Skip to content

Latest commit

 

History

6 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Linux Vulnerability Audit Toolkit

Linux Audit Validation

A safety-focused Linux auditing toolkit for discovering software versions that may require vulnerability, lifecycle, or vendor-support review.

Project Overview

This project demonstrates a controlled approach to auditing Linux systems for selected Java, application-server, cryptographic, and database components.

The toolkit collects evidence without installing packages, applying patches, restarting services, or changing system configuration.

This repository uses fictional examples and sanitized documentation. It contains no employer, customer, production, or confidential infrastructure data.

Audit Scope

The current discovery checks cover:

  • Oracle Java and OpenJDK
  • Apache Tomcat
  • Apache Log4j 1.x candidates
  • OpenSSL
  • MySQL
  • MariaDB
  • RPM package metadata
  • Selected application files under common installation paths

A detected component is not automatically considered vulnerable. Findings must be verified against authoritative vendor and operating-system security advisories.

Project Objectives

  • Perform read-only Linux software discovery
  • Support local shell-based auditing
  • Support controlled multi-host discovery with Ansible
  • Separate discovery from remediation
  • Protect sensitive audit results
  • Produce structured evidence for further analysis
  • Validate scripts and playbooks automatically with GitHub Actions
  • Document security, privacy, and operational limitations

Repository Structure

linux-vulnerability-audit/
├── .github/
│   └── workflows/
│       └── shellcheck.yml
├── ansible/
│   └── audit.yml
├── config/
│   └── software-patterns.yml
├── docs/
│   ├── methodology.md
│   └── security-controls.md
├── sample-output/
│   └── README.md
├── scripts/
│   └── audit.sh
├── .gitattributes
├── .gitignore
├── LICENSE
└── README.md

Safety Controls

The toolkit is designed to be:

  • Read-only by default
  • Non-remediating
  • Non-disruptive
  • Usable without privilege escalation for standard checks
  • Explicit about incomplete or inaccessible data
  • Protective of raw reports and infrastructure information

See Security Controls for the complete safety model.

Local Linux Audit

Run the shell script on an authorized Linux system:

bash scripts/audit.sh

The script writes a timestamped CSV report beneath:

reports/

The reports/ directory is excluded from Git because raw output may contain sensitive system information.

To specify a different approved output directory:

bash scripts/audit.sh /approved/private/output/path

Ansible Audit

The playbook targets the inventory group:

[linux_audit_targets]
lab-rhel-01.example.invalid
lab-rhel-02.example.invalid

Perform a syntax check:

ansible-playbook -i inventory.ini ansible/audit.yml --syntax-check

Run the discovery playbook only against authorized systems:

ansible-playbook -i inventory.ini ansible/audit.yml

Do not commit a real inventory or raw command output to this public repository.

Finding Interpretation

Classification Meaning
Discovered A package, runtime, or file was detected
Candidate Additional version or vendor verification is required
Confirmed An authoritative source confirms exposure
Not affected Evidence shows the installed build is not affected
Remediation planned A reviewed corrective action has been approved
Remediated The corrective action was completed and validated

The toolkit reports discovery evidence. It does not independently prove exploitability.

Validation

GitHub Actions automatically performs:

  • ShellCheck analysis of scripts/audit.sh
  • YAML formatting validation
  • Ansible syntax validation

Local Terraform, cloud credentials, and infrastructure deployment are not required for this project.

Documentation

Technologies

  • Linux
  • Bash
  • Ansible
  • RPM
  • YAML
  • GitHub Actions
  • ShellCheck
  • yamllint

Project Status

The initial audit framework is complete and statically validated through continuous integration. Future development may add structured JSON output, package-manager portability, approved vulnerability-feed correlation, and automated tests.

License

This project is licensed under the MIT License.

About

A safety-focused Linux auditing toolkit for discovering vulnerable and unsupported software versions.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages