audit-labs/audit-tools

A collection of scripts, queries, and other goodies you can use in an audit. audit automation compliance evidence scripts

Commit 455c26478a

455c26478a28788b6f438e9ac7e1dd2a61aa08d3

parent: 3812cc8994

Unsigned

cmc <hello@cleberg.net> · 2025-05-07 02:31 UTC
committer: <noreply@github.com>

reorganize db dir (#6)

Layout: unified · split

README.md +19 −8
@@ -36,25 +36,36 @@ tree -I ".git*|venv"
36│   ├── approvals.py 36│   ├── approvals.py
37│   ├── branch_protections.py 37│   ├── branch_protections.py
38│   ├── passwords.py 38│   ├── passwords.py
39│   ├── pipelines.py
39│   ├── provisioning.py 40│   ├── provisioning.py
40│   ├── README.org 41│   ├── README.org
42│   ├── repositories.py
41│   └── users.py 43│   └── users.py
42├── CODEOWNERS 44├── CODEOWNERS
43├── databases 45├── databases
44│   ├── administrators 46│   ├── mongo
45│   │   ├── mssql_admins.sql 47│   │   ├── admins.py
48│   │   └── README.org
49│   ├── mysql
46│   │   ├── mysql_admins_alt.sql 50│   │   ├── mysql_admins_alt.sql
47│   │   ├── mysql_admins.sh
48│   │   ├── mysql_admins.sql 51│   │   ├── mysql_admins.sql
52│   │   ├── passwords.sql
53│   │   └── README.org
54│   ├── oracle
49│   │   ├── oracle_admins_alt.sql 55│   │   ├── oracle_admins_alt.sql
50│   │   └── oracle_admins.sql 56│   │   └── oracle_admins.sql
51│   └── passwords 57│   ├── postgres
52│   └── sql 58│   │   ├── admins.sql
59│   │   ├── passwords.sql
60│   │   └── README.org
61│   └── sql
62│   ├── admins.sql
63│   └── passwords
53│   ├── data.csv 64│   ├── data.csv
54│   ├── get_data.sql 65│   ├── get_data.sql
55│   └── test.py 66│   └── test.py
56├── LICENSE 67├── LICENSE
57├── operating-systems 68├── os
58│   └── linux 69│   └── linux
59│   ├── passwords.sh 70│   ├── passwords.sh
60│   ├── README.org 71│   ├── README.org
@@ -68,12 +79,12 @@ tree -I ".git*|venv"
68│   └── project_dashboard 79│   └── project_dashboard
69│   ├── project_dashboard.pbix 80│   ├── project_dashboard.pbix
70│   └── project_data.xlsx 81│   └── project_data.xlsx
71├── README.org 82├── README.md
72├── requirements.txt 83├── requirements.txt
73└── sampling 84└── sampling
74 ├── README.org 85 ├── README.org
75 ├── sample-html.png
76 ├── sample.html 86 ├── sample.html
87 ├── sample-html.png
77 └── sample.py 88 └── sample.py
78``` 89```
79 90
databases/administrators/mysql/README.org deleted −108
@@ -1,108 +0,0 @@
1#+title: MySQL Admins
2
3* =mysql_admins.sql=
4
5#+begin_src sql
6SELECT * FROM information_schema.user_privileges;
7#+end_src
8
9#+begin_src
10MySQL [(none)]> SELECT * FROM information_schema.user_privileges;
11+--------------------------------+---------------+---------------------------------+--------------+
12| GRANTEE | TABLE_CATALOG | PRIVILEGE_TYPE | IS_GRANTABLE |
13+--------------------------------+---------------+---------------------------------+--------------+
14| 'mysql.infoschema'@'localhost' | def | SELECT | NO |
15| 'mysql.infoschema'@'localhost' | def | AUDIT_ABORT_EXEMPT | NO |
16| 'mysql.infoschema'@'localhost' | def | FIREWALL_EXEMPT | NO |
17| 'mysql.infoschema'@'localhost' | def | SYSTEM_USER | NO |
18| 'mysql.session'@'localhost' | def | SHUTDOWN | NO |
19| 'mysql.session'@'localhost' | def | SUPER | NO |
20| 'mysql.session'@'localhost' | def | AUDIT_ABORT_EXEMPT | NO |
21| 'mysql.session'@'localhost' | def | AUTHENTICATION_POLICY_ADMIN | NO |
22| 'mysql.session'@'localhost' | def | BACKUP_ADMIN | NO |
23| 'mysql.session'@'localhost' | def | CLONE_ADMIN | NO |
24| 'mysql.session'@'localhost' | def | CONNECTION_ADMIN | NO |
25| 'mysql.session'@'localhost' | def | FIREWALL_EXEMPT | NO |
26| 'mysql.session'@'localhost' | def | PERSIST_RO_VARIABLES_ADMIN | NO |
27| 'mysql.session'@'localhost' | def | SESSION_VARIABLES_ADMIN | NO |
28| 'mysql.session'@'localhost' | def | SYSTEM_USER | NO |
29| 'mysql.session'@'localhost' | def | SYSTEM_VARIABLES_ADMIN | NO |
30| 'mysql.sys'@'localhost' | def | USAGE | NO |
31| 'mysql.sys'@'localhost' | def | AUDIT_ABORT_EXEMPT | NO |
32| 'mysql.sys'@'localhost' | def | FIREWALL_EXEMPT | NO |
33| 'mysql.sys'@'localhost' | def | SYSTEM_USER | NO |
34| 'root'@'localhost' | def | SELECT | YES |
35| 'root'@'localhost' | def | INSERT | YES |
36| 'root'@'localhost' | def | UPDATE | YES |
37| 'root'@'localhost' | def | DELETE | YES |
38| 'root'@'localhost' | def | CREATE | YES |
39| 'root'@'localhost' | def | DROP | YES |
40| 'root'@'localhost' | def | RELOAD | YES |
41| 'root'@'localhost' | def | SHUTDOWN | YES |
42| 'root'@'localhost' | def | PROCESS | YES |
43| 'root'@'localhost' | def | FILE | YES |
44| 'root'@'localhost' | def | REFERENCES | YES |
45| 'root'@'localhost' | def | INDEX | YES |
46| 'root'@'localhost' | def | ALTER | YES |
47| 'root'@'localhost' | def | SHOW DATABASES | YES |
48| 'root'@'localhost' | def | SUPER | YES |
49| 'root'@'localhost' | def | CREATE TEMPORARY TABLES | YES |
50| 'root'@'localhost' | def | LOCK TABLES | YES |
51| 'root'@'localhost' | def | EXECUTE | YES |
52| 'root'@'localhost' | def | REPLICATION SLAVE | YES |
53| 'root'@'localhost' | def | REPLICATION CLIENT | YES |
54| 'root'@'localhost' | def | CREATE VIEW | YES |
55| 'root'@'localhost' | def | SHOW VIEW | YES |
56| 'root'@'localhost' | def | CREATE ROUTINE | YES |
57| 'root'@'localhost' | def | ALTER ROUTINE | YES |
58| 'root'@'localhost' | def | CREATE USER | YES |
59| 'root'@'localhost' | def | EVENT | YES |
60| 'root'@'localhost' | def | TRIGGER | YES |
61| 'root'@'localhost' | def | CREATE TABLESPACE | YES |
62| 'root'@'localhost' | def | CREATE ROLE | YES |
63| 'root'@'localhost' | def | DROP ROLE | YES |
64| 'root'@'localhost' | def | ALLOW_NONEXISTENT_DEFINER | YES |
65| 'root'@'localhost' | def | APPLICATION_PASSWORD_ADMIN | YES |
66| 'root'@'localhost' | def | AUDIT_ABORT_EXEMPT | YES |
67| 'root'@'localhost' | def | AUDIT_ADMIN | YES |
68| 'root'@'localhost' | def | AUTHENTICATION_POLICY_ADMIN | YES |
69| 'root'@'localhost' | def | BACKUP_ADMIN | YES |
70| 'root'@'localhost' | def | BINLOG_ADMIN | YES |
71| 'root'@'localhost' | def | BINLOG_ENCRYPTION_ADMIN | YES |
72| 'root'@'localhost' | def | CLONE_ADMIN | YES |
73| 'root'@'localhost' | def | CONNECTION_ADMIN | YES |
74| 'root'@'localhost' | def | CREATE_SPATIAL_REFERENCE_SYSTEM | YES |
