audit-labs/audit-tools

A collection of scripts, queries, and other goodies you can use in an audit. audit automation compliance evidence scripts

Commit 69f1606a74

69f1606a74b087cc4a108f733c27394034dc89bd

parent: 455c26478a

Unsigned

cmc <hello@cleberg.net> · 2025-05-07 02:54 UTC
committer: <noreply@github.com>

add and update READMEs (#7)

* add and update READMEs

* Commit from GitHub Actions (Ruff)

---------

Co-authored-by: github-actions <41898282+github-actions[bot]@users.noreply.github.com>

Layout: unified · split

README.md → README.org renamed +20 −19
@@ -1,17 +1,17 @@
1# Background
1* Background
22
33I have been an auditor for years, starting with operational/financial
44audits and quickly transitioning to technology audits early in my
55career.
66
77While performing technology audits, attestations, etc., you will find
8that it requires a lot of manual effort if you don\'t use the right
9tools to automate as much as possible.
8that it requires a lot of manual effort if you don't use the right tools
9to automate as much as possible.
1010
1111This repository serves as my personal collection of audit tools that I
1212want to save and re-use later.
1313
14## Scope
14** Scope
1515
1616While I created the scripts and tools within this repository
1717specifically for the applications I use, I am working to include
@@ -19,11 +19,11 @@ edge-cases and niche tools as I can.
1919
2020For now, refer to the tree below for application coverage.
2121
22```shell
22#+begin_src shell
2323tree -I ".git*|venv"
24```
24#+end_src
2525
26```text
26#+begin_src text
2727.
2828├── applications
2929│   ├── github
@@ -53,17 +53,19 @@ tree -I ".git*|venv"
5353│   │   └── README.org
5454│   ├── oracle
5555│   │   ├── oracle_admins_alt.sql
56│   │   └── oracle_admins.sql
56│   │   ├── oracle_admins.sql
57│   │   └── README.org
5758│   ├── postgres
5859│   │   ├── admins.sql
5960│   │   ├── passwords.sql
6061│   │   └── README.org
6162│   └── sql
6263│   ├── admins.sql
63│   └── passwords
64│   ├── data.csv
65│   ├── get_data.sql
66│   └── test.py
64│   ├── passwords
65│   │   ├── example_data.csv
66│   │   ├── passwords.py
67│   │   └── query.sql
68│   └── README.org
6769├── LICENSE
6870├── os
6971│   └── linux
@@ -79,25 +81,24 @@ tree -I ".git*|venv"
7981│   └── project_dashboard
8082│   ├── project_dashboard.pbix
8183│   └── project_data.xlsx
82├── README.md
84├── README.org
8385├── requirements.txt
8486└── sampling
8587 ├── README.org
8688 ├── sample.html
8789 ├── sample-html.png
8890 └── sample.py
89```
90
91# Development
91#+end_src
9292
93## Python
93* Development
94** Python
9495
9596For the Python scripts, use the following to activate a virtual
9697environment for consistent packing:
9798
98```shell
99#+begin_src shell
99100python3 -m venv venv
100101source ./venv/bin/activate
101102pip install PACKAGE_NAME
102103python3 ./PYTHON_SCRIPT.py
103```
104#+end_src
databases/oracle/README.org added +81
@@ -0,0 +1,81 @@
1* =oracle_admins.sql=
2
3#+begin_src sql
4SELECT
5 grantee AS "User",
6 privilege AS "Privilege"
7FROM
8 dba_sys_privs
9WHERE
10 grantee IN (SELECT DISTINCT grantee FROM dba_sys_privs)
11UNION ALL
12SELECT
13 grantee AS "User",
14 privilege AS "Privilege"
15FROM
16 dba_tab_privs
17WHERE
18 grantee IN (SELECT DISTINCT grantee FROM dba_tab_privs);
19#+end_src
20
21#+begin_src text
22| User | Privilege |
23|----------+---------------------|
24| SCOTT | CREATE SESSION |
25| SCOTT | CREATE TABLE |
26| SCOTT | SELECT |
27| SCOTT | INSERT |
28| HR | CREATE SESSION |
29| HR | SELECT |
30| HR | INSERT |
31| HR | UPDATE |
32| SYS | CREATE USER |
33| SYS | GRANT ANY PRIVILEGE |
34| SYS | DROP USER |
35| SYSTEM | CREATE TABLESPACE |
36| SYSTEM | CREATE USER |
37| SYSTEM | ALTER USER |
38| SYSTEM | DROP USER |
39| APP_USER | SELECT ON EMPLOYEES |
40| APP_USER | INSERT ON EMPLOYEES |
41| APP_USER | UPDATE ON EMPLOYEES |
42#+end_src
43
44* =oracle_admins_alt.sql=
45
46#+begin_src sql
47SELECT ** FROM sys.dba_role_privs;
48SELECT ** FROM sys.dba_sys_privs;
49SELECT ** FROM sys.dba_tab_privs;
50SELECT ** FROM sys.dba_users;
51#+end_src
52
53#+begin_src text
54| Grantee | Granted_Role | Admin_Option |
