A safety-focused Linux auditing toolkit for discovering software versions that may require vulnerability, lifecycle, or vendor-support review.
This project demonstrates a controlled approach to auditing Linux systems for selected Java, application-server, cryptographic, and database components.
The toolkit collects evidence without installing packages, applying patches, restarting services, or changing system configuration.
This repository uses fictional examples and sanitized documentation. It contains no employer, customer, production, or confidential infrastructure data.
The current discovery checks cover:
- Oracle Java and OpenJDK
- Apache Tomcat
- Apache Log4j 1.x candidates
- OpenSSL
- MySQL
- MariaDB
- RPM package metadata
- Selected application files under common installation paths
A detected component is not automatically considered vulnerable. Findings must be verified against authoritative vendor and operating-system security advisories.
- Perform read-only Linux software discovery
- Support local shell-based auditing
- Support controlled multi-host discovery with Ansible
- Separate discovery from remediation
- Protect sensitive audit results
- Produce structured evidence for further analysis
- Validate scripts and playbooks automatically with GitHub Actions
- Document security, privacy, and operational limitations
linux-vulnerability-audit/
├── .github/
│ └── workflows/
│ └── shellcheck.yml
├── ansible/
│ └── audit.yml
├── config/
│ └── software-patterns.yml
├── docs/
│ ├── methodology.md
│ └── security-controls.md
├── sample-output/
│ └── README.md
├── scripts/
│ └── audit.sh
├── .gitattributes
├── .gitignore
├── LICENSE
└── README.md
The toolkit is designed to be:
- Read-only by default
- Non-remediating
- Non-disruptive
- Usable without privilege escalation for standard checks
- Explicit about incomplete or inaccessible data
- Protective of raw reports and infrastructure information
See Security Controls for the complete safety model.
Run the shell script on an authorized Linux system:
bash scripts/audit.shThe script writes a timestamped CSV report beneath:
reports/
The reports/ directory is excluded from Git because raw output may contain sensitive system information.
To specify a different approved output directory:
bash scripts/audit.sh /approved/private/output/pathThe playbook targets the inventory group:
[linux_audit_targets]
lab-rhel-01.example.invalid
lab-rhel-02.example.invalidPerform a syntax check:
ansible-playbook -i inventory.ini ansible/audit.yml --syntax-checkRun the discovery playbook only against authorized systems:
ansible-playbook -i inventory.ini ansible/audit.ymlDo not commit a real inventory or raw command output to this public repository.
| Classification | Meaning |
|---|---|
| Discovered | A package, runtime, or file was detected |
| Candidate | Additional version or vendor verification is required |
| Confirmed | An authoritative source confirms exposure |
| Not affected | Evidence shows the installed build is not affected |
| Remediation planned | A reviewed corrective action has been approved |
| Remediated | The corrective action was completed and validated |
The toolkit reports discovery evidence. It does not independently prove exploitability.
GitHub Actions automatically performs:
- ShellCheck analysis of
scripts/audit.sh - YAML formatting validation
- Ansible syntax validation
Local Terraform, cloud credentials, and infrastructure deployment are not required for this project.
- Linux
- Bash
- Ansible
- RPM
- YAML
- GitHub Actions
- ShellCheck
- yamllint
The initial audit framework is complete and statically validated through continuous integration. Future development may add structured JSON output, package-manager portability, approved vulnerability-feed correlation, and automated tests.
This project is licensed under the MIT License.