Commit 69f1606a74
69f1606a74b087cc4a108f733c27394034dc89bd
parent: 455c26478a
Unsigned
cmc <hello@cleberg.net> · 2025-05-07 02:54 UTC
committer: <noreply@github.com>
add and update READMEs (#7)
* add and update READMEs
* Commit from GitHub Actions (Ruff)
---------
Co-authored-by: github-actions <41898282+github-actions[bot]@users.noreply.github.com>
Layout: unified · split
README.md → README.org
renamed
+20 −19
| @@ -1,17 +1,17 @@ |
| 1 | | # Background |
| 1 | * Background |
| 2 | 2 | |
| 3 | 3 | I have been an auditor for years, starting with operational/financial |
| 4 | 4 | audits and quickly transitioning to technology audits early in my |
| 5 | 5 | career. |
| 6 | 6 | |
| 7 | 7 | While performing technology audits, attestations, etc., you will find |
| 8 | | that it requires a lot of manual effort if you don\'t use the right |
| 9 | | tools to automate as much as possible. |
| 8 | that it requires a lot of manual effort if you don't use the right tools |
| 9 | to automate as much as possible. |
| 10 | 10 | |
| 11 | 11 | This repository serves as my personal collection of audit tools that I |
| 12 | 12 | want to save and re-use later. |
| 13 | 13 | |
| 14 | | ## Scope |
| 14 | ** Scope |
| 15 | 15 | |
| 16 | 16 | While I created the scripts and tools within this repository |
| 17 | 17 | specifically for the applications I use, I am working to include |
| @@ -19,11 +19,11 @@ edge-cases and niche tools as I can. |
| 19 | 19 | |
| 20 | 20 | For now, refer to the tree below for application coverage. |
| 21 | 21 | |
| 22 | | ```shell |
| 22 | #+begin_src shell |
| 23 | 23 | tree -I ".git*|venv" |
| 24 | | ``` |
| 24 | #+end_src |
| 25 | 25 | |
| 26 | | ```text |
| 26 | #+begin_src text |
| 27 | 27 | . |
| 28 | 28 | ├── applications |
| 29 | 29 | │ ├── github |
| @@ -53,17 +53,19 @@ tree -I ".git*|venv" |
| 53 | 53 | │ │ └── README.org |
| 54 | 54 | │ ├── oracle |
| 55 | 55 | │ │ ├── oracle_admins_alt.sql |
| 56 | | │ │ └── oracle_admins.sql |
| 56 | │ │ ├── oracle_admins.sql |
| 57 | │ │ └── README.org |
| 57 | 58 | │ ├── postgres |
| 58 | 59 | │ │ ├── admins.sql |
| 59 | 60 | │ │ ├── passwords.sql |
| 60 | 61 | │ │ └── README.org |
| 61 | 62 | │ └── sql |
| 62 | 63 | │ ├── admins.sql |
| 63 | | │ └── passwords |
| 64 | | │ ├── data.csv |
| 65 | | │ ├── get_data.sql |
| 66 | | │ └── test.py |
| 64 | │ ├── passwords |
| 65 | │ │ ├── example_data.csv |
| 66 | │ │ ├── passwords.py |
| 67 | │ │ └── query.sql |
| 68 | │ └── README.org |
| 67 | 69 | ├── LICENSE |
| 68 | 70 | ├── os |
| 69 | 71 | │ └── linux |
| @@ -79,25 +81,24 @@ tree -I ".git*|venv" |
| 79 | 81 | │ └── project_dashboard |
| 80 | 82 | │ ├── project_dashboard.pbix |
| 81 | 83 | │ └── project_data.xlsx |
| 82 | | ├── README.md |
| 84 | ├── README.org |
| 83 | 85 | ├── requirements.txt |
| 84 | 86 | └── sampling |
| 85 | 87 | ├── README.org |
| 86 | 88 | ├── sample.html |
| 87 | 89 | ├── sample-html.png |
| 88 | 90 | └── sample.py |
| 89 | | ``` |
| 90 | | |
| 91 | | # Development |
| 91 | #+end_src |
| 92 | 92 | |
| 93 | | ## Python |
| 93 | * Development |
| 94 | ** Python |
| 94 | 95 | |
| 95 | 96 | For the Python scripts, use the following to activate a virtual |
| 96 | 97 | environment for consistent packing: |
| 97 | 98 | |
| 98 | | ```shell |
| 99 | #+begin_src shell |
