Complete command reference for AuditKit.

Command Structure

auditkit [command] [flags]

Commands

cache

List and manage the offline scan cache.

auditkit cache

Every scan is cached under ~/.auditkit/cache. Combined with -offline, this lets you scan on a connected machine and produce reports on an air-gapped one.

# Report from the newest cached scan, no cloud API calls
auditkit scan -provider aws -framework soc2 -offline

# Report from a specific cache file
auditkit scan -offline -cache-file /path/to/scan.json

scan

Run a compliance scan against your cloud infrastructure.

auditkit scan [flags]

Examples:

# Basic scan (defaults to AWS, all frameworks)
auditkit scan

# Specify provider and framework
auditkit scan -provider aws -framework soc2
auditkit scan -provider azure -framework pci
auditkit scan -provider gcp -framework cmmc

# All frameworks
auditkit scan -framework all

# Verbose output
auditkit scan -verbose

# Show all controls (no truncation)
auditkit scan --full

Flags: - -provider - Cloud provider: aws, azure, gcp (default: aws) - -framework - Compliance framework: soc2, pci, cmmc, hipaa, gdpr, nist-csf, 800-53, iso27001, fedramp-low, fedramp-moderate, fedramp-high, cis, cis-aws, cis-azure, cis-gcp, all (default: all) - -verbose - Show detailed output - --full - Show all controls without truncation - -format - Output format: text, json, html, pdf, csv (default: text) - -output - Output file path (e.g., report.pdf) - -profile - AWS profile name (AWS only)

These exist only on the Pro binary. Passing them to Community Edition exits with flag provided but not defined:

integrate

Import results from third-party tools (Prowler, ScubaGear).

auditkit integrate -source [tool] -file [path] [flags]

Examples:

# Import Prowler results (AWS/Azure/GCP)
auditkit integrate -source prowler -file prowler-output.json

# Generate PDF from Prowler results
auditkit integrate -source prowler -file prowler-output.json -format pdf -output prowler-report.pdf

# Import ScubaGear results (M365)
auditkit integrate -source scubagear -file ScubaResults/ScubaResults.json

# Generate PDF from ScubaGear results
auditkit integrate -source scubagear -file ScubaResults.json -format pdf -output m365-report.pdf

Flags: - -source - Source tool: prowler, scubagear - -file - Path to results file - -format - Output format: text, json, pdf (default: text) - -output - Output file path

fix

Generate remediation scripts for failed controls.

auditkit fix [flags]

Examples:

# Generate fix script
auditkit fix

# Save to file
auditkit fix -output fixes.sh

# Review before running
cat fixes.sh
bash fixes.sh  # Run after review

Flags: - -output - Output file path (default: auditkit-<provider>-fixes.sh) - -provider - Cloud provider to re-scan; fix runs a fresh scan rather than reusing the last one (default: aws)

progress

Show compliance improvement over time.

auditkit progress

Output:

Compliance Progress Report
==========================
Framework: SOC2
Provider: AWS

Scan History:
2025-10-15: 65.0% (42/64 passed)
2025-10-18: 72.5% (46/64 passed)
2025-10-19: 78.1% (50/64 passed)

Improvement: +13.1% over 4 days
Trend: Increasing

compare

Compare the last two scans.

auditkit compare

Output:

Compliance Comparison
=====================
Framework: SOC2
Provider: AWS

Previous Scan: 2025-10-18 (72.5%)
Current Scan:  2025-10-19 (78.1%)

Improvements:
+ CC6.1 - IAM Key Rotation (now passing)
+ CC6.2 - S3 Public Access (now passing)
+ CC7.1 - CloudTrail Logging (now passing)
+ CC8.1 - Encryption at Rest (now passing)

New Failures:
- None

Score Change: +5.6%

evidence

Track the evidence an assessor will ask for. Auditors want evidence for every control, including the ones that pass, so this covers the whole scan rather than just failures.