75| 'root'@'localhost' | def | ENCRYPTION_KEY_ADMIN | YES |
76| 'root'@'localhost' | def | FIREWALL_EXEMPT | YES |
77| 'root'@'localhost' | def | FLUSH_OPTIMIZER_COSTS | YES |
78| 'root'@'localhost' | def | FLUSH_PRIVILEGES | YES |
79| 'root'@'localhost' | def | FLUSH_STATUS | YES |
80| 'root'@'localhost' | def | FLUSH_TABLES | YES |
81| 'root'@'localhost' | def | FLUSH_USER_RESOURCES | YES |
82| 'root'@'localhost' | def | GROUP_REPLICATION_ADMIN | YES |
83| 'root'@'localhost' | def | GROUP_REPLICATION_STREAM | YES |
84| 'root'@'localhost' | def | INNODB_REDO_LOG_ARCHIVE | YES |
85| 'root'@'localhost' | def | INNODB_REDO_LOG_ENABLE | YES |
86| 'root'@'localhost' | def | OPTIMIZE_LOCAL_TABLE | YES |
87| 'root'@'localhost' | def | PASSWORDLESS_USER_ADMIN | YES |
88| 'root'@'localhost' | def | PERSIST_RO_VARIABLES_ADMIN | YES |
89| 'root'@'localhost' | def | REPLICATION_APPLIER | YES |
90| 'root'@'localhost' | def | REPLICATION_SLAVE_ADMIN | YES |
91| 'root'@'localhost' | def | RESOURCE_GROUP_ADMIN | YES |
92| 'root'@'localhost' | def | RESOURCE_GROUP_USER | YES |
93| 'root'@'localhost' | def | ROLE_ADMIN | YES |
94| 'root'@'localhost' | def | SENSITIVE_VARIABLES_OBSERVER | YES |
95| 'root'@'localhost' | def | SERVICE_CONNECTION_ADMIN | YES |
96| 'root'@'localhost' | def | SESSION_VARIABLES_ADMIN | YES |
97| 'root'@'localhost' | def | SET_ANY_DEFINER | YES |
98| 'root'@'localhost' | def | SHOW_ROUTINE | YES |
99| 'root'@'localhost' | def | SYSTEM_USER | YES |
100| 'root'@'localhost' | def | SYSTEM_VARIABLES_ADMIN | YES |
101| 'root'@'localhost' | def | TABLE_ENCRYPTION_ADMIN | YES |
102| 'root'@'localhost' | def | TELEMETRY_LOG_ADMIN | YES |
103| 'root'@'localhost' | def | TRANSACTION_GTID_TAG | YES |
104| 'root'@'localhost' | def | XA_RECOVER_ADMIN | YES |
105| 'cmc'@'%' | def | USAGE | NO |
106+--------------------------------+---------------+---------------------------------+--------------+
10792 rows in set (0.001 sec)
108#+end_src
databases/administrators/mongo/README.org → databases/mongo/README.org renamed
databases/administrators/mongo/admins.py → databases/mongo/admins.py renamed
databases/passwords/mysql/README.org → databases/mysql/README.org renamed +108 −1
@@ -1,7 +1,114 @@
1#+title: MySQL Passwords 1#+title: MySQL
2 2
3* =mysql_admins.sql= 3* =mysql_admins.sql=
4 4
5#+begin_src sql
6SELECT * FROM information_schema.user_privileges;
7#+end_src
8
9#+begin_src
10MySQL [(none)]> SELECT * FROM information_schema.user_privileges;
11+--------------------------------+---------------+---------------------------------+--------------+
12| GRANTEE | TABLE_CATALOG | PRIVILEGE_TYPE | IS_GRANTABLE |
13+--------------------------------+---------------+---------------------------------+--------------+
14| 'mysql.infoschema'@'localhost' | def | SELECT | NO |
15| 'mysql.infoschema'@'localhost' | def | AUDIT_ABORT_EXEMPT | NO |
16| 'mysql.infoschema'@'localhost' | def | FIREWALL_EXEMPT | NO |
17| 'mysql.infoschema'@'localhost' | def | SYSTEM_USER | NO |
18| 'mysql.session'@'localhost' | def | SHUTDOWN | NO |
19| 'mysql.session'@'localhost' | def | SUPER | NO |
20| 'mysql.session'@'localhost' | def | AUDIT_ABORT_EXEMPT | NO |
