Complete command-line reference for AuditKit
Complete command reference for AuditKit.
auditkit [command] [flags]
List and manage the offline scan cache.
auditkit cache
Every scan is cached under ~/.auditkit/cache. Combined with -offline, this lets you scan on a connected machine and produce reports on an air-gapped one.
# Report from the newest cached scan, no cloud API calls
auditkit scan -provider aws -framework soc2 -offline
# Report from a specific cache file
auditkit scan -offline -cache-file /path/to/scan.json
Run a compliance scan against your cloud infrastructure.
auditkit scan [flags]
Examples:
# Basic scan (defaults to AWS, all frameworks)
auditkit scan
# Specify provider and framework
auditkit scan -provider aws -framework soc2
auditkit scan -provider azure -framework pci
auditkit scan -provider gcp -framework cmmc
# All frameworks
auditkit scan -framework all
# Verbose output
auditkit scan -verbose
# Show all controls (no truncation)
auditkit scan --full
Flags:
- -provider - Cloud provider: aws, azure, gcp (default: aws)
- -framework - Compliance framework: soc2, pci, cmmc, hipaa, gdpr, nist-csf, 800-53, iso27001, fedramp-low, fedramp-moderate, fedramp-high, cis, cis-aws, cis-azure, cis-gcp, all (default: all)
- -verbose - Show detailed output
- --full - Show all controls without truncation
- -format - Output format: text, json, html, pdf, csv (default: text)
- -output - Output file path (e.g., report.pdf)
- -profile - AWS profile name (AWS only)
These exist only on the Pro binary. Passing them to Community Edition exits with
flag provided but not defined:
--scan-all - Scan all accounts/subscriptions/projects--max-concurrent - Max concurrent scans (default: 5)--summary-only - Show summary only, skip detailed resultsImport results from third-party tools (Prowler, ScubaGear).
auditkit integrate -source [tool] -file [path] [flags]
Examples:
# Import Prowler results (AWS/Azure/GCP)
auditkit integrate -source prowler -file prowler-output.json
# Generate PDF from Prowler results
auditkit integrate -source prowler -file prowler-output.json -format pdf -output prowler-report.pdf
# Import ScubaGear results (M365)
auditkit integrate -source scubagear -file ScubaResults/ScubaResults.json
# Generate PDF from ScubaGear results
auditkit integrate -source scubagear -file ScubaResults.json -format pdf -output m365-report.pdf
Flags:
- -source - Source tool: prowler, scubagear
- -file - Path to results file
- -format - Output format: text, json, pdf (default: text)
- -output - Output file path
Generate remediation scripts for failed controls.
auditkit fix [flags]
Examples:
# Generate fix script
auditkit fix
# Save to file
auditkit fix -output fixes.sh
# Review before running
cat fixes.sh
bash fixes.sh # Run after review
Flags:
- -output - Output file path (default: auditkit-<provider>-fixes.sh)
- -provider - Cloud provider to re-scan; fix runs a fresh scan rather than reusing the last one (default: aws)
Show compliance improvement over time.
auditkit progress
Output:
Compliance Progress Report
==========================
Framework: SOC2
Provider: AWS
Scan History:
2025-10-15: 65.0% (42/64 passed)
2025-10-18: 72.5% (46/64 passed)
2025-10-19: 78.1% (50/64 passed)
Improvement: +13.1% over 4 days
Trend: Increasing
Compare the last two scans.
auditkit compare
Output:
Compliance Comparison
=====================
Framework: SOC2
Provider: AWS
Previous Scan: 2025-10-18 (72.5%)
Current Scan: 2025-10-19 (78.1%)
Improvements:
+ CC6.1 - IAM Key Rotation (now passing)
+ CC6.2 - S3 Public Access (now passing)
+ CC7.1 - CloudTrail Logging (now passing)
+ CC8.1 - Encryption at Rest (now passing)
New Failures:
- None
Score Change: +5.6%
Track the evidence an assessor will ask for. Auditors want evidence for every control, including the ones that pass, so this covers the whole scan rather than just failures.
