Commit 69f1606a74
69f1606a74b087cc4a108f733c27394034dc89bd
parent: 455c26478a
Unsigned
cmc <hello@cleberg.net> · 2025-05-07 02:54 UTC
committer: <noreply@github.com>
add and update READMEs (#7)
* add and update READMEs
* Commit from GitHub Actions (Ruff)
---------
Co-authored-by: github-actions <41898282+github-actions[bot]@users.noreply.github.com>
Layout: unified · split
README.md → README.org
renamed
+20 −19
| @@ -1,17 +1,17 @@ |
| 1 | # Background |
1 | * Background |
| 2 | |
2 | |
| 3 | I have been an auditor for years, starting with operational/financial |
3 | I have been an auditor for years, starting with operational/financial |
| 4 | audits and quickly transitioning to technology audits early in my |
4 | audits and quickly transitioning to technology audits early in my |
| 5 | career. |
5 | career. |
| 6 | |
6 | |
| 7 | While performing technology audits, attestations, etc., you will find |
7 | While performing technology audits, attestations, etc., you will find |
| 8 | that it requires a lot of manual effort if you don\'t use the right |
8 | that it requires a lot of manual effort if you don't use the right tools |
| 9 | tools to automate as much as possible. |
9 | to automate as much as possible. |
| 10 | |
10 | |
| 11 | This repository serves as my personal collection of audit tools that I |
11 | This repository serves as my personal collection of audit tools that I |
| 12 | want to save and re-use later. |
12 | want to save and re-use later. |
| 13 | |
13 | |
| 14 | ## Scope |
14 | ** Scope |
| 15 | |
15 | |
| 16 | While I created the scripts and tools within this repository |
16 | While I created the scripts and tools within this repository |
| 17 | specifically for the applications I use, I am working to include |
17 | specifically for the applications I use, I am working to include |
| @@ -19,11 +19,11 @@ edge-cases and niche tools as I can. |
| 19 | |
19 | |
| 20 | For now, refer to the tree below for application coverage. |
20 | For now, refer to the tree below for application coverage. |
| 21 | |
21 | |
| 22 | ```shell |
22 | #+begin_src shell |
| 23 | tree -I ".git*|venv" |
23 | tree -I ".git*|venv" |
| 24 | ``` |
24 | #+end_src |
| 25 | |
25 | |
| 26 | ```text |
26 | #+begin_src text |
| 27 | . |
27 | . |
| 28 | ├── applications |
28 | ├── applications |
| 29 | │ ├── github |
29 | │ ├── github |
| @@ -53,17 +53,19 @@ tree -I ".git*|venv" |
| 53 | │ │ └── README.org |
53 | │ │ └── README.org |
| 54 | │ ├── oracle |
54 | │ ├── oracle |
| 55 | │ │ ├── oracle_admins_alt.sql |
55 | │ │ ├── oracle_admins_alt.sql |
| 56 | │ │ └── oracle_admins.sql |
56 | │ │ ├── oracle_admins.sql |
| |
57 | │ │ └── README.org |
| 57 | │ ├── postgres |
58 | │ ├── postgres |
| 58 | │ │ ├── admins.sql |
59 | │ │ ├── admins.sql |
| 59 | │ │ ├── passwords.sql |
60 | │ │ ├── passwords.sql |
| 60 | │ │ └── README.org |
61 | │ │ └── README.org |
| 61 | │ └── sql |
62 | │ └── sql |
| 62 | │ ├── admins.sql |
63 | │ ├── admins.sql |
| 63 | │ └── passwords |
64 | │ ├── passwords |
| 64 | │ ├── data.csv |
65 | │ │ ├── example_data.csv |
| 65 | │ ├── get_data.sql |
66 | │ │ ├── passwords.py |
| 66 | │ └── test.py |
67 | │ │ └── query.sql |
| |
68 | │ └── README.org |
| 67 | ├── LICENSE |
69 | ├── LICENSE |
| 68 | ├── os |
70 | ├── os |
| 69 | │ └── linux |
71 | │ └── linux |
| @@ -79,25 +81,24 @@ tree -I ".git*|venv" |
| 79 | │ └── project_dashboard |
81 | │ └── project_dashboard |
| 80 | │ ├── project_dashboard.pbix |
82 | │ ├── project_dashboard.pbix |
| 81 | │ └── project_data.xlsx |
83 | │ └── project_data.xlsx |
| 82 | ├── README.md |
84 | ├── README.org |
| 83 | ├── requirements.txt |
85 | ├── requirements.txt |
| 84 | └── sampling |
86 | └── sampling |
| 85 | ├── README.org |
87 | ├── README.org |
| 86 | ├── sample.html |
88 | ├── sample.html |