55|----------+--------------+--------------|
56| SCOTT | DBA | NO |
57| HR | RESOURCE | YES |
58| APP_USER | DATA_ANALYST | NO |
59
60| Grantee | Privilege |
61|---------+---------------------|
62| SCOTT | CREATE SESSION |
63| HR | CREATE TABLE |
64| SYS | GRANT ANY PRIVILEGE |
65| SYSTEM | CREATE USER |
66
67| Grantee | Table_Name | Privilege |
68|----------+-------------+-----------|
69| SCOTT | EMPLOYEES | SELECT |
70| SCOTT | EMPLOYEES | INSERT |
71| HR | DEPARTMENTS | SELECT |
72| APP_USER | EMPLOYEES | UPDATE |
73
74| Username | Account_Status | Default_Tablespace | Temporary_Tablespace |
75|----------+----------------+--------------------+----------------------|
76| SCOTT | OPEN | USERS | TEMP |
77| HR | OPEN | USERS | TEMP |
78| SYS | OPEN | SYSTEM | TEMP |
79| SYSTEM | OPEN | SYSTEM | TEMP |
80| APP_USER | OPEN | USERS | TEMP |
81#+end_src
databases/sql/README.org added +36
@@ -0,0 +1,36 @@
1* =admins.sql=
2
3#+begin_src sql
4:r admins.sql
5#+end_src
6
7,#+begin_src text
8| UserName | UserType | DatabaseUserName | Role | PermissionType | PermissionState | ObjectType | ObjectName | ColumnName |
9|-------------+--------------+------------------+-----------------+----------------+-----------------+----------------------+--------------------+------------|
10| SCOTT | SQL User | SCOTT | NULL | SELECT | GRANT | USER_TABLE | EMPLOYEES | NULL |
11| SCOTT | SQL User | SCOTT | NULL | INSERT | GRANT | USER_TABLE | EMPLOYEES | NULL |
12| HR | SQL User | HR | NULL | EXECUTE | GRANT | SQL_STORED_PROCEDURE | SP_GET_EMPLOYEE | NULL |
13| APP_USER | Windows User | APP_USER | ApplicationRole | SELECT | GRANT | VIEW | vw_EmployeeDetails | NULL |
14| APP_USER | Windows User | APP_USER | ApplicationRole | INSERT | GRANT | USER_TABLE | EMPLOYEES | NULL |
15| {All Users} | {All Users} | {All Users} | public | SELECT | GRANT | USER_TABLE | EMPLOYEES | NULL |
16| {All Users} | {All Users} | {All Users} | public | EXECUTE | GRANT | SQL_STORED_PROCEDURE | SP_GET_EMPLOYEE | NULL |
17#+end_src
18
19* =passwords.py=
20
21#+begin_src shell
22python passwords.py
23#+end_src
24
25#+begin_src text
26| Name | Type | Check Policy | Check Expiration | Reason |
27|-------+-----------+--------------+------------------+-----------------------------------------------------------------------------------------------------------------------------------------------|
28| user1 | SQL_LOGIN | PASS | FAIL | Password policy is enforced. Reviewer to check the assigned policy. Password expiration is not enforced. |
29| user2 | SQL_LOGIN | FAIL | FAIL | Password policy is not enforced. Password expiration is not enforced. |
30| user3 | SQL_LOGIN | PASS | FAIL | Password policy is enforced. Reviewer to check the assigned policy. Password expiration is not enforced. |
31| user4 | SQL_LOGIN | PASS | FAIL | Password policy is enforced. Reviewer to check the assigned policy. Password expiration is not enforced. |
32| user5 | SQL_LOGIN | PASS | FAIL | Password policy is enforced. Reviewer to check the assigned policy. Password expiration is not enforced. |
33| user6 | SQL_LOGIN | PASS | PASS | Password policy is enforced. Reviewer to check the assigned policy. Password expiration is enforced. Reviewer to check the expiration policy. |
34| user7 | SQL_LOGIN | PASS | PASS | Password policy is enforced. Reviewer to check the assigned policy. Password expiration is enforced. Reviewer to check the expiration policy. |
35| user8 | SQL_LOGIN | PASS | PASS | Password policy is enforced. Reviewer to check the assigned policy. Password expiration is enforced. Reviewer to check the expiration policy. |
36#+end_src
databases/sql/passwords/data.csv → databases/sql/passwords/example_data.csv renamed
databases/sql/passwords/test.py → databases/sql/passwords/passwords.py renamed +5
@@ -72,6 +72,11 @@ def main():
7272 report = apply_rules_and_report(df_input)
7373 report_df = pd.DataFrame(report)
7474
75 # Do not truncate output
76 pd.set_option("display.expand_frame_repr", True)
77 pd.set_option("display.width", 1000)
78 pd.set_option("display.max_colwidth", 1000)
79
7580 # Print the report
7681 print(report_df)
7782
databases/sql/passwords/get_data.sql → databases/sql/passwords/query.sql renamed