Note: the tracker currently always runs the SOC2 control set. The -framework
flag does not apply to this command.
auditkit evidence [flags]
Runs a scan, writes an HTML checklist, and records the controls in a durable
tracker at ~/.auditkit/evidence_<account>.json. The checklist keeps ticks in
your browser; the tracker is the copy you can share, review, or hand over.
Flags:
- -provider - Cloud provider: aws, azure, gcp (default: aws)
- -profile - AWS profile, Azure subscription, or GCP project
- -output - Where to write the HTML checklist (default: evidence-tracker.html)
Show what evidence has been collected, what is outstanding, and what has gone stale. Runs against the stored tracker, so it needs no cloud credentials.
auditkit evidence status [flags]
Flags:
- -account - Account ID, if you track more than one
- -stale-after - Days before collected evidence is considered stale (default: 90)
- -all - List every outstanding control rather than the first 20
Evidence older than the staleness window is reported as outstanding rather than collected. Assessors sample evidence from within the period under review, so a screenshot from last year is not evidence.
Record that evidence has been captured for a control.
auditkit evidence collect CONTROL-ID [flags]
Examples:
auditkit evidence collect CC6.1 -notes "IAM policy export and console screenshot" -by rob
auditkit evidence collect CC7.2 -artifact ./evidence/cloudwatch-alarms.png
Flags:
- -notes - What was captured and where it came from
- -artifact - Path to the screenshot or export
- -by - Who collected it
- -account - Account ID, if you track more than one
Load the JSON exported from the HTML checklist, so ticks made in the browser become part of the durable record.
auditkit evidence import PROGRESS.json [-by name]
Controls in the file that the scanner has not seen are reported and skipped.
Check for newer version of AuditKit.
auditkit update
Output:
Current version: v0.7.0
Latest version: v0.7.1
Update available!
Download: https://github.com/guardian-nexus/AuditKit-Community-Edition/releases/tag/v0.7.1
Show AuditKit version.
auditkit version
Output:
AuditKit v1.0.0 - Multi-cloud compliance scanning (AWS, Azure, GCP; M365 via ScubaGear import)
These flags work with all commands:
auditkit version - Show versionauditkit <command> --help - Show the flag list (e.g. auditkit scan --help)Note: bare -h, --help, -v and --version are not recognised — they are treated as commands and print the usage block with an "Unknown command" warning.
Human-readable terminal output with colors.
auditkit scan
Machine-readable JSON for automation.
auditkit scan -format json -output results.json
JSON Structure:
{
"timestamp": "2025-10-19T14:30:00Z",
"provider": "aws",
"framework": "soc2",
"account_id": "123456789012",
"score": 72.5,
"total_controls": 64,
"passed_controls": 46,
"failed_controls": 18,
"controls": [
{
"id": "CC6.6",
"name": "User MFA Enforcement",
"status": "FAIL",
"severity": "CRITICAL",
"evidence": "12 users without MFA",
"remediation": "Enable MFA for all users"
}
]
}
HTML report with Failed, Passed and Manual tabs.
auditkit scan -format html -output report.html
Audit-ready PDF report for auditors and management.
auditkit scan -format pdf -output report.pdf
PDF includes: - Executive summary - Compliance score - Passed/failed controls - Evidence collection guides - Remediation commands - Compliance mappings
AWS_ACCESS_KEY_ID # AWS access key
AWS_SECRET_ACCESS_KEY # AWS secret key
AWS_DEFAULT_REGION # Default AWS region
AWS_PROFILE # AWS CLI profile name
AZURE_CLIENT_ID # Service principal client ID
AZURE_CLIENT_SECRET # Service principal secret
AZURE_TENANT_ID # Azure tenant ID
AZURE_SUBSCRIPTION_ID # Subscription to scan
GOOGLE_APPLICATION_CREDENTIALS # Path to service account JSON
GOOGLE_CLOUD_PROJECT # GCP project ID
GCP_PROJECT # Alternative project ID variable
0 - Success1 - Any error the scanner reports (missing credentials, permission denied, or a failed scan)2 - A flag the binary does not recognise, or a malformed one; the flag parser exits before the scanner runsAuditKit does not currently distinguish error classes by exit code. To branch on the result in CI, parse the JSON report rather than the exit status.
