts of this machine — passively observed, not a network-wide view: which external peers it talks to, grouped by operator, country or program. On request, CERNIS records these observations permanently.
External contacts
A network security report with the “network health” score (0–100), cleanly structured.
Security report

Depth beneath the friendly surface

From the one-click scan to the topology graph and the CVE cross-check, through to the network-wide DNS guardian and the detailed FRITZ!Box read-out: the range spans from beginner to professional — without overwhelming the beginner.

Features in detail

What can be checked

Trust should not be necessary here: the packages are under the GPL-2.0-only, and the source code is there to be read — in the same download area as the packages.

More on privacy & trust