audit-labs/audit-tools

A collection of scripts, queries, and other goodies you can use in an audit. audit automation compliance evidence scripts

Commit 4425565447

44255654474d891abb5b1cc367cfc210b725f1ec

parent: 2364326274

Unsigned

Christian Cleberg <156287552+ccleberg@users.noreply.github.com> · 2024-10-25 17:07 UTC
committer: <noreply@github.com>

reformat sql db_password test

Layout: unified · split

db_passwords/sql/data.csv added +9
@@ -0,0 +1,9 @@
1name,principal_id,sid,type,type_desc,is_disabled,create_date,modify_date,default_database_name,default_language_name,credential_id,is_policy_checked,is_expiration_checked,password_hash,IsMustChange,IsLocked,LockoutTime,PasswordLastSetTime,IsExpired,BadPasswordCount,BadPasswordTime,HistoryLength
2user1,1,,S,SQL_LOGIN,0,2023-01-15 10:35:00,2023-01-15 10:35:00,master,us_english,NULL,1,0,0x01004086CEB6772AE2356381B9B069D4E02C0185D5A06CFA3822,0,0,,2023-01-15 10:35:00,0,0,,5
3user2,267,,S,SQL_LOGIN,0,2023-02-20 20:49:00,2023-02-20 20:49:00,master,us_english,NULL,0,0,0x01003E3A7A6F88A8F548540ECB2043946AC2545120424CCD8782,1,0,,2023-02-20 20:49:00,0,1,2023-02-20 20:50:00,3
4user3,268,,S,SQL_LOGIN,0,2023-03-10 11:20:00,2023-03-10 11:20:00,Adminserver,us_english,NULL,1,0,0x010042516769FBC191A67840731CB36B41EFDACC97BE8264281F,0,0,,2023-03-10 11:20:00,0,0,,4
5user4,269,,S,SQL_LOGIN,0,2023-04-01 10:40:00,2023-04-01 11:32:00,Adminserver,us_english,NULL,1,0,0x01005F3B351B26E2DB7C7FD3C7ED02B3FD2EDC09BB2BF13DA3E5,0,1,2023-04-01 11:32:00,2023-04-01 10:40:00,0,3,2023-04-01 11:30:00,2
6user5,270,,S,SQL_LOGIN,0,2023-05-05 12:33:00,2023-05-05 12:33:00,master,us_english,NULL,1,0,0x0100AE15D55972BB3D6C6283921711CD4A208747888BEEFED71B,0,0,,2023-05-05 12:33:00,0,0,,6
7user6,272,,S,SQL_LOGIN,0,2023-06-15 11:46:00,2023-06-15 11:46:00,Adminserver,us_english,NULL,1,1,0x0100F12FAE790FCE0FF356A0948211AE4052653503E1BBC28FAB,0,0,,2023-06-15 11:46:00,0,0,,7
8user7,279,,S,SQL_LOGIN,0,2023-07-20 12:50:00,2023-07-20 12:50:00,Adminserver,us_english,NULL,1,1,0x01004856A222264E62219236AB6AC7E5B622F1E53D1CCA2AF9B8,0,0,,2023-07-20 12:50:00,0,0,,8
9user8,284,,S,SQL_LOGIN,0,2023-08-25 13:56:00,2023-08-25 13:56:00,master,us_english,NULL,1,1,0x0100723BEDBE69779CD3087C0E60AD69C33CC7E969F78DA2498A,0,0,,2023-08-25 13:56:00,0,0,,9
\ No newline at end of file
db_passwords/sql/test.py +25 −24
@@ -4,27 +4,23 @@ Checks SQL Server user data for compliance with Windows policies.
44
55# Import packages
66import pandas as pd
7from io import StringIO
8
9# Sample data as a CSV string
10data = """name,principal_id,sid,type,type_desc,is_disabled,create_date,modify_date,default_database_name,default_language_name,credential_id,is_policy_checked,is_expiration_checked,password_hash,IsMustChange,IsLocked,LockoutTime,PasswordLastSetTime,IsExpired,BadPasswordCount,BadPasswordTime,HistoryLength
11user1,1,,S,SQL_LOGIN,0,2023-01-15 10:35:00,2023-01-15 10:35:00,master,us_english,NULL,1,0,0x01004086CEB6772AE2356381B9B069D4E02C0185D5A06CFA3822,0,0,,2023-01-15 10:35:00,0,0,,5
12user2,267,,S,SQL_LOGIN,0,2023-02-20 20:49:00,2023-02-20 20:49:00,master,us_english,NULL,0,0,0x01003E3A7A6F88A8F548540ECB2043946AC2545120424CCD8782,1,0,,2023-02-20 20:49:00,0,1,2023-02-20 20:50:00,3
