← All Apps
VS Code Audit Add-on icon

VS Code Audit Add-on

Splunk Enterprise and Splunk Cloud

Brings VS Code extensions, settings, workspace files and remote development sessions into Splunk for security and operational monitoring.

Download on Splunkbase ↗Get Help Setting It Up

Overview

Developer workstations hold source code, credentials and access to core infrastructure, and VS Code is where that work happens. Malicious extensions, auto-running workspace files and agentic Ai settings have turned the editor into an attack surface most security teams can't see.

The VS Code Audit Add-on brings that visibility into Splunk: installed extensions, settings, workspace files that can run code, and remote development sessions, on Windows and macOS.

Features

  • Extension inventory for client and server extensions, with install source, dependencies, trust mode and pinned versions
  • User settings.json and argv.json startup arguments
  • Per-project .vscode/settings.json, tasks.json, launch.json and devcontainer.json
  • Remote sessions over SSH, WSL, attached containers and dev containers, with host, user and auth method
  • Installation inventory across VS Code, Insiders, VSCodium, Code-OSS, Cursor and Windsurf
  • Windows batch and macOS shell scripts with zero dependencies
  • Never collects API keys, secrets or credentials, and makes no network calls

Use Cases

  • Baseline VS Code configuration and extension posture across engineering teams
  • Detect risky agentic Ai settings, including global auto-approve
  • Investigate supply chain incidents tied to malicious Marketplace or OpenVSX extensions
  • Compare installed extensions against allow and deny lists
  • Catch configuration and extension drift between users, projects and environments
  • See local versus remote development across SSH, WSL and containers, and surface unapproved environments

Get Started

  1. Download the add-on from Splunkbase.
  2. Install it on Universal Forwarders to collect, on heavy forwarders or indexers for routing, and on search heads for field extraction.
  3. Set the index and interval in inputs.conf (3600 seconds recommended) and enable one scripted input per forwarder.
  4. Restart the forwarders, then search sourcetype=vscode:*.
← Back to All Apps

Details

Version

v1.0.0 · Dec 2025

Works with

Splunk Enterprise and Splunk Cloud

Questions or a Custom Version?

The engineers who built it can help you deploy it, tune it to your environment, or build what you need next.

Talk to Our Team →

Need Help Getting It Running?

We can deploy it across your organization, tune it to your environment, or build something new around it.

Book a Call →