{"id":19260405,"url":"https://github.com/mitre/systeminspector","last_synced_at":"2025-04-21T16:31:49.638Z","repository":{"id":69082726,"uuid":"81118205","full_name":"mitre/SystemInspector","owner":"mitre","description":"SystemInspector is a script to pull a majority of the security-relevant files and settings from a system.","archived":false,"fork":false,"pushed_at":"2018-05-22T18:08:24.000Z","size":108,"stargazers_count":18,"open_issues_count":0,"forks_count":4,"subscribers_count":4,"default_branch":"master","last_synced_at":"2025-04-01T14:37:23.661Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"Shell","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/mitre.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2017-02-06T18:30:31.000Z","updated_at":"2024-11-24T16:05:31.000Z","dependencies_parsed_at":"2023-02-26T18:15:16.037Z","dependency_job_id":null,"html_url":"https://github.com/mitre/SystemInspector","commit_stats":null,"previous_names":[],"tags_count":1,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mitre%2FSystemInspector","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mitre%2FSystemInspector/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mitre%2FSystemInspector/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mitre%2FSystemInspector/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/mitre","download_url":"https://codeload.github.com/mitre/SystemInspector/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":250090924,"owners_count":21373279,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-11-09T19:20:48.927Z","updated_at":"2025-04-21T16:31:49.621Z","avatar_url":"https://github.com/mitre.png","language":"Shell","funding_links":[],"categories":[],"sub_categories":[],"readme":"## SystemInspector for Enterprise Linux ##\n\nSystem Inspector for Enterprise Linux is designed to pull some of the most of the security-relevant files and \ninformation from a Linux system; current versions supported are Red Hat Enterprise Linux 6 and 7 and \nCentOS 6 and 7. Items such as iptables may differ between the output of the running configuration  and the \nsaved configuration in /etc/sysconfig/iptables, so System Inspector pulls both in order for the user to \nevaluate such conditions.\n\nIf you would like to use System Inspector to its full potential, please download the Unix Privilege Escalation\nCheck zip file from the following link and save the `unix-privesc-check-1_x` folder into the root of \nthe `system-inspector-el[x]` folder. Note that there will probably be a `unix-privesc-check-1_x` folder within a folder of the same name, move the second folder to the `SystemInspector` directory: https://github.com/pentestmonkey/unix-privesc-check/tree/1_x\n\n## Requirements ## \n1. Run as root\n2. Set SELinux to Permissive\n3. OpenSCAP installation (openscap-scanner and scap-security-guide)\n4. python \u003e= 2.x (if running repochk)\n\n## How to Operate ##\nIf the system is able to connect to the Internet, the user needs to run the following to clone the repo correctly, which will clone SystemInspector, repochk, and FindRogueElfs: `git clone --recursive https://github.com/mitre/SystemInspector.git`\n\nIf the system is not able to connect to the Internet, the user needs to download the .zip file from GitHub, extract the contents, and manually bring the files to the system (i.e. via CD/DVD, USB, etc.). If the user plans to run repochk, the `update_repo.sh` script needs to be run on a system with Internet access. The output of that script should then be placed in the `repochk` directory on the system to be inspected. If the system does not have Python \u003e= 2.x, repochk will not work. \n\nIn the root directory of system-inspector-el[x], run the `inspect.sh` shell script. The user will be prompted to run the tool in either offline or online mode.\n\nOnce the scan is complete, everything will be dumped into a `results/` folder and then into a gzipped tarball; the `results/` folder will be deleted for ease of use. \n\n***DO NOT FORGET TO REMOVE THE FILES FROM THE SYSTEM WHEN FINISHED.*** \n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmitre%2Fsysteminspector","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fmitre%2Fsysteminspector","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmitre%2Fsysteminspector/lists"}