| 87 | ├── sample-html.png |
89 | ├── sample-html.png |
| 88 | └── sample.py |
90 | └── sample.py |
| 89 | ``` |
91 | #+end_src |
| 90 | |
| |
| 91 | # Development |
| |
| 92 | |
92 | |
| 93 | ## Python |
93 | * Development |
| |
94 | ** Python |
| 94 | |
95 | |
| 95 | For the Python scripts, use the following to activate a virtual |
96 | For the Python scripts, use the following to activate a virtual |
| 96 | environment for consistent packing: |
97 | environment for consistent packing: |
| 97 | |
98 | |
| 98 | ```shell |
99 | #+begin_src shell |
| 99 | python3 -m venv venv |
100 | python3 -m venv venv |
| 100 | source ./venv/bin/activate |
101 | source ./venv/bin/activate |
| 101 | pip install PACKAGE_NAME |
102 | pip install PACKAGE_NAME |
| 102 | python3 ./PYTHON_SCRIPT.py |
103 | python3 ./PYTHON_SCRIPT.py |
| 103 | ``` |
104 | #+end_src |
databases/oracle/README.org
added
+81
| @@ -0,0 +1,81 @@ |
| |
1 | * =oracle_admins.sql= |
| |
2 | |
| |
3 | #+begin_src sql |
| |
4 | SELECT |
| |
5 | grantee AS "User", |
| |
6 | privilege AS "Privilege" |
| |
7 | FROM |
| |
8 | dba_sys_privs |
| |
9 | WHERE |
| |
10 | grantee IN (SELECT DISTINCT grantee FROM dba_sys_privs) |
| |
11 | UNION ALL |
| |
12 | SELECT |
| |
13 | grantee AS "User", |
| |
14 | privilege AS "Privilege" |
| |
15 | FROM |
| |
16 | dba_tab_privs |
| |
17 | WHERE |
| |
18 | grantee IN (SELECT DISTINCT grantee FROM dba_tab_privs); |
| |
19 | #+end_src |
| |
20 | |
| |
21 | #+begin_src text |
| |
22 | | User | Privilege | |
| |
23 | |----------+---------------------| |
| |
24 | | SCOTT | CREATE SESSION | |
| |
25 | | SCOTT | CREATE TABLE | |
| |
26 | | SCOTT | SELECT | |
| |
27 | | SCOTT | INSERT | |
| |
28 | | HR | CREATE SESSION | |
| |
29 | | HR | SELECT | |
| |
30 | | HR | INSERT | |
| |
31 | | HR | UPDATE | |
| |
32 | | SYS | CREATE USER | |
| |
33 | | SYS | GRANT ANY PRIVILEGE | |
| |
34 | | SYS | DROP USER | |
| |
35 | | SYSTEM | CREATE TABLESPACE | |
| |
36 | | SYSTEM | CREATE USER | |
| |
37 | | SYSTEM | ALTER USER | |
| |
38 | | SYSTEM | DROP USER | |
| |
39 | | APP_USER | SELECT ON EMPLOYEES | |
| |
40 | | APP_USER | INSERT ON EMPLOYEES | |
| |
41 | | APP_USER | UPDATE ON EMPLOYEES | |
| |
42 | #+end_src |
| |
43 | |
| |
44 | * =oracle_admins_alt.sql= |
| |
45 | |
| |
46 | #+begin_src sql |
| |
47 | SELECT ** FROM sys.dba_role_privs; |
| |
48 | SELECT ** FROM sys.dba_sys_privs; |
| |
49 | SELECT ** FROM sys.dba_tab_privs; |
| |
50 | SELECT ** FROM sys.dba_users; |
| |
51 | #+end_src |
| |
52 | |
| |
53 | #+begin_src text |
| |
54 | | Grantee | Granted_Role | Admin_Option | |
| |
55 | |----------+--------------+--------------| |
| |
56 | | SCOTT | DBA | NO | |
| |
57 | | HR | RESOURCE | YES | |
| |
58 | | APP_USER | DATA_ANALYST | NO | |
| |
59 | |
| |
60 | | Grantee | Privilege | |
| |
61 | |---------+---------------------| |
| |
62 | | SCOTT | CREATE SESSION | |
| |
63 | | HR | CREATE TABLE | |
| |
64 | | SYS | GRANT ANY PRIVILEGE | |
| |
65 | | SYSTEM | CREATE USER | |
| |
66 | |
| |
67 | | Grantee | Table_Name | Privilege | |
| |
68 | |----------+-------------+-----------| |
| |
69 | | SCOTT | EMPLOYEES | SELECT | |
| |
70 | | SCOTT | EMPLOYEES | INSERT | |
| |
71 | | HR | DEPARTMENTS | SELECT | |
| |
72 | | APP_USER | EMPLOYEES | UPDATE | |
| |
73 | |
| |
74 | | Username | Account_Status | Default_Tablespace | Temporary_Tablespace | |
| |
75 | |----------+----------------+--------------------+----------------------| |
| |
76 | | SCOTT | OPEN | USERS | TEMP | |
| |
77 | | HR | OPEN | USERS | TEMP | |
| |
78 | | SYS | OPEN | SYSTEM | TEMP | |
| |
79 | | SYSTEM | OPEN | SYSTEM | TEMP | |
| |
80 | | APP_USER | OPEN | USERS | TEMP | |
| |
81 | #+end_src |
databases/sql/README.org
added
+36
| @@ -0,0 +1,36 @@ |
| |
1 | * =admins.sql= |
| |
2 | |
| |