| 99 | 100 | python3 -m venv venv |
| 100 | 101 | source ./venv/bin/activate |
| 101 | 102 | pip install PACKAGE_NAME |
| 102 | 103 | python3 ./PYTHON_SCRIPT.py |
| 103 | | ``` |
| 104 | #+end_src |
databases/oracle/README.org
added
+81
| @@ -0,0 +1,81 @@ |
| 1 | * =oracle_admins.sql= |
| 2 | |
| 3 | #+begin_src sql |
| 4 | SELECT |
| 5 | grantee AS "User", |
| 6 | privilege AS "Privilege" |
| 7 | FROM |
| 8 | dba_sys_privs |
| 9 | WHERE |
| 10 | grantee IN (SELECT DISTINCT grantee FROM dba_sys_privs) |
| 11 | UNION ALL |
| 12 | SELECT |
| 13 | grantee AS "User", |
| 14 | privilege AS "Privilege" |
| 15 | FROM |
| 16 | dba_tab_privs |
| 17 | WHERE |
| 18 | grantee IN (SELECT DISTINCT grantee FROM dba_tab_privs); |
| 19 | #+end_src |
| 20 | |
| 21 | #+begin_src text |
| 22 | | User | Privilege | |
| 23 | |----------+---------------------| |
| 24 | | SCOTT | CREATE SESSION | |
| 25 | | SCOTT | CREATE TABLE | |
| 26 | | SCOTT | SELECT | |
| 27 | | SCOTT | INSERT | |
| 28 | | HR | CREATE SESSION | |
| 29 | | HR | SELECT | |
| 30 | | HR | INSERT | |
| 31 | | HR | UPDATE | |
| 32 | | SYS | CREATE USER | |
| 33 | | SYS | GRANT ANY PRIVILEGE | |
| 34 | | SYS | DROP USER | |
| 35 | | SYSTEM | CREATE TABLESPACE | |
| 36 | | SYSTEM | CREATE USER | |
| 37 | | SYSTEM | ALTER USER | |
| 38 | | SYSTEM | DROP USER | |
| 39 | | APP_USER | SELECT ON EMPLOYEES | |
| 40 | | APP_USER | INSERT ON EMPLOYEES | |
| 41 | | APP_USER | UPDATE ON EMPLOYEES | |
| 42 | #+end_src |
| 43 | |
| 44 | * =oracle_admins_alt.sql= |
| 45 | |
| 46 | #+begin_src sql |
| 47 | SELECT ** FROM sys.dba_role_privs; |
| 48 | SELECT ** FROM sys.dba_sys_privs; |
| 49 | SELECT ** FROM sys.dba_tab_privs; |
| 50 | SELECT ** FROM sys.dba_users; |
| 51 | #+end_src |
| 52 | |
| 53 | #+begin_src text |
| 54 | | Grantee | Granted_Role | Admin_Option | |
| 55 | |----------+--------------+--------------| |
| 56 | | SCOTT | DBA | NO | |
| 57 | | HR | RESOURCE | YES | |
| 58 | | APP_USER | DATA_ANALYST | NO | |
| 59 | |
| 60 | | Grantee | Privilege | |
| 61 | |---------+---------------------| |
| 62 | | SCOTT | CREATE SESSION | |
| 63 | | HR | CREATE TABLE | |
| 64 | | SYS | GRANT ANY PRIVILEGE | |
| 65 | | SYSTEM | CREATE USER | |
| 66 | |
| 67 | | Grantee | Table_Name | Privilege | |
| 68 | |----------+-------------+-----------| |
| 69 | | SCOTT | EMPLOYEES | SELECT | |
| 70 | | SCOTT | EMPLOYEES | INSERT | |
| 71 | | HR | DEPARTMENTS | SELECT | |
| 72 | | APP_USER | EMPLOYEES | UPDATE | |
| 73 | |
| 74 | | Username | Account_Status | Default_Tablespace | Temporary_Tablespace | |
| 75 | |----------+----------------+--------------------+----------------------| |
| 76 | | SCOTT | OPEN | USERS | TEMP | |
| 77 | | HR | OPEN | USERS | TEMP | |
| 78 | | SYS | OPEN | SYSTEM | TEMP | |
| 79 | | SYSTEM | OPEN | SYSTEM | TEMP | |
| 80 | | APP_USER | OPEN | USERS | TEMP | |
| 81 | #+end_src |
databases/sql/README.org
added
+36
| @@ -0,0 +1,36 @@ |
| 1 | * =admins.sql= |
| 2 | |
| 3 | #+begin_src sql |
| 4 | :r admins.sql |
| 5 | #+end_src |
| 6 | |
| 7 | ,#+begin_src text |
| 8 | | UserName | UserType | DatabaseUserName | Role | PermissionType | PermissionState | ObjectType | ObjectName | ColumnName | |
| 9 | |-------------+--------------+------------------+-----------------+----------------+-----------------+----------------------+--------------------+------------| |
