#audit
7 one-liners with this tag.
All one-liners tagged audit
Find world-writable files and directories
$find /var/www/vhosts -xdev -perm -0002 ! -type l -ls 2>/dev/null
List all SSH keys authorized on the server
#find / -xdev -path '*/.ssh/authorized_keys' -type f -exec awk 'NF && !/^#/ {print FILENAME ": " $NF}' {} + 2>/dev/null
List user accounts with a login shell
$awk -F: '$7 !~ /(nologin|false)$/ {print $1, $3, $6, $7}' /etc/passwd
Show commands run with sudo from the journal
#journalctl _COMM=sudo --since "7 days ago" --no-pager | grep 'COMMAND='
Show recent server logins with IP address
$last -i | head -30
Show successful SSH logins from the journal
#journalctl -u ssh --since "7 days ago" --no-pager | grep 'Accepted'
Show the password status of all user accounts
#passwd -S -a