audit-labs/audit-tools

A collection of scripts, queries, and other goodies you can use in an audit. audit automation compliance evidence scripts

Commit 69f1606a74

69f1606a74b087cc4a108f733c27394034dc89bd

parent: 455c26478a

Unsigned

cmc <hello@cleberg.net> · 2025-05-07 02:54 UTC
committer: <noreply@github.com>

add and update READMEs (#7)

* add and update READMEs

* Commit from GitHub Actions (Ruff)

---------

Co-authored-by: github-actions <41898282+github-actions[bot]@users.noreply.github.com>

Layout: unified · split

README.md → README.org renamed +20 −19
@@ -1,17 +1,17 @@
1# Background 1* Background
2 2
3I have been an auditor for years, starting with operational/financial 3I have been an auditor for years, starting with operational/financial
4audits and quickly transitioning to technology audits early in my 4audits and quickly transitioning to technology audits early in my
5career. 5career.
6 6
7While performing technology audits, attestations, etc., you will find 7While performing technology audits, attestations, etc., you will find
8that it requires a lot of manual effort if you don\'t use the right 8that it requires a lot of manual effort if you don't use the right tools
9tools to automate as much as possible. 9to automate as much as possible.
10 10
11This repository serves as my personal collection of audit tools that I 11This repository serves as my personal collection of audit tools that I
12want to save and re-use later. 12want to save and re-use later.
13 13
14## Scope 14** Scope
15 15
16While I created the scripts and tools within this repository 16While I created the scripts and tools within this repository
17specifically for the applications I use, I am working to include 17specifically for the applications I use, I am working to include
@@ -19,11 +19,11 @@ edge-cases and niche tools as I can.
19 19
20For now, refer to the tree below for application coverage. 20For now, refer to the tree below for application coverage.
21 21
22```shell 22#+begin_src shell
23tree -I ".git*|venv" 23tree -I ".git*|venv"
24``` 24#+end_src
25 25
26```text 26#+begin_src text
27. 27.
28├── applications 28├── applications
29│   ├── github 29│   ├── github
@@ -53,17 +53,19 @@ tree -I ".git*|venv"
53│   │   └── README.org 53│   │   └── README.org
54│   ├── oracle 54│   ├── oracle
55│   │   ├── oracle_admins_alt.sql 55│   │   ├── oracle_admins_alt.sql
56│   │   └── oracle_admins.sql 56│   │   ├── oracle_admins.sql
57│   │   └── README.org
57│   ├── postgres 58│   ├── postgres
58│   │   ├── admins.sql 59│   │   ├── admins.sql
59│   │   ├── passwords.sql 60│   │   ├── passwords.sql
60│   │   └── README.org 61│   │   └── README.org
61│   └── sql 62│   └── sql
62│   ├── admins.sql 63│   ├── admins.sql
63│   └── passwords 64│   ├── passwords
64│   ├── data.csv 65│   │   ├── example_data.csv
65│   ├── get_data.sql 66│   │   ├── passwords.py
66│   └── test.py 67│   │   └── query.sql
68│   └── README.org
67├── LICENSE 69├── LICENSE
68├── os 70├── os
69│   └── linux 71│   └── linux
@@ -79,25 +81,24 @@ tree -I ".git*|venv"
79│   └── project_dashboard 81│   └── project_dashboard
80│   ├── project_dashboard.pbix 82│   ├── project_dashboard.pbix
81│   └── project_data.xlsx 83│   └── project_data.xlsx
82├── README.md 84├── README.org
83├── requirements.txt 85├── requirements.txt
84└── sampling 86└── sampling
85 ├── README.org 87 ├── README.org
86 ├── sample.html 88 ├── sample.html
87 ├── sample-html.png 89 ├── sample-html.png
88 └── sample.py 90 └── sample.py
89``` 91#+end_src
90
91# Development
92 92
93## Python 93* Development
94** Python
94 95
95For the Python scripts, use the following to activate a virtual 96For the Python scripts, use the following to activate a virtual
96environment for consistent packing: 97environment for consistent packing:
97 98
98```shell 99#+begin_src shell
99python3 -m venv venv 100python3 -m venv venv
100source ./venv/bin/activate 101source ./venv/bin/activate
101pip install PACKAGE_NAME 102pip install PACKAGE_NAME
102python3 ./PYTHON_SCRIPT.py 103python3 ./PYTHON_SCRIPT.py
103``` 104#+end_src
databases/oracle/README.org added +81
@@ -0,0 +1,81 @@
1* =oracle_admins.sql=
2
3#+begin_src sql
4SELECT
5 grantee AS "User",
6 privilege AS "Privilege"
7FROM
8 dba_sys_privs
9WHERE
10 grantee IN (SELECT DISTINCT grantee FROM dba_sys_privs)
11UNION ALL
12SELECT
13 grantee AS "User",
14 privilege AS "Privilege"
15FROM
16 dba_tab_privs
17WHERE
18 grantee IN (SELECT DISTINCT grantee FROM dba_tab_privs);
19#+end_src
20
21#+begin_src text
22| User | Privilege |
23|----------+---------------------|
24| SCOTT | CREATE SESSION |
25| SCOTT | CREATE TABLE |
26| SCOTT | SELECT |
27| SCOTT | INSERT |
28| HR | CREATE SESSION |
29| HR | SELECT |
30| HR | INSERT |
31| HR | UPDATE |
32| SYS | CREATE USER |
33| SYS | GRANT ANY PRIVILEGE |
34| SYS | DROP USER |