| 10 | | SCOTT | SQL User | SCOTT | NULL | SELECT | GRANT | USER_TABLE | EMPLOYEES | NULL | |
| 11 | | SCOTT | SQL User | SCOTT | NULL | INSERT | GRANT | USER_TABLE | EMPLOYEES | NULL | |
| 12 | | HR | SQL User | HR | NULL | EXECUTE | GRANT | SQL_STORED_PROCEDURE | SP_GET_EMPLOYEE | NULL | |
| 13 | | APP_USER | Windows User | APP_USER | ApplicationRole | SELECT | GRANT | VIEW | vw_EmployeeDetails | NULL | |
| 14 | | APP_USER | Windows User | APP_USER | ApplicationRole | INSERT | GRANT | USER_TABLE | EMPLOYEES | NULL | |
| 15 | | {All Users} | {All Users} | {All Users} | public | SELECT | GRANT | USER_TABLE | EMPLOYEES | NULL | |
| 16 | | {All Users} | {All Users} | {All Users} | public | EXECUTE | GRANT | SQL_STORED_PROCEDURE | SP_GET_EMPLOYEE | NULL | |
| 17 | #+end_src |
| 18 | |
| 19 | * =passwords.py= |
| 20 | |
| 21 | #+begin_src shell |
| 22 | python passwords.py |
| 23 | #+end_src |
| 24 | |
| 25 | #+begin_src text |
| 26 | | Name | Type | Check Policy | Check Expiration | Reason | |
| 27 | |-------+-----------+--------------+------------------+-----------------------------------------------------------------------------------------------------------------------------------------------| |
| 28 | | user1 | SQL_LOGIN | PASS | FAIL | Password policy is enforced. Reviewer to check the assigned policy. Password expiration is not enforced. | |
| 29 | | user2 | SQL_LOGIN | FAIL | FAIL | Password policy is not enforced. Password expiration is not enforced. | |
| 30 | | user3 | SQL_LOGIN | PASS | FAIL | Password policy is enforced. Reviewer to check the assigned policy. Password expiration is not enforced. | |
| 31 | | user4 | SQL_LOGIN | PASS | FAIL | Password policy is enforced. Reviewer to check the assigned policy. Password expiration is not enforced. | |
| 32 | | user5 | SQL_LOGIN | PASS | FAIL | Password policy is enforced. Reviewer to check the assigned policy. Password expiration is not enforced. | |
| 33 | | user6 | SQL_LOGIN | PASS | PASS | Password policy is enforced. Reviewer to check the assigned policy. Password expiration is enforced. Reviewer to check the expiration policy. | |
| 34 | | user7 | SQL_LOGIN | PASS | PASS | Password policy is enforced. Reviewer to check the assigned policy. Password expiration is enforced. Reviewer to check the expiration policy. | |
| 35 | | user8 | SQL_LOGIN | PASS | PASS | Password policy is enforced. Reviewer to check the assigned policy. Password expiration is enforced. Reviewer to check the expiration policy. | |
| 36 | #+end_src |
databases/sql/passwords/data.csv → databases/sql/passwords/example_data.csv
renamed
databases/sql/passwords/test.py → databases/sql/passwords/passwords.py
renamed
+5
| @@ -72,6 +72,11 @@ def main(): |
| 72 | 72 | report = apply_rules_and_report(df_input) |
| 73 | 73 | report_df = pd.DataFrame(report) |
| 74 | 74 | |
| 75 | # Do not truncate output |
| 76 | pd.set_option("display.expand_frame_repr", True) |
| 77 | pd.set_option("display.width", 1000) |
| 78 | pd.set_option("display.max_colwidth", 1000) |
| 79 | |
| 75 | 80 | # Print the report |
| 76 | 81 | print(report_df) |
| 77 | 82 | |
databases/sql/passwords/get_data.sql → databases/sql/passwords/query.sql
renamed