Audit Tools is a collection of open-source Python scripts and related resources intended to support auditors, risk professionals, and data analysts in automating common audit procedures and analyses.
This repository includes practical examples that can be used as-is or adapted to specific audit environments.
It also ships an interactive terminal UI (audit_tui.py) that walks you through
running an audit against GitHub, GitLab, or AWS — pick a platform, enter
connection details, choose which checks to run, and watch live progress.
| Directory | Description |
|---|---|
applications/aws/ | AWS IAM users, account/root security, password policy, S3 public access, open security groups, CloudTrail, Config, SSO |
applications/github/ | GitHub admin enumeration, org security settings, webhooks, deploy keys, secret-scanning/Dependabot alerts, audit log, branch protections, commits |
applications/gitlab/ | GitLab group/project members, branch protections, approvals, pipelines, audit events |
databases/mongo/ | MongoDB admin enumeration |
databases/mysql/ | MySQL admin and password queries |
databases/oracle/ | Oracle admin queries |
databases/postgres/ | PostgreSQL admin and password queries |
databases/sql/ | Generic SQL admin queries and password analysis |
os/linux/ | Linux OS reporting, password file analysis, and SSH root login checks |
project_management/ | Audit project tracking dashboards (Alteryx, Dash, Power BI) |
sampling/ | Random and stratified sampling tools |
tui/ | Interactive terminal UI that walks you through running an audit |
Clone the Repository
git clone https://github.com/audit-labs/audit-tools
cd audit-toolsInstall Dependencies
pip install -r requirements.txtRun a Script
For example, to run the Linux OS report tool:
./os/linux/report/linux.shOr to run a Python script:
python sampling/sample.pyOutput will be shown in the terminal or saved to a file, depending on the script.
Interactive TUI
To pick a platform and be walked through an audit interactively:
python audit_tui.pyEach run writes the same package the platform’s audit.py produces — one CSV per
check plus a summary — with a progress bar and per-check results:
See tui/README.md for details. GitHub, GitLab, and AWS are supported.
Contributions are welcome. You can contribute by:
- Adding new audit-related scripts
- Suggesting improvements or feature ideas
- Enhancing documentation
- Testing the tools on additional datasets and reporting any issues
To contribute:
- Fork the repository
- Create a new branch:
git checkout -b my-feature - Commit your changes:
git commit -m 'Added new audit test' - Push your branch:
git push origin my-feature - Open a pull request