3 | #+begin_src sql |
| |
4 | :r admins.sql |
| |
5 | #+end_src |
| |
6 | |
| |
7 | ,#+begin_src text |
| |
8 | | UserName | UserType | DatabaseUserName | Role | PermissionType | PermissionState | ObjectType | ObjectName | ColumnName | |
| |
9 | |-------------+--------------+------------------+-----------------+----------------+-----------------+----------------------+--------------------+------------| |
| |
10 | | SCOTT | SQL User | SCOTT | NULL | SELECT | GRANT | USER_TABLE | EMPLOYEES | NULL | |
| |
11 | | SCOTT | SQL User | SCOTT | NULL | INSERT | GRANT | USER_TABLE | EMPLOYEES | NULL | |
| |
12 | | HR | SQL User | HR | NULL | EXECUTE | GRANT | SQL_STORED_PROCEDURE | SP_GET_EMPLOYEE | NULL | |
| |
13 | | APP_USER | Windows User | APP_USER | ApplicationRole | SELECT | GRANT | VIEW | vw_EmployeeDetails | NULL | |
| |
14 | | APP_USER | Windows User | APP_USER | ApplicationRole | INSERT | GRANT | USER_TABLE | EMPLOYEES | NULL | |
| |
15 | | {All Users} | {All Users} | {All Users} | public | SELECT | GRANT | USER_TABLE | EMPLOYEES | NULL | |
| |
16 | | {All Users} | {All Users} | {All Users} | public | EXECUTE | GRANT | SQL_STORED_PROCEDURE | SP_GET_EMPLOYEE | NULL | |
| |
17 | #+end_src |
| |
18 | |
| |
19 | * =passwords.py= |
| |
20 | |
| |
21 | #+begin_src shell |
| |
22 | python passwords.py |
| |
23 | #+end_src |
| |
24 | |
| |
25 | #+begin_src text |
| |
26 | | Name | Type | Check Policy | Check Expiration | Reason | |
| |
27 | |-------+-----------+--------------+------------------+-----------------------------------------------------------------------------------------------------------------------------------------------| |
| |
28 | | user1 | SQL_LOGIN | PASS | FAIL | Password policy is enforced. Reviewer to check the assigned policy. Password expiration is not enforced. | |
| |
29 | | user2 | SQL_LOGIN | FAIL | FAIL | Password policy is not enforced. Password expiration is not enforced. | |
| |
30 | | user3 | SQL_LOGIN | PASS | FAIL | Password policy is enforced. Reviewer to check the assigned policy. Password expiration is not enforced. | |
| |
31 | | user4 | SQL_LOGIN | PASS | FAIL | Password policy is enforced. Reviewer to check the assigned policy. Password expiration is not enforced. | |
| |
32 | | user5 | SQL_LOGIN | PASS | FAIL | Password policy is enforced. Reviewer to check the assigned policy. Password expiration is not enforced. | |
| |
33 | | user6 | SQL_LOGIN | PASS | PASS | Password policy is enforced. Reviewer to check the assigned policy. Password expiration is enforced. Reviewer to check the expiration policy. | |
| |
34 | | user7 | SQL_LOGIN | PASS | PASS | Password policy is enforced. Reviewer to check the assigned policy. Password expiration is enforced. Reviewer to check the expiration policy. | |
| |
35 | | user8 | SQL_LOGIN | PASS | PASS | Password policy is enforced. Reviewer to check the assigned policy. Password expiration is enforced. Reviewer to check the expiration policy. | |
| |
36 | #+end_src |
databases/sql/passwords/data.csv → databases/sql/passwords/example_data.csv
renamed
databases/sql/passwords/test.py → databases/sql/passwords/passwords.py
renamed
+5
| @@ -72,6 +72,11 @@ def main(): |
| 72 | report = apply_rules_and_report(df_input) |
72 | report = apply_rules_and_report(df_input) |
| 73 | report_df = pd.DataFrame(report) |
73 | report_df = pd.DataFrame(report) |
| 74 | |
74 | |
| |
75 | # Do not truncate output |
| |
76 | pd.set_option("display.expand_frame_repr", True) |
| |
77 | pd.set_option("display.width", 1000) |
| |
78 | pd.set_option("display.max_colwidth", 1000) |
| |
79 | |
| 75 | # Print the report |
80 | # Print the report |
| 76 | print(report_df) |
81 | print(report_df) |
| 77 | |
82 | |
databases/sql/passwords/get_data.sql → databases/sql/passwords/query.sql
renamed