# Run first scan
auditkit scan -provider aws -framework soc2 -verbose
# Generate PDF report for auditor
auditkit scan -provider aws -framework soc2 -format pdf -output initial-assessment.pdf
# Generate evidence tracker
auditkit evidence -format html -output evidence-tracker.html
# Generate fix script
auditkit fix -output fixes.sh
# Review and run fixes
cat fixes.sh
bash fixes.sh
# Re-scan to verify
auditkit scan -provider aws -framework soc2
# Compare improvements
auditkit compare
# Scan all providers
auditkit scan -provider aws -framework soc2 -output aws-results.json -format json
auditkit scan -provider azure -framework soc2 -output azure-results.json -format json
auditkit scan -provider gcp -framework soc2 -output gcp-results.json -format json
# Generate individual reports
auditkit scan -provider aws -framework soc2 -format pdf -output aws-report.pdf
auditkit scan -provider azure -framework soc2 -format pdf -output azure-report.pdf
auditkit scan -provider gcp -framework soc2 -format pdf -output gcp-report.pdf
# Run scan in pipeline
auditkit scan -provider aws -framework soc2 -format json -output results.json
# Check exit code
if [ $? -eq 0 ]; then
echo "Scan completed successfully"
else
echo "Scan failed"
exit 1
fi
# Parse results
jq '.score' results.json # Get compliance score
jq '.failed_controls' results.json # Get failed control count
# Weekly scans
# Monday
auditkit scan -provider aws -framework soc2
# Friday (after fixes)
auditkit scan -provider aws -framework soc2
# Show progress
auditkit progress
# Compare before/after
auditkit compare
These features require AuditKit:
# Scan entire AWS Organization
auditkit-pro scan -provider aws -framework soc2 --scan-all
# Scan Azure Management Group
auditkit-pro scan -provider azure -framework soc2 --scan-all
# Scan GCP Organization
auditkit-pro scan -provider gcp -framework soc2 --scan-all
# Control concurrency
auditkit-pro scan -provider aws --scan-all --max-concurrent 5
# Scan for CMMC Level 2 (110 practices)
auditkit-pro scan -provider aws -framework cmmc
# Generate Level 2 report
auditkit-pro scan -provider aws -framework cmmc -format pdf -output cmmc-l2-report.pdf
# Scan GKE clusters (Pro only)
auditkit-pro scan -provider gcp -framework soc2 # Includes GKE checks
# Scan Vertex AI (Pro only)
auditkit-pro scan -provider gcp -framework soc2 # Includes Vertex AI checks
Both editions answer RA.L2-3.11.2 and PCI 11.3.1 from what Inspector, Defender
for Cloud or VM Manager actually reaches. Pro adds remediation ageing
(RA.L2-3.11.3), a configurable policy, third-party scan import and the
vulnerability-management/ folder in the evidence package.
# Measure open findings against your own remediation windows
auditkit-pro scan -provider aws -framework cmmc -vuln-policy vuln-policy.yaml
# Evaluate a Nessus, Trivy or Grype report against the same policy
auditkit-pro integrate -source nessus -file scan.nessus
auditkit-pro integrate -source trivy -file trivy.json
auditkit-pro integrate -source grype -file grype.json
-vuln-policy is also read from ./vuln-policy.yaml, ~/.auditkit/ and
/etc/auditkit/. Without one, the built-in policy applies: critical within 30
days, high 90, medium 180, and a scan is stale after 30. The report names the
policy it measured against.
auditkit [command] --help