vulkro-sf org audit-trail
Every live-org command (vulkro-sf org ...) is part of Pro: Live-org audit (sf-live-org), permissions, session, MFA, sharing, packages and trust, read from the org itself. On Free it stops before doing any work, prints what it needs and where to get it, and exits 1. See Pricing.
Tracks privilege escalation through SetupAuditTrail
(SF-AUDIT-TRAIL-001 / -002).
SetupAuditTrail is the org's record of who changed what in Setup. This command reads the recent window and reports the two shapes that matter after an account compromise: a permission being escalated, and Setup being edited outside normal hours.
Synopsis
vulkro-sf org audit-trail --target-org <alias> [flags]
Flags
| Flag | Type | Default | Description |
|---|---|---|---|
--target-org, -o <alias> | string | (required) | Target org alias or username, as known to sf org login. |
--format <fmt> | enum | table | Output format. |
--check-apt-playbooks | flag | off | Also walk the SetupAuditTrail plus AuthSession timeline against the bundled APT TTP playbooks. Equivalent to setting VULKRO_SF_APT_PLAYBOOKS=1. |
--verbose, -v | flag | off | Bump stderr log verbosity. -v enables debug-level tracing for the vulkro + vulkro_sf targets; -vv enables trace. Honoured only when RUST_LOG is unset (an explicit RUST_LOG always wins). |
What gets read
SetupAuditTrail rows: CreatedDate, Action, Section,
CreatedBy.Name, Display, most recent first, capped at the latest
1000 rows.
SF-AUDIT-TRAIL-001 evaluates against a 30-day window.
SF-AUDIT-TRAIL-002 evaluates every row the query returns, regardless of
age, so it can flag an out-of-hours Setup edit older than 30 days.
What gets reported
| Rule | Severity | Signal |
|---|---|---|
SF-AUDIT-TRAIL-001 | High | audit-trail-privilege-escalation |
SF-AUDIT-TRAIL-002 | Medium | audit-trail-out-of-hours-edit |
APT playbook walk (optional)
Passing --check-apt-playbooks (or setting
VULKRO_SF_APT_PLAYBOOKS=1) also walks the SetupAuditTrail plus
AuthSession timeline against the APT TTP playbooks bundled into the
binary: APT-CRED-EXFIL-001, APT-DATA-EXFIL-002,
APT-PRIV-ESC-003, APT-LATERAL-MOVE-004, and
APT-PERSISTENCE-005. Findings append to the SF-AUDIT-TRAIL-001 /
-002 output.
The environment variable is honoured so non-interactive CI runs do not need to add the flag to every job spec.
A playbook match means the recent timeline resembles a known tactic sequence. It is a lead for a human responder, not an attribution and not a confirmed compromise.
Examples
vulkro-sf org audit-trail --target-org my-prod
# Include the APT TTP playbook walk.
vulkro-sf org audit-trail -o my-prod --check-apt-playbooks
# Same, driven by environment for a CI job.
VULKRO_SF_APT_PLAYBOOKS=1 vulkro-sf org audit-trail -o my-prod --format json
Exit codes
0- no findings.1- findings reported.2- error.
Scope and honesty
The org is read locally through your own authenticated sf CLI login;
nothing is sent anywhere, and the playbook bundle ships inside the
binary rather than being fetched.
The window is the latest 1000 SetupAuditTrail rows. In a busy org, older changes fall out of that window, so a quiet run is not evidence that no escalation occurred. Findings are pattern signals over an audit log, not runtime-validated exploits, and nothing here certifies an org uncompromised.
Where to go next
- vulkro-sf org forensic-snapshot - capture the full identity and sharing state for offline analysis.
- vulkro-sf org login-history - the logins that preceded these changes.
- vulkro-sf org event-monitoring - Shield event-log anomalies.