Complete installation instructions for AuditKit.

System Requirements

Operating Systems: - Linux (any modern distribution) - macOS (10.15 Catalina or newer) - Windows (10/11 or Server 2016+)

Requirements: - Go 1.24 or newer (for building from source) - Cloud CLI tools (AWS CLI, Azure CLI, or gcloud CLI) - Read-only cloud credentials - Internet connection (for downloading and scanning)

Disk Space: - Universal binary (all clouds): ~64 MB download, ~325 MB installed - Source code: ~50 MB - Scan results: ~1-10 MB per scan

Installation Methods

Option 1: Download Pre-Built Binary (Recommended)

Fastest and easiest method

Linux (x86_64)

# Download and extract
curl -LO https://github.com/guardian-nexus/AuditKit-Community-Edition/releases/latest/download/auditkit-linux-amd64.tar.gz
tar -xzf auditkit-linux-amd64.tar.gz

# Move to PATH
sudo mv auditkit-linux-amd64 /usr/local/bin/auditkit
sudo chmod +x /usr/local/bin/auditkit

# Verify installation
auditkit version

Linux (ARM64)

For AWS Graviton, Raspberry Pi, and Linux VMs on Apple Silicon Macs.

# Download and extract
curl -LO https://github.com/guardian-nexus/AuditKit-Community-Edition/releases/latest/download/auditkit-linux-arm64.tar.gz
tar -xzf auditkit-linux-arm64.tar.gz

# Move to PATH
sudo mv auditkit-linux-arm64 /usr/local/bin/auditkit
sudo chmod +x /usr/local/bin/auditkit

# Verify installation
auditkit version

macOS (Apple Silicon)

# Download and extract
curl -LO https://github.com/guardian-nexus/AuditKit-Community-Edition/releases/latest/download/auditkit-darwin-arm64.tar.gz
tar -xzf auditkit-darwin-arm64.tar.gz

# Move to PATH
sudo mv auditkit-darwin-arm64 /usr/local/bin/auditkit
sudo chmod +x /usr/local/bin/auditkit

# The binary is unsigned. If macOS blocks it on first run:
# System Settings -> Privacy and Security -> Open Anyway

# Verify installation
auditkit version

macOS (Intel)

# Download and extract
curl -LO https://github.com/guardian-nexus/AuditKit-Community-Edition/releases/latest/download/auditkit-darwin-amd64.tar.gz
tar -xzf auditkit-darwin-amd64.tar.gz

# Move to PATH
sudo mv auditkit-darwin-amd64 /usr/local/bin/auditkit
sudo chmod +x /usr/local/bin/auditkit

# Verify installation
auditkit version

Windows

# Download and extract
curl.exe -LO https://github.com/guardian-nexus/AuditKit-Community-Edition/releases/latest/download/auditkit-windows-amd64.zip
Expand-Archive -Path auditkit-windows-amd64.zip -DestinationPath .

# Rename to auditkit.exe
Rename-Item auditkit-windows-amd64.exe auditkit.exe

# Add to PATH or run from current directory
.\auditkit.exe version

Option 2: Build from Source

For developers or custom builds

Prerequisites

# Install Go 1.24 or newer
# Download from: https://go.dev/dl/

# Verify Go installation
go version  # Should show 1.24 or higher

Clone and Build

# Clone repository
git clone https://github.com/guardian-nexus/AuditKit-Community-Edition
cd AuditKit-Community-Edition/scanner

# Build binary
go build ./cmd/auditkit

# Binary is now at: ./auditkit

# Optional: Move to PATH
sudo mv auditkit /usr/local/bin/

# Verify installation
auditkit version

Build for Different Platforms

# Linux (amd64)
GOOS=linux GOARCH=amd64 go build -o auditkit-linux ./cmd/auditkit

# macOS (amd64)
GOOS=darwin GOARCH=amd64 go build -o auditkit-macos ./cmd/auditkit

# macOS (arm64 - M1/M2)
GOOS=darwin GOARCH=arm64 go build -o auditkit-macos-arm64 ./cmd/auditkit

# Windows (amd64)
GOOS=windows GOARCH=amd64 go build -o auditkit.exe ./cmd/auditkit

Option 3: Go Install

For Go users

# Install directly from GitHub
go install github.com/guardian-nexus/AuditKit-Community-Edition/scanner/cmd/auditkit@latest

# Binary installed to: $GOPATH/bin/auditkit

# Add GOPATH/bin to PATH if needed
export PATH=$PATH:$(go env GOPATH)/bin

# Verify installation
auditkit version

Installing Cloud CLI Tools

AuditKit requires cloud CLI tools for authentication.

AWS CLI

Linux/macOS:

# Option 1: Using package manager
# macOS
brew install awscli

# Ubuntu/Debian
sudo apt-get install awscli

# Option 2: Using pip
pip3 install awscli

# Verify installation
aws --version

Windows:

# Download installer from:
# https://aws.amazon.com/cli/

# Or using Chocolatey
choco install awscli

# Verify installation
aws --version

AWS Setup Guide →

Azure CLI

Linux/macOS:

# macOS
brew install azure-cli

# Ubuntu/Debian
curl -sL https://aka.ms/InstallAzureCLIDeb | sudo bash

# Verify installation
az --version

Windows:

# Download installer from:
# https://docs.microsoft.com/cli/azure/install-azure-cli-windows

# Or using Chocolatey
choco install azure-cli

# Verify installation
az --version

Azure Setup Guide →

Google Cloud SDK

Linux/macOS:

