dotfiles/.local/bin/audit-users
2026-08-15 19:39:06 +01:00

22 lines
720 B
Bash
Executable file

#!/usr/bin/env bash
# COLOURS
cyan='\033[0;36m'
nc='\033[0m'
# USER AUDIT
printf "${cyan}AUTHORISED HUMAN USERS${nc}\n"
printf "%-12s %-6s %-15s %-30s %s\n" "user" "uid" "shell" "groups" "last login"
# filter for uids between 1000 and 60000
awk -F: '$3 >= 1000 && $3 < 60000 {print $1}' /etc/passwd | while read -r user; do
uid=$(id -u "$user")
groups=$(groups "$user" | cut -d: -f2 | xargs)
shell=$(getent passwd "$user" | cut -d: -f7)
# parse lastlog for the second line and strip the username to get the timestamp
last_raw=$(lastlog -u "$user" | awk 'NR==2 { $1=""; print $0 }' | xargs)
printf "%-12s %-6s %-15s %-30s %s\n" \
"$user" "$uid" "$shell" "$groups" "${last_raw:-never logged in}"
done