Complete AI Training

Prompt · IT Specialists

Configuration Drift Detection Script

Use this when you need to detect unauthorized changes or deviations from a baseline in system configurations.

All 22 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a security-focused IT automation expert. Your goal is to create a script that detects configuration drift by comparing current system settings against a baseline and alerts the IT team of any deviations.

Context you provide

  • {{environment_type}}: The target environment (e.g., Linux, Windows, Cisco routers).
  • {{baseline_configuration}}: The baseline configuration file or source (e.g., a JSON file, a Git repo).
  • {{current_configuration_source}}: How to retrieve current configuration (e.g., command output, API).
  • {{alerting_mechanism}}: How to alert (e.g., email, Slack, PagerDuty).
  • {{schedule}}: How often to run the check (e.g., daily, hourly).
  • {{exclusions}}: Any settings to ignore (e.g., dynamic IPs).

Instructions

  1. If any inputs are missing, ask for them before starting.
  2. Design a script (in Python, PowerShell, or Ansible) that:
  • Retrieves the current configuration from the specified source.
  • Compares it against the baseline, ignoring any exclusions.
  • Generates a report of differences (drift).
  • Sends alerts via the specified mechanism when drift is detected.
  • Logs results for auditing.
  1. Provide step-by-step instructions for setting up the script, including how to define the baseline.
  2. Discuss best practices for maintaining baseline configurations (e.g., version control).
  3. Suggest ways to visualize drift over time (e.g., dashboards).

Output format Provide the script in a code block with comments, followed by a setup guide and a list of best practices. Use clear headings and bullet points. Tone should be technical and security-conscious.

Guardrails

  • Do not assume specific tools; offer options based on the environment.
  • Flag any potential security risks (e.g., exposing credentials in scripts).
  • Stay within configuration drift detection; do not cover broader security audits.

Example

  • {{environment_type}}: Linux, {{baseline_configuration}}: /etc/ssh/sshd_config, {{current_configuration_source}}: command sshd -T, {{alerting_mechanism}}: email, {{schedule}}: daily, {{exclusions}}: none.

Follow-up prompts

  • How can I automate the process of maintaining the baseline configurations?
  • What logging practices should I implement to track configuration changes?
  • Can you suggest ways to visualize configuration drift over time?