Skip to main content

netaudit

CI PyPI Python License: Apache 2.0

CI-native network egress auditing via strace. Wrap any process or test suite, declare what connections are allowed, get pass/fail — no raw strace noise.

Install

pip install netaudit

Requires strace (Linux only):

sudo apt-get install strace   # Debian/Ubuntu
sudo dnf install strace       # RHEL/Fedora

Or use the Docker image — strace is pre-installed.

Quick start

  1. Create netaudit.yaml in your project root:
version: 1
allowlist:
  - name: "Internal API"
    family: AF_INET
    addr: 10.0.0.1
    port: 8080
  1. Run:
# Trace any command and fail on unexpected connections
netaudit run -- pytest
netaudit run -- curl https://example.com
netaudit run -- ./my-service --port 8080

# Show all network calls annotated with the matching rule name
# Everything after -- is the wrapped command
netaudit run --verbose -- pytest tests/

# Offline analysis of an existing strace log
netaudit analyze /tmp/trace.log

# Machine-readable output for CI artifacts
netaudit run --format json -- make test

Exit codes: 0 clean · 1 violations · 2 strace not found

pytest plugin

Enable automatic auditing of your test suite without changing any test code:

# pyproject.toml
[tool.netaudit]
enabled = true
allowlist = "netaudit.yaml"
pytest --netaudit                # fail session on violations
pytest --netaudit --netaudit-verbose  # show every connection per test

Violations are attributed to the individual test that triggered them.

Docker

No local strace install needed:

docker pull ghcr.io/cybersecauto-labs/netaudit:latest

docker run --rm --cap-add SYS_PTRACE \
  -v "$(pwd)/netaudit.yaml:/netaudit.yaml" \
  ghcr.io/cybersecauto-labs/netaudit \
  run --allowlist /netaudit.yaml -- curl https://example.com

Documentation

Full docs at netaudit.readthedocs.io:

How it works

netaudit run spawns your command under strace -e trace=connect -f -tt, parses every connect() syscall, and checks each against your allowlist. Built-in rules automatically permit loopback, Unix sockets, and AF_NETLINK — you only need to list external destinations.

Development

python3.11 -m venv .venv
.venv/bin/pip install -e ".[dev]"
.venv/bin/pytest

See Contributing for the full guide.

Metadata

Release files for netaudit 0.5.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for netaudit 0.5.0
File Size Uploaded
netaudit-0.5.0.tar.gz 37.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for netaudit 0.5.0
File Interpreter ABI Platform
netaudit-0.5.0-py3-none-any.whl Python 3 none any Details

Total release size: 61.0 kB

Release files / netaudit-0.5.0.tar.gz

Download URL netaudit-0.5.0.tar.gz
Size 37.6 kB
Tags Source
SHA-256 checksum
How to use checksums
c926ff3ba7a9b078dde17ef2af82ac0cceffd418734da23478f21d7d99e0213c
BLAKE2b-256 checksum
How to use checksums
331b1f27d2c11ca58231dad08389d5cc142565752dcfb1033edbdc5084c7de8b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 1, 2026.

Transparency log

Release files / netaudit-0.5.0-py3-none-any.whl

Download URL netaudit-0.5.0-py3-none-any.whl
Size 23.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
018e242a7f6e386b99bf4287f3ced7b1aaaf4fc26d899189383de621e6765f9f
BLAKE2b-256 checksum
How to use checksums
656596ec05d21fe24f13194cc6d94caa67e6f66d490cfabac944bcf12394bd77
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 1, 2026.

Transparency log

Release history Release notifications | RSS feed

0.6.1

2 release files

This release

0.5.0 This release

2 release files

0.4.1

2 release files

0.4.0

2 release files

0.3.0

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page