21| 'mysql.session'@'localhost' | def | AUTHENTICATION_POLICY_ADMIN | NO |
22| 'mysql.session'@'localhost' | def | BACKUP_ADMIN | NO |
23| 'mysql.session'@'localhost' | def | CLONE_ADMIN | NO |
24| 'mysql.session'@'localhost' | def | CONNECTION_ADMIN | NO |
25| 'mysql.session'@'localhost' | def | FIREWALL_EXEMPT | NO |
26| 'mysql.session'@'localhost' | def | PERSIST_RO_VARIABLES_ADMIN | NO |
27| 'mysql.session'@'localhost' | def | SESSION_VARIABLES_ADMIN | NO |
28| 'mysql.session'@'localhost' | def | SYSTEM_USER | NO |
29| 'mysql.session'@'localhost' | def | SYSTEM_VARIABLES_ADMIN | NO |
30| 'mysql.sys'@'localhost' | def | USAGE | NO |
31| 'mysql.sys'@'localhost' | def | AUDIT_ABORT_EXEMPT | NO |
32| 'mysql.sys'@'localhost' | def | FIREWALL_EXEMPT | NO |
33| 'mysql.sys'@'localhost' | def | SYSTEM_USER | NO |
34| 'root'@'localhost' | def | SELECT | YES |
35| 'root'@'localhost' | def | INSERT | YES |
36| 'root'@'localhost' | def | UPDATE | YES |
37| 'root'@'localhost' | def | DELETE | YES |
38| 'root'@'localhost' | def | CREATE | YES |
39| 'root'@'localhost' | def | DROP | YES |
40| 'root'@'localhost' | def | RELOAD | YES |
41| 'root'@'localhost' | def | SHUTDOWN | YES |
42| 'root'@'localhost' | def | PROCESS | YES |
43| 'root'@'localhost' | def | FILE | YES |
44| 'root'@'localhost' | def | REFERENCES | YES |
45| 'root'@'localhost' | def | INDEX | YES |
46| 'root'@'localhost' | def | ALTER | YES |
47| 'root'@'localhost' | def | SHOW DATABASES | YES |
48| 'root'@'localhost' | def | SUPER | YES |
49| 'root'@'localhost' | def | CREATE TEMPORARY TABLES | YES |
50| 'root'@'localhost' | def | LOCK TABLES | YES |
51| 'root'@'localhost' | def | EXECUTE | YES |
52| 'root'@'localhost' | def | REPLICATION SLAVE | YES |
53| 'root'@'localhost' | def | REPLICATION CLIENT | YES |
54| 'root'@'localhost' | def | CREATE VIEW | YES |
55| 'root'@'localhost' | def | SHOW VIEW | YES |
56| 'root'@'localhost' | def | CREATE ROUTINE | YES |
57| 'root'@'localhost' | def | ALTER ROUTINE | YES |
58| 'root'@'localhost' | def | CREATE USER | YES |
59| 'root'@'localhost' | def | EVENT | YES |
60| 'root'@'localhost' | def | TRIGGER | YES |
61| 'root'@'localhost' | def | CREATE TABLESPACE | YES |
62| 'root'@'localhost' | def | CREATE ROLE | YES |
63| 'root'@'localhost' | def | DROP ROLE | YES |
64| 'root'@'localhost' | def | ALLOW_NONEXISTENT_DEFINER | YES |
65| 'root'@'localhost' | def | APPLICATION_PASSWORD_ADMIN | YES |
66| 'root'@'localhost' | def | AUDIT_ABORT_EXEMPT | YES |
67| 'root'@'localhost' | def | AUDIT_ADMIN | YES |
68| 'root'@'localhost' | def | AUTHENTICATION_POLICY_ADMIN | YES |
69| 'root'@'localhost' | def | BACKUP_ADMIN | YES |
70| 'root'@'localhost' | def | BINLOG_ADMIN | YES |
71| 'root'@'localhost' | def | BINLOG_ENCRYPTION_ADMIN | YES |
72| 'root'@'localhost' | def | CLONE_ADMIN | YES |
73| 'root'@'localhost' | def | CONNECTION_ADMIN | YES |
74| 'root'@'localhost' | def | CREATE_SPATIAL_REFERENCE_SYSTEM | YES |
75| 'root'@'localhost' | def | ENCRYPTION_KEY_ADMIN | YES |
76| 'root'@'localhost' | def | FIREWALL_EXEMPT | YES |
77| 'root'@'localhost' | def | FLUSH_OPTIMIZER_COSTS | YES |
