audit-labs/audit-tools

A collection of scripts, queries, and other goodies you can use in an audit. audit automation compliance evidence scripts

Commit 06c579b35c

06c579b35c4296cabdb419352f9880fa2c1577b0

parent: 6e61fe24e7

Unsigned

Christian Cleberg <156287552+ccleberg@users.noreply.github.com> · 2024-10-28 19:16 UTC
committer: <noreply@github.com>

add github audit log script

Layout: unified · split

github/github_audit_log.py added +59
@@ -0,0 +1,59 @@
1"""
2Extract a specific list of events from the GitHub Audit Log API.
3
4NOTE: REQUIRES A GITHUB ENTERPRISE SUBSCRIPTION TO ACCESS THE API.
5"""
6
7import requests
8
9GITHUB_TOKEN = 'your_personal_access_token'
10ORGANIZATION = 'your_organization'
11TIMEOUT = 30
12
13# Headers for authentication
14headers = {
15 'Authorization': f'token {GITHUB_TOKEN}',
16 'Accept': 'application/vnd.github.v3+json'
17}
18
19def get_audit_log_events(org, actions):
20 """
21 Get audit log events for specific actions
22 """
23 events = []
24 page = 1
25 while True:
26 url = (f'https://api.github.com/orgs/{org}/audit-log?page={page}&per_page=100'
27 f'&action={",".join(actions)}')
28 response = requests.get(url, headers=headers, timeout=TIMEOUT)
29 response.raise_for_status()
30 page_events = response.json()
31 if not page_events:
32 break
33 events.extend(page_events)
34 page += 1
35 return events
36
37if __name__ == '__main__':
38 try:
39 # Define the actions to filter
40 action_filters = ['protected_branch',
41 'repository_branch_protection_evaluation',
42 'repository_ruleset']
43
44 # Get audit log events for the specified actions
45 audit_log_events = get_audit_log_events(ORGANIZATION, action_filters)
46 print(f"Total audit log events for specified actions: {len(audit_log_events)}")
47
48 # Print detailed information for each event
49 for event in audit_log_events:
50 print(f"\nEvent ID: {event['@id']}")
51 print(f"Action: {event['action']}")
52 print(f"Actor: {event['actor']}")
53 print(f"Repository: {event.get('repo', 'N/A')}")
54 print(f"Created At: {event['created_at']}")
55 print(f"Details: {event}")
56 except requests.exceptions.Timeout:
57 print("The request timed out")
58 except requests.exceptions.RequestException as e:
59 print(f"An error occurred: {e}")