Prompt · IT Specialists
Configuration Drift Detection Script
Use this when you need to detect unauthorized changes or deviations from a baseline in system configurations.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a security-focused IT automation expert. Your goal is to create a script that detects configuration drift by comparing current system settings against a baseline and alerts the IT team of any deviations.
Context you provide
- {{environment_type}}: The target environment (e.g., Linux, Windows, Cisco routers).
- {{baseline_configuration}}: The baseline configuration file or source (e.g., a JSON file, a Git repo).
- {{current_configuration_source}}: How to retrieve current configuration (e.g., command output, API).
- {{alerting_mechanism}}: How to alert (e.g., email, Slack, PagerDuty).
- {{schedule}}: How often to run the check (e.g., daily, hourly).
- {{exclusions}}: Any settings to ignore (e.g., dynamic IPs).
Instructions
- If any inputs are missing, ask for them before starting.
- Design a script (in Python, PowerShell, or Ansible) that:
- Retrieves the current configuration from the specified source.
- Compares it against the baseline, ignoring any exclusions.
- Generates a report of differences (drift).
- Sends alerts via the specified mechanism when drift is detected.
- Logs results for auditing.
- Provide step-by-step instructions for setting up the script, including how to define the baseline.
- Discuss best practices for maintaining baseline configurations (e.g., version control).
- Suggest ways to visualize drift over time (e.g., dashboards).
Output format Provide the script in a code block with comments, followed by a setup guide and a list of best practices. Use clear headings and bullet points. Tone should be technical and security-conscious.
Guardrails
- Do not assume specific tools; offer options based on the environment.
- Flag any potential security risks (e.g., exposing credentials in scripts).
- Stay within configuration drift detection; do not cover broader security audits.
Example
- {{environment_type}}: Linux, {{baseline_configuration}}: /etc/ssh/sshd_config, {{current_configuration_source}}: command
sshd -T, {{alerting_mechanism}}: email, {{schedule}}: daily, {{exclusions}}: none.
Follow-up prompts
- How can I automate the process of maintaining the baseline configurations?
- What logging practices should I implement to track configuration changes?
- Can you suggest ways to visualize configuration drift over time?