VS Code Audit Add-on
Splunk Enterprise and Splunk Cloud
Brings VS Code extensions, settings, workspace files and remote development sessions into Splunk for security and operational monitoring.
@@shots https://cdn.prod.website-files.com/654c082e33faa8130383d311/6ac9e9e2be08e27a23436b41_vsc-1-extensions.webp | Splunk event listing installed VS Code extensions with publisher, version, install source and trust mode ;; https://cdn.prod.website-files.com/654c082e33faa8130383d311/6ac9e9e2c913829d3083bdb0_vsc-2-settings.webp | VS Code settings.json collected into Splunk, with the global auto-approve and agent request settings highlighted ;; https://cdn.prod.website-files.com/654c082e33faa8130383d311/6ac9e9e27e711878fa26a385_vsc-3-sessions.webp | Remote development sessions in Splunk: WSL, an attached container and SSH, with host, user and auth method ;; https://cdn.prod.website-files.com/654c082e33faa8130383d311/6ac9e9e27e711878fa26a398_vsc-4-cli.webp | vscode_audit.sh help output listing its nine sourcetypes and collection options @@specs Splunk versions | 9.0 to 10.6 ;; Endpoints | Windows 7+ and macOS 10.13+ ;; VS Code | 1.70 and later ;; Deployment | Standalone and distributed ;; Sourcetypes | Nine, from vscode:settings to vscode:sessions ;; Secrets collected | None ;; Dependencies | None ;; Release notes | v1.0.0 on GitHub -> https://github.com/zuykn/TA-vscode_audit/releases/tag/v1.0.0
Overview
Developer workstations hold source code, credentials and access to core infrastructure, and VS Code is where that work happens. Malicious extensions, auto-running workspace files and agentic Ai settings have turned the editor into an attack surface most security teams can't see.
The VS Code Audit Add-on brings that visibility into Splunk: installed extensions, settings, workspace files that can run code, and remote development sessions, on Windows and macOS.
Features
- Extension inventory for client and server extensions, with install source, dependencies, trust mode and pinned versions
- User settings.json and argv.json startup arguments
- Per-project .vscode/settings.json, tasks.json, launch.json and devcontainer.json
- Remote sessions over SSH, WSL, attached containers and dev containers, with host, user and auth method
- Installation inventory across VS Code, Insiders, VSCodium, Code-OSS, Cursor and Windsurf
- Windows batch and macOS shell scripts with zero dependencies
- Never collects API keys, secrets or credentials, and makes no network calls
Use Cases
- Baseline VS Code configuration and extension posture across engineering teams
- Detect risky agentic Ai settings, including global auto-approve
- Investigate supply chain incidents tied to malicious Marketplace or OpenVSX extensions
- Compare installed extensions against allow and deny lists
- Catch configuration and extension drift between users, projects and environments
- See local versus remote development across SSH, WSL and containers, and surface unapproved environments
Get Started
- Download the add-on from Splunkbase.
- Install it on Universal Forwarders to collect, on heavy forwarders or indexers for routing, and on search heads for field extraction.
- Set the index and interval in inputs.conf (3600 seconds recommended) and enable one scripted input per forwarder.
- Restart the forwarders, then search sourcetype=vscode:*.
Details
Version
v1.0.0 · Dec 2025
Works with
Splunk Enterprise and Splunk Cloud
Questions or a Custom Version?
The engineers who built it can help you deploy it, tune it to your environment, or build what you need next.
Talk to Our Team →Need Help Getting It Running?
We can deploy it across your organization, tune it to your environment, or build something new around it.
Book a Call →