Sign inSign up

gerardokaztro/iam-audit

By gerardokaztro

•Updated 6 months ago

Audit IAM users and access keys across AWS Organizations — interactive HTML dashboard included

Image
Security
Developer tools
0

1.8K

gerardokaztro/iam-audit repository overview

⁠iam-audit

Audits IAM users and access keys across all accounts in an AWS Organization. Generates an interactive HTML dashboard — available locally at localhost:8000 or delivered via Slack with a presigned S3 URL when running on AWS Fargate.


⁠Modes

ModeHowOutput
LocalDocker + AWS profileDashboard at localhost:8000
FargateEventBridge Scheduler (every Monday 9am)Slack notification with presigned URL (48hs)

⁠Local Usage

⁠Prerequisites
  • Docker installed
  • AWS credentials configured locally (~/.aws)
  • An audit role deployed in each member account (e.g. AWSControlTowerExecution)
docker run --rm \
  -v ~/.aws:/root/.aws \
  -v $(pwd)/output:/app/output \
  -p 8000:8000 \
  gerardokaztro/iam-audit \
  --profile YOUR-AWS-PROFILE \
  --role YOUR-AUDIT-ROLE

When the scan finishes, open your browser at:

http://localhost:8000

Press Ctrl+C to stop the server.


⁠Fargate Usage (Scheduled)

Deploy the infrastructure with Terraform — the task runs automatically every Monday at 9am (Lima, UTC-5) and sends a Slack notification with the dashboard URL.

⁠Prerequisites
  • Terraform >= 1.14.0
  • AWS CLI configured with admin access to your Security account
  • An audit role deployed in each member account (e.g. AWSControlTowerExecution)
  • A Slack webhook URL
⁠Deploy
cd infra
cp backend.hcl.example backend.hcl
cp terraform.tfvars.example terraform.tfvars
# Edit both files with your values
terraform init -backend-config=backend.hcl
terraform plan
terraform apply

⁠Output

All files are saved to ./output/ locally or to s3://iam-audit-reports-{account_id}/reports/YYYY-MM-DD/ on Fargate:

FileContent
iam_audit_report_TIMESTAMP.htmlInteractive dashboard
iam_audit_report_TIMESTAMP.csvIAM findings
root_audit_report_TIMESTAMP.csvRoot account findings
cloudtrail_events_TIMESTAMP.csvRemediation tracking

⁠Parameters

ParameterRequiredDescription
--profileNo (local only)AWS CLI profile name
--roleNoRole name to assume in each account (default: AWSControlTowerExecution)

⁠What it audits

  • Access keys per user — status, age, last used, service
  • MFA status per user (Virtual, Hardware, or missing)
  • Console access and last login
  • Root account — MFA, access keys, last login via CloudTrail
  • Remediation trend from CloudTrail events

⁠Infrastructure (Fargate mode)

Deployed via Terraform in your Security account:

ResourcePurpose
ECS Fargate TaskRuns the audit container
EventBridge SchedulerTriggers every Monday 9am Lima
S3 BucketStores reports (90-day lifecycle)
Secrets ManagerStores Slack webhook URL
IAM RolesTask Role + Execution Role

⁠Security

All releases are built for linux/amd64 from a pinned base image digest. Recommended usage by digest for reproducibility:

docker pull gerardokaztro/iam-audit@sha256:2876b73349c6a8c4847d4478a8e1f65971a6e1a3978320a2817e0ee3426e4ea4

⁠Source

GitHub: github.com/gerardokaztro/iam-audit⁠

Tag summary

Content type

Image

Digest

sha256:6b416a9dc…

Size

77.8 MB

Last updated

6 months ago

docker pull gerardokaztro/iam-audit