# macOS
brew install google-cloud-sdk

# Linux - using snap
sudo snap install google-cloud-cli --classic

# Or download from:
# https://cloud.google.com/sdk/docs/install

# Verify installation
gcloud --version

Windows:

# Download installer from:
# https://cloud.google.com/sdk/docs/install

# Or using Chocolatey
choco install gcloudsdk

# Verify installation
gcloud --version

GCP Setup Guide →

Verifying Installation

Check AuditKit Version

auditkit version

Expected output:

AuditKit v1.0.0 - Multi-cloud compliance scanning (AWS, Azure, GCP; M365 via ScubaGear import)

Check Cloud CLI Tools

# AWS
aws --version

# Azure
az --version

# GCP
gcloud --version

Run Test Scan

# Test AWS (requires configured credentials)
auditkit scan -provider aws -framework soc2

# Test Azure (requires login)
auditkit scan -provider azure -framework soc2

# Test GCP (requires auth)
auditkit scan -provider gcp -framework soc2

Configuration

Setting Up Cloud Credentials

AWS:

aws configure
# Enter: Access Key ID, Secret Access Key, Region

Azure:

az login
export AZURE_SUBSCRIPTION_ID="your-subscription-id"

GCP:

gcloud auth application-default login
export GOOGLE_CLOUD_PROJECT=your-project-id

Detailed setup guides →

Updating AuditKit

Check for Updates

auditkit update

Update Binary Installation

# Download new version
curl -LO https://github.com/guardian-nexus/AuditKit-Community-Edition/releases/latest/download/auditkit-linux-amd64.tar.gz

# Replace old binary
chmod +x auditkit-linux-amd64
sudo mv auditkit-linux-amd64 /usr/local/bin/auditkit

# Verify new version
auditkit version

Update Source Installation

cd AuditKit-Community-Edition
git pull origin main
cd scanner
go build ./cmd/auditkit
sudo mv auditkit /usr/local/bin/

Update Go Install

go install github.com/guardian-nexus/AuditKit-Community-Edition/scanner/cmd/auditkit@latest

Troubleshooting Installation

"Command not found: auditkit"

Cause: Binary not in PATH

Solution:

# Find where binary is located
which auditkit

# If not found, add to PATH
export PATH=$PATH:/path/to/auditkit/directory

# Or move to standard location
sudo mv auditkit /usr/local/bin/

"Permission denied" when running auditkit

Cause: Binary not executable

Solution:

chmod +x auditkit

macOS "cannot be opened because the developer cannot be verified"

Cause: macOS Gatekeeper security

Solution:

# Remove quarantine attribute
xattr -d com.apple.quarantine auditkit

# Or: System Preferences > Security & Privacy > Allow

Build errors with Go

Cause: Go version too old or dependencies missing

Solution:

# Update Go to 1.24 or newer
go version

# Clean build cache
go clean -cache -modcache

# Rebuild
go build ./cmd/auditkit

"Cannot connect to AWS/Azure/GCP"

Cause: Cloud CLI not installed or not configured

Solution:

# Install cloud CLI tools (see above)
# Configure credentials (see setup guides)

# Test cloud CLI directly
aws sts get-caller-identity  # AWS
az account show              # Azure
gcloud projects list         # GCP

Uninstalling AuditKit

Remove Binary

# Find installation location
which auditkit

# Remove binary
sudo rm /usr/local/bin/auditkit

Remove Source Installation

# Remove cloned repository
rm -rf ~/auditkit

# Remove Go binary (if installed via go install)
rm $(go env GOPATH)/bin/auditkit

Clean Up Scan Results

# Remove scan history (if you want to)
rm -rf ~/.auditkit/

Advanced Installation

Installing in Air-Gapped Environment

For environments without internet access:

AuditKit can scan on a connected machine and report on a disconnected one. Every scan is cached under ~/.auditkit/cache; auditkit cache lists what is stored, and auditkit scan -offline (optionally -cache-file <path>) rebuilds a report with no cloud API calls.

  1. Download binary on internet-connected machine:
curl -LO https://github.com/guardian-nexus/AuditKit-Community-Edition/releases/latest/download/auditkit-linux-amd64.tar.gz
  1. Transfer to air-gapped machine via USB/secure transfer

  2. Install normally:

chmod +x auditkit-linux-amd64
sudo mv auditkit-linux-amd64 /usr/local/bin/auditkit

Note: Cloud CLI tools must also be installed offline

Installing for Multiple Users

System-wide installation:

# Install to /usr/local/bin (all users can access)
sudo cp auditkit /usr/local/bin/
sudo chmod 755 /usr/local/bin/auditkit

# Verify all users can run
su - otheruser -c "auditkit version"

Custom Installation Directory

# Install to custom location
mkdir -p ~/tools
cp auditkit ~/tools/

# Add to PATH in shell profile
echo 'export PATH=$PATH:$HOME/tools' >> ~/.bashrc
source ~/.bashrc

# Verify
auditkit version

Pro Version Installation

For AuditKit customers:

  1. Sign up for trial →
  2. Receive .lic license file via email
  3. Download Pro binary from customer portal
  4. Save your license file and run:
# Install Pro binary (note: different binary name)
chmod +x auditkit-pro
sudo mv auditkit-pro /usr/local/bin/auditkit-pro

# Save license file (received after purchase/trial signup)
mkdir -p ~/.auditkit-pro
cp ~/Downloads/license.lic ~/.auditkit-pro/license.lic

# Activation is automatic on first run — no separate command needed
auditkit-pro version  # Shows "Pro" edition

# Run Pro scans
auditkit-pro scan -provider aws -framework cmmc

Note: Pro version uses auditkit-pro command, not auditkit

Pro feature details →

Next Steps