13user3,268,,S,SQL_LOGIN,0,2023-03-10 11:20:00,2023-03-10 11:20:00,Adminserver,us_english,NULL,1,0,0x010042516769FBC191A67840731CB36B41EFDACC97BE8264281F,0,0,,2023-03-10 11:20:00,0,0,,4
14user4,269,,S,SQL_LOGIN,0,2023-04-01 10:40:00,2023-04-01 11:32:00,Adminserver,us_english,NULL,1,0,0x01005F3B351B26E2DB7C7FD3C7ED02B3FD2EDC09BB2BF13DA3E5,0,1,2023-04-01 11:32:00,2023-04-01 10:40:00,0,3,2023-04-01 11:30:00,2
15user5,270,,S,SQL_LOGIN,0,2023-05-05 12:33:00,2023-05-05 12:33:00,master,us_english,NULL,1,0,0x0100AE15D55972BB3D6C6283921711CD4A208747888BEEFED71B,0,0,,2023-05-05 12:33:00,0,0,,6
16user6,272,,S,SQL_LOGIN,0,2023-06-15 11:46:00,2023-06-15 11:46:00,Adminserver,us_english,NULL,1,1,0x0100F12FAE790FCE0FF356A0948211AE4052653503E1BBC28FAB,0,0,,2023-06-15 11:46:00,0,0,,7
17user7,279,,S,SQL_LOGIN,0,2023-07-20 12:50:00,2023-07-20 12:50:00,Adminserver,us_english,NULL,1,1,0x01004856A222264E62219236AB6AC7E5B622F1E53D1CCA2AF9B8,0,0,,2023-07-20 12:50:00,0,0,,8
18user8,284,,S,SQL_LOGIN,0,2023-08-25 13:56:00,2023-08-25 13:56:00,master,us_english,NULL,1,1,0x0100723BEDBE69779CD3087C0E60AD69C33CC7E969F78DA2498A,0,0,,2023-08-25 13:56:00,0,0,,9
19"""
207
218# Load the data into a pandas DataFrame
22df = pd.read_csv(StringIO(data))
9df_input = pd.read_csv('./data.csv')
2310
2411# Function to apply rules and generate report
2512def apply_rules_and_report(df):
13 """
14 Apply defined rules against the input data.
15
16 Parameters:
17 df (pandas.DataFrame): SQL login data
18
19 Returns:
20 report (list): List of dictionaries containing test results
21 """
2622 report = []
27 for index, row in df.iterrows():
23 for _, row in df.iterrows():
2824 result = {
2925 'Name': row['name'],
3026 'Type Check': '',
@@ -46,29 +42,34 @@ def apply_rules_and_report(df):
4642 # Check if password policy is enforced
4743 if row['is_policy_checked'] == 1:
4844 result['Policy Check'] = 'PASS'
49 result['Reason'] += ' Password policy is enforced. Reviewer to check the assigned policy.'
45 result['Reason'] += '''Password policy is enforced. Reviewer to
46 check the assigned policy.'''
5047 else:
5148 result['Policy Check'] = 'FAIL'
52 result['Reason'] += ' Password policy is not enforced.'
53
49 result['Reason'] += 'Password policy is not enforced.'
50
5451 # Check if password expiration is enforced
5552 if row['is_expiration_checked'] == 1:
5653 result['Expiration Check'] = 'PASS'
57 result['Reason'] += ' Password expiration is enforced. Reviewer to check the expiration policy.'
54 result['Reason'] += '''Password expiration is enforced. Reviewer to
55 check the expiration policy.'''
5856 else:
5957 result['Expiration Check'] = 'FAIL'
60 result['Reason'] += ' Password expiration is not enforced.'
61
58 result['Reason'] += 'Password expiration is not enforced.'
59
6260 report.append(result)
63
61
6462 return report
6563
6664# Main function to run the script
6765def main():
66 """
67 Apply defined rules against the input data and print the results.
68 """
6869 # Apply rules and generate report
69 report = apply_rules_and_report(df)
70 report = apply_rules_and_report(df_input)
7071 report_df = pd.DataFrame(report)
71
72
7273 # Print the report
7374 print(report_df)
7475