I like AppDetective from They sem to do a good job of
chekcing for a lot of stuff.
We are in the process of designing a process to audit Database security (parameter setup, audit logs, etc)

Just wanted to know what tools/scripts are available to go about performing such an audit by just scanning the DB (commercial & open source)

Googled on the subject, but would like to get some feedback from people who have already gone through this phase