78| 'root'@'localhost' | def | FLUSH_PRIVILEGES | YES |
79| 'root'@'localhost' | def | FLUSH_STATUS | YES |
80| 'root'@'localhost' | def | FLUSH_TABLES | YES |
81| 'root'@'localhost' | def | FLUSH_USER_RESOURCES | YES |
82| 'root'@'localhost' | def | GROUP_REPLICATION_ADMIN | YES |
83| 'root'@'localhost' | def | GROUP_REPLICATION_STREAM | YES |
84| 'root'@'localhost' | def | INNODB_REDO_LOG_ARCHIVE | YES |
85| 'root'@'localhost' | def | INNODB_REDO_LOG_ENABLE | YES |
86| 'root'@'localhost' | def | OPTIMIZE_LOCAL_TABLE | YES |
87| 'root'@'localhost' | def | PASSWORDLESS_USER_ADMIN | YES |
88| 'root'@'localhost' | def | PERSIST_RO_VARIABLES_ADMIN | YES |
89| 'root'@'localhost' | def | REPLICATION_APPLIER | YES |
90| 'root'@'localhost' | def | REPLICATION_SLAVE_ADMIN | YES |
91| 'root'@'localhost' | def | RESOURCE_GROUP_ADMIN | YES |
92| 'root'@'localhost' | def | RESOURCE_GROUP_USER | YES |
93| 'root'@'localhost' | def | ROLE_ADMIN | YES |
94| 'root'@'localhost' | def | SENSITIVE_VARIABLES_OBSERVER | YES |
95| 'root'@'localhost' | def | SERVICE_CONNECTION_ADMIN | YES |
96| 'root'@'localhost' | def | SESSION_VARIABLES_ADMIN | YES |
97| 'root'@'localhost' | def | SET_ANY_DEFINER | YES |
98| 'root'@'localhost' | def | SHOW_ROUTINE | YES |
99| 'root'@'localhost' | def | SYSTEM_USER | YES |
100| 'root'@'localhost' | def | SYSTEM_VARIABLES_ADMIN | YES |
101| 'root'@'localhost' | def | TABLE_ENCRYPTION_ADMIN | YES |
102| 'root'@'localhost' | def | TELEMETRY_LOG_ADMIN | YES |
103| 'root'@'localhost' | def | TRANSACTION_GTID_TAG | YES |
104| 'root'@'localhost' | def | XA_RECOVER_ADMIN | YES |
105| 'cmc'@'%' | def | USAGE | NO |
106+--------------------------------+---------------+---------------------------------+--------------+
10792 rows in set (0.001 sec)
108#+end_src
109
110* =passwords.sql=
111
5#+begin_src sql 112#+begin_src sql
6SELECT user, host, plugin FROM mysql.user; 113SELECT user, host, plugin FROM mysql.user;
7#+end_src 114#+end_src
databases/administrators/mysql/mysql_admins.sql → databases/mysql/mysql_admins.sql renamed
databases/administrators/mysql/mysql_admins_alt.sql → databases/mysql/mysql_admins_alt.sql renamed
databases/passwords/mysql/passwords.sql → databases/mysql/passwords.sql renamed
databases/administrators/oracle/oracle_admins.sql → databases/oracle/oracle_admins.sql renamed
databases/administrators/oracle/oracle_admins_alt.sql → databases/oracle/oracle_admins_alt.sql renamed
databases/passwords/postgres/README.org deleted −31
@@ -1,31 +0,0 @@
1#+title: Postgres Passwords
2
3* =passwords.sql=
4
5#+begin_src sql
6SELECT *
7FROM pg_settings
8WHERE name LIKE 'password_%';
9#+end_src
10
11#+begin_src
12| name | setting | unit | category | short_desc | extra_desc | context | vartype | source | min_val | max_val | enumvals | boot_val | reset_val | sourcefile | sourceline | pending_restart |
13|---------------------+---------------+------+-------------------------------------------------+-------------------------------------------------+------------+---------+---------+---------+---------+---------+---------------------+---------------+---------------+------------+------------+-----------------|