35| SYSTEM | CREATE TABLESPACE |
36| SYSTEM | CREATE USER |
37| SYSTEM | ALTER USER |
38| SYSTEM | DROP USER |
39| APP_USER | SELECT ON EMPLOYEES |
40| APP_USER | INSERT ON EMPLOYEES |
41| APP_USER | UPDATE ON EMPLOYEES |
42#+end_src
43
44* =oracle_admins_alt.sql=
45
46#+begin_src sql
47SELECT ** FROM sys.dba_role_privs;
48SELECT ** FROM sys.dba_sys_privs;
49SELECT ** FROM sys.dba_tab_privs;
50SELECT ** FROM sys.dba_users;
51#+end_src
52
53#+begin_src text
54| Grantee | Granted_Role | Admin_Option |
55|----------+--------------+--------------|
56| SCOTT | DBA | NO |
57| HR | RESOURCE | YES |
58| APP_USER | DATA_ANALYST | NO |
59
60| Grantee | Privilege |
61|---------+---------------------|
62| SCOTT | CREATE SESSION |
63| HR | CREATE TABLE |
64| SYS | GRANT ANY PRIVILEGE |
65| SYSTEM | CREATE USER |
66
67| Grantee | Table_Name | Privilege |
68|----------+-------------+-----------|
69| SCOTT | EMPLOYEES | SELECT |
70| SCOTT | EMPLOYEES | INSERT |
71| HR | DEPARTMENTS | SELECT |
72| APP_USER | EMPLOYEES | UPDATE |
73
74| Username | Account_Status | Default_Tablespace | Temporary_Tablespace |
75|----------+----------------+--------------------+----------------------|
76| SCOTT | OPEN | USERS | TEMP |
77| HR | OPEN | USERS | TEMP |
78| SYS | OPEN | SYSTEM | TEMP |
79| SYSTEM | OPEN | SYSTEM | TEMP |
80| APP_USER | OPEN | USERS | TEMP |
81#+end_src
databases/sql/README.org added +36
@@ -0,0 +1,36 @@
1* =admins.sql=
2
3#+begin_src sql
4:r admins.sql
5#+end_src
6
7,#+begin_src text
8| UserName | UserType | DatabaseUserName | Role | PermissionType | PermissionState | ObjectType | ObjectName | ColumnName |
9|-------------+--------------+------------------+-----------------+----------------+-----------------+----------------------+--------------------+------------|
10| SCOTT | SQL User | SCOTT | NULL | SELECT | GRANT | USER_TABLE | EMPLOYEES | NULL |
11| SCOTT | SQL User | SCOTT | NULL | INSERT | GRANT | USER_TABLE | EMPLOYEES | NULL |
12| HR | SQL User | HR | NULL | EXECUTE | GRANT | SQL_STORED_PROCEDURE | SP_GET_EMPLOYEE | NULL |
13| APP_USER | Windows User | APP_USER | ApplicationRole | SELECT | GRANT | VIEW | vw_EmployeeDetails | NULL |
14| APP_USER | Windows User | APP_USER | ApplicationRole | INSERT | GRANT | USER_TABLE | EMPLOYEES | NULL |
15| {All Users} | {All Users} | {All Users} | public | SELECT | GRANT | USER_TABLE | EMPLOYEES | NULL |
16| {All Users} | {All Users} | {All Users} | public | EXECUTE | GRANT | SQL_STORED_PROCEDURE | SP_GET_EMPLOYEE | NULL |
17#+end_src
18
19* =passwords.py=
20
21#+begin_src shell
22python passwords.py
23#+end_src
24
25#+begin_src text
26| Name | Type | Check Policy | Check Expiration | Reason |
27|-------+-----------+--------------+------------------+-----------------------------------------------------------------------------------------------------------------------------------------------|
28| user1 | SQL_LOGIN | PASS | FAIL | Password policy is enforced. Reviewer to check the assigned policy. Password expiration is not enforced. |
29| user2 | SQL_LOGIN | FAIL | FAIL | Password policy is not enforced. Password expiration is not enforced. |
30| user3 | SQL_LOGIN | PASS | FAIL | Password policy is enforced. Reviewer to check the assigned policy. Password expiration is not enforced. |
31| user4 | SQL_LOGIN | PASS | FAIL | Password policy is enforced. Reviewer to check the assigned policy. Password expiration is not enforced. |
32| user5 | SQL_LOGIN | PASS | FAIL | Password policy is enforced. Reviewer to check the assigned policy. Password expiration is not enforced. |
33| user6 | SQL_LOGIN | PASS | PASS | Password policy is enforced. Reviewer to check the assigned policy. Password expiration is enforced. Reviewer to check the expiration policy. |
34| user7 | SQL_LOGIN | PASS | PASS | Password policy is enforced. Reviewer to check the assigned policy. Password expiration is enforced. Reviewer to check the expiration policy. |
35| user8 | SQL_LOGIN | PASS | PASS | Password policy is enforced. Reviewer to check the assigned policy. Password expiration is enforced. Reviewer to check the expiration policy. |
36#+end_src
databases/sql/passwords/data.csv → databases/sql/passwords/example_data.csv renamed
databases/sql/passwords/test.py → databases/sql/passwords/passwords.py renamed +5
@@ -72,6 +72,11 @@ def main():
72 report = apply_rules_and_report(df_input) 72 report = apply_rules_and_report(df_input)
73 report_df = pd.DataFrame(report) 73 report_df = pd.DataFrame(report)
74 74
75 # Do not truncate output
76 pd.set_option("display.expand_frame_repr", True)
77 pd.set_option("display.width", 1000)
78 pd.set_option("display.max_colwidth", 1000)
79
75 # Print the report 80 # Print the report
76 print(report_df) 81 print(report_df)
77 82
databases/sql/passwords/get_data.sql → databases/sql/passwords/query.sql renamed