Note: the tracker currently always runs the SOC2 control set. The -framework flag does not apply to this command.

auditkit evidence [flags]

Runs a scan, writes an HTML checklist, and records the controls in a durable tracker at ~/.auditkit/evidence_<account>.json. The checklist keeps ticks in your browser; the tracker is the copy you can share, review, or hand over.

Flags: - -provider - Cloud provider: aws, azure, gcp (default: aws) - -profile - AWS profile, Azure subscription, or GCP project - -output - Where to write the HTML checklist (default: evidence-tracker.html)

evidence status

Show what evidence has been collected, what is outstanding, and what has gone stale. Runs against the stored tracker, so it needs no cloud credentials.

auditkit evidence status [flags]

Flags: - -account - Account ID, if you track more than one - -stale-after - Days before collected evidence is considered stale (default: 90) - -all - List every outstanding control rather than the first 20

Evidence older than the staleness window is reported as outstanding rather than collected. Assessors sample evidence from within the period under review, so a screenshot from last year is not evidence.

evidence collect

Record that evidence has been captured for a control.

auditkit evidence collect CONTROL-ID [flags]

Examples:

auditkit evidence collect CC6.1 -notes "IAM policy export and console screenshot" -by rob
auditkit evidence collect CC7.2 -artifact ./evidence/cloudwatch-alarms.png

Flags: - -notes - What was captured and where it came from - -artifact - Path to the screenshot or export - -by - Who collected it - -account - Account ID, if you track more than one

evidence import

Load the JSON exported from the HTML checklist, so ticks made in the browser become part of the durable record.

auditkit evidence import PROGRESS.json [-by name]

Controls in the file that the scanner has not seen are reported and skipped.

update

Check for newer version of AuditKit.

auditkit update

Output:

Current version: v0.7.0
Latest version:  v0.7.1
Update available!

Download: https://github.com/guardian-nexus/AuditKit-Community-Edition/releases/tag/v0.7.1

version

Show AuditKit version.

auditkit version

Output:

AuditKit v1.0.0 - Multi-cloud compliance scanning (AWS, Azure, GCP; M365 via ScubaGear import)

Global Flags

These flags work with all commands:

Note: bare -h, --help, -v and --version are not recognised — they are treated as commands and print the usage block with an "Unknown command" warning.

Output Formats

text (default)

Human-readable terminal output with colors.

auditkit scan

json

Machine-readable JSON for automation.

auditkit scan -format json -output results.json

JSON Structure:

{
  "timestamp": "2025-10-19T14:30:00Z",
  "provider": "aws",
  "framework": "soc2",
  "account_id": "123456789012",
  "score": 72.5,
  "total_controls": 64,
  "passed_controls": 46,
  "failed_controls": 18,
  "controls": [
    {
      "id": "CC6.6",
      "name": "User MFA Enforcement",
      "status": "FAIL",
      "severity": "CRITICAL",
      "evidence": "12 users without MFA",
      "remediation": "Enable MFA for all users"
    }
  ]
}

html

HTML report with Failed, Passed and Manual tabs.

auditkit scan -format html -output report.html

pdf

Audit-ready PDF report for auditors and management.

auditkit scan -format pdf -output report.pdf

PDF includes: - Executive summary - Compliance score - Passed/failed controls - Evidence collection guides - Remediation commands - Compliance mappings

Environment Variables

AWS

AWS_ACCESS_KEY_ID          # AWS access key
AWS_SECRET_ACCESS_KEY      # AWS secret key
AWS_DEFAULT_REGION         # Default AWS region
AWS_PROFILE                # AWS CLI profile name

Azure

AZURE_CLIENT_ID            # Service principal client ID
AZURE_CLIENT_SECRET        # Service principal secret
AZURE_TENANT_ID            # Azure tenant ID
AZURE_SUBSCRIPTION_ID      # Subscription to scan

GCP

GOOGLE_APPLICATION_CREDENTIALS  # Path to service account JSON
GOOGLE_CLOUD_PROJECT            # GCP project ID
GCP_PROJECT                     # Alternative project ID variable

Exit Codes

AuditKit does not currently distinguish error classes by exit code. To branch on the result in CI, parse the JSON report rather than the exit status.

