netaudit
CI-native network egress auditing via strace. Wrap any process or test suite, declare what connections are allowed, get pass/fail — no raw strace noise.
Install
pip install netaudit
Requires strace (Linux only):
sudo apt-get install strace # Debian/Ubuntu
sudo dnf install strace # RHEL/Fedora
Or use the Docker image — strace is pre-installed.
Quick start
- Create
netaudit.yamlin your project root:
version: 1
allowlist:
- name: "Internal API"
family: AF_INET
addr: 10.0.0.1
port: 8080
- Run:
# Trace any command and fail on unexpected connections
netaudit run -- pytest
netaudit run -- curl https://example.com
netaudit run -- ./my-service --port 8080
# Show all network calls annotated with the matching rule name
# Everything after -- is the wrapped command
netaudit run --verbose -- pytest tests/
# Offline analysis of an existing strace log
netaudit analyze /tmp/trace.log
# Machine-readable output for CI artifacts
netaudit run --format json -- make test
Exit codes: 0 clean · 1 violations · 2 strace not found
pytest plugin
Enable automatic auditing of your test suite without changing any test code:
# pyproject.toml
[tool.netaudit]
enabled = true
allowlist = "netaudit.yaml"
pytest --netaudit # fail session on violations
pytest --netaudit --netaudit-verbose # show every connection per test
Violations are attributed to the individual test that triggered them.
Docker
No local strace install needed:
docker pull ghcr.io/cybersecauto-labs/netaudit:latest
docker run --rm --cap-add SYS_PTRACE \
-v "$(pwd)/netaudit.yaml:/netaudit.yaml" \
ghcr.io/cybersecauto-labs/netaudit \
run --allowlist /netaudit.yaml -- curl https://example.com
Documentation
Full docs at netaudit.readthedocs.io:
How it works
netaudit run spawns your command under strace -e trace=connect -f -tt, parses every
connect() syscall, and checks each against your allowlist. Built-in rules automatically
permit loopback, Unix sockets, and AF_NETLINK — you only need to list external destinations.
Development
python3.11 -m venv .venv
.venv/bin/pip install -e ".[dev]"
.venv/bin/pytest
See Contributing for the full guide.
Metadata
Release files for netaudit 0.5.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| netaudit-0.5.0.tar.gz | 37.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| netaudit-0.5.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 61.0 kB
Release files / netaudit-0.5.0.tar.gz
| Download URL | netaudit-0.5.0.tar.gz |
|---|---|
| Size | 37.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
c926ff3ba7a9b078dde17ef2af82ac0cceffd418734da23478f21d7d99e0213c
|
|
BLAKE2b-256 checksum How to use checksums |
331b1f27d2c11ca58231dad08389d5cc142565752dcfb1033edbdc5084c7de8b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 1, 2026.
Transparency logRelease files / netaudit-0.5.0-py3-none-any.whl
| Download URL | netaudit-0.5.0-py3-none-any.whl |
|---|---|
| Size | 23.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
018e242a7f6e386b99bf4287f3ced7b1aaaf4fc26d899189383de621e6765f9f
|
|
BLAKE2b-256 checksum How to use checksums |
656596ec05d21fe24f13194cc6d94caa67e6f66d490cfabac944bcf12394bd77
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 1, 2026.
Transparency log