14| password_encryption | scram-sha-256 | | Connections and Authentication / Authentication | Chooses the algorithm for encrypting passwords. | | user | enum | default | | | {md5,scram-sha-256} | scram-sha-256 | scram-sha-256 | | | false |
15#+end_src
16
17#+begin_src sql
18SELECT
19 usename AS user_name,
20 passwd AS password,
21 valuntil AS valid_until,
22 useconfig AS user_config
23FROM pg_shadow;
24#+end_src
25
26#+begin_src
27| user_name | password | valid_until | user_config |
28|-----------+---------------------------------------------------------------------------------------------------------------------------------------+------------------------+-------------|
29| cmc | | | |
30| testuser | SCRAM-SHA-256$4096:+NSpEU+8afhJ4BUTkzdKeg==$FGIRcTWr89b42qkLUl4Ntfp4RUpoc3GIpLHqJl/fWZE=:o1UM8YiEj5SLV5l/geMuqXMRi6onWazryn/l+LXYMxU= | 2025-12-31 00:00:00-06 | |
31#+end_src
databases/administrators/postgres/README.org → databases/postgres/README.org renamed +31 −1
@@ -1,4 +1,34 @@
1#+title: Postgres Admins 1#+title: Postgres
2
3* =passwords.sql=
4
5#+begin_src sql
6SELECT *
7FROM pg_settings
8WHERE name LIKE 'password_%';
9#+end_src
10
11#+begin_src
12| name | setting | unit | category | short_desc | extra_desc | context | vartype | source | min_val | max_val | enumvals | boot_val | reset_val | sourcefile | sourceline | pending_restart |
13|---------------------+---------------+------+-------------------------------------------------+-------------------------------------------------+------------+---------+---------+---------+---------+---------+---------------------+---------------+---------------+------------+------------+-----------------|
14| password_encryption | scram-sha-256 | | Connections and Authentication / Authentication | Chooses the algorithm for encrypting passwords. | | user | enum | default | | | {md5,scram-sha-256} | scram-sha-256 | scram-sha-256 | | | false |
15#+end_src
16
17#+begin_src sql
18SELECT
19 usename AS user_name,
20 passwd AS password,
21 valuntil AS valid_until,
22 useconfig AS user_config
23FROM pg_shadow;
24#+end_src
25
26#+begin_src
27| user_name | password | valid_until | user_config |
28|-----------+---------------------------------------------------------------------------------------------------------------------------------------+------------------------+-------------|
29| cmc | | | |
30| testuser | SCRAM-SHA-256$4096:+NSpEU+8afhJ4BUTkzdKeg==$FGIRcTWr89b42qkLUl4Ntfp4RUpoc3GIpLHqJl/fWZE=:o1UM8YiEj5SLV5l/geMuqXMRi6onWazryn/l+LXYMxU= | 2025-12-31 00:00:00-06 | |
31#+end_src
2 32
3* =admins.sql= 33* =admins.sql=
4 34
databases/administrators/postgres/admins.sql → databases/postgres/admins.sql renamed
databases/passwords/postgres/passwords.sql → databases/postgres/passwords.sql renamed
databases/administrators/microsoft-sql/mssql_admins.sql → databases/sql/admins.sql renamed
databases/passwords/sql/data.csv → databases/sql/passwords/data.csv renamed
databases/passwords/sql/get_data.sql → databases/sql/passwords/get_data.sql renamed
databases/passwords/sql/test.py → databases/sql/passwords/test.py renamed