Examples by Use Case

Initial Assessment

# Run first scan
auditkit scan -provider aws -framework soc2 -verbose

# Generate PDF report for auditor
auditkit scan -provider aws -framework soc2 -format pdf -output initial-assessment.pdf

# Generate evidence tracker
auditkit evidence -format html -output evidence-tracker.html

Fix and Verify

# Generate fix script
auditkit fix -output fixes.sh

# Review and run fixes
cat fixes.sh
bash fixes.sh

# Re-scan to verify
auditkit scan -provider aws -framework soc2

# Compare improvements
auditkit compare

Multi-Cloud Scanning

# Scan all providers
auditkit scan -provider aws -framework soc2 -output aws-results.json -format json
auditkit scan -provider azure -framework soc2 -output azure-results.json -format json
auditkit scan -provider gcp -framework soc2 -output gcp-results.json -format json

# Generate individual reports
auditkit scan -provider aws -framework soc2 -format pdf -output aws-report.pdf
auditkit scan -provider azure -framework soc2 -format pdf -output azure-report.pdf
auditkit scan -provider gcp -framework soc2 -format pdf -output gcp-report.pdf

CI/CD Integration

# Run scan in pipeline
auditkit scan -provider aws -framework soc2 -format json -output results.json

# Check exit code
if [ $? -eq 0 ]; then
  echo "Scan completed successfully"
else
  echo "Scan failed"
  exit 1
fi

# Parse results
jq '.score' results.json  # Get compliance score
jq '.failed_controls' results.json  # Get failed control count

Progress Tracking

# Weekly scans
# Monday
auditkit scan -provider aws -framework soc2

# Friday (after fixes)
auditkit scan -provider aws -framework soc2

# Show progress
auditkit progress

# Compare before/after
auditkit compare

Pro-Only Features

These features require AuditKit:

Multi-Account Scanning

# Scan entire AWS Organization
auditkit-pro scan -provider aws -framework soc2 --scan-all

# Scan Azure Management Group
auditkit-pro scan -provider azure -framework soc2 --scan-all

# Scan GCP Organization
auditkit-pro scan -provider gcp -framework soc2 --scan-all

# Control concurrency
auditkit-pro scan -provider aws --scan-all --max-concurrent 5

CMMC Level 2

# Scan for CMMC Level 2 (110 practices)
auditkit-pro scan -provider aws -framework cmmc

# Generate Level 2 report
auditkit-pro scan -provider aws -framework cmmc -format pdf -output cmmc-l2-report.pdf

Advanced GCP

# Scan GKE clusters (Pro only)
auditkit-pro scan -provider gcp -framework soc2  # Includes GKE checks

# Scan Vertex AI (Pro only)
auditkit-pro scan -provider gcp -framework soc2  # Includes Vertex AI checks

Vulnerability Remediation Evidence

Both editions answer RA.L2-3.11.2 and PCI 11.3.1 from what Inspector, Defender for Cloud or VM Manager actually reaches. Pro adds remediation ageing (RA.L2-3.11.3), a configurable policy, third-party scan import and the vulnerability-management/ folder in the evidence package.

# Measure open findings against your own remediation windows
auditkit-pro scan -provider aws -framework cmmc -vuln-policy vuln-policy.yaml

# Evaluate a Nessus, Trivy or Grype report against the same policy
auditkit-pro integrate -source nessus -file scan.nessus
auditkit-pro integrate -source trivy -file trivy.json
auditkit-pro integrate -source grype -file grype.json

-vuln-policy is also read from ./vuln-policy.yaml, ~/.auditkit/ and /etc/auditkit/. Without one, the built-in policy applies: critical within 30 days, high 90, medium 180, and a scan is stale after 30. The report names the policy it measured against.

Getting Help