Giter Club home page Giter Club logo

audit-aws's Introduction

Audit AWS

This deployment is intended for the following AWS use cases:

##Auditing your AWS for:

  1. Usage and Billing.

  2. User reports:

  • Service access lists.
  • Console Authentication history
  • API Authentication history
  1. Cataloging:
  • EC2 instances.
  • S3 Buckets.
  • Lambda Functions.

Setup

Prerequisites

What do you need?

Any operating system that supports:

  • Git
  • Ansible
  • AWSCLI (Latest Version)

Deployment

To run the playbook you are required to have an existing aws configured profile with at minimum, view permissions for the services you wish to audit, To setup your AWS profile simply run the following on the host machine and supply the information.

aws configure

Getting started

If you have the prerequisites all setup simply follow the steps below: Clone the git repo.

git clone https://github.com/rnjudas/audit-aws

Change directory to the local repo:

cd audit-aws

Run the Ansible playbook with any of your desired options set to true. Alternatively you are able to use this playbook as is with Jenkins or any other Ci/CD server that allows for the specification of booleans at runtime.

ansible-playbook -i 'localhost,' ./play.yml -e "ROLE=audit-aws" -e "TARGET=localhost" -e "USER=ubuntu" \
-e "USER_REPORT=true" -e "EC2_REPORT=false" -e "LAMBDA_REPORT=false" -e "S3_REPORT=false" \
-e "RDS_REPORT=false" -e "CLOUDFRONT_REPORT=false" \
-e "CLOUDFORMATION_REPORT=false" -e "COST_USAGE_REPORT=false" -e "DAYS=1" \
-e "USER_AUTH_REPORT=false"

The results of the audit can be found in private/csv

Security

To make use of the billing module you will be required to use an AWS account with the needed policies to view billing information.

Built With

  • Ansible - The automation tool used
  • Vagrant - Portable virtual software maintainer
  • Virtualbox - General-purpose full virtualizer for x86 hardware

Contributing

Please read CONTRIBUTING.md for details on our code of conduct, and the process for submitting pull requests to us.

Versioning

N/A

Authors

  • Renaldo Maclons - Initial work - RNJudas

See also the list of contributors who participated in this project.

License

This project is licensed under the MIT License - see the LICENSE.md file for details

Acknowledgments

  • Henning Jacobs - AWS Cost Report - hjacobs

audit-aws's People

Contributors

renaldo-maclons avatar

Watchers

 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.