-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathdebian_audit.sh
55 lines (49 loc) · 1.34 KB
/
debian_audit.sh
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
#!/bin/sh
# vim:set syntax=sh:
# kate: syntax bash;
# SPDX-License-Identifier: CC-BY-SA-4.0
# Copyright 2021-2023 Jakob Meng, <jakobmeng@web.de>
exit # do not run any commands when file is executed
#
# System Audit
#
journalctl -xb # check for errors
reboot
journalctl -xb # check for errors again
# look for open ports
ss -tulpen
# or
netstat -tulpen # deprecated
# look for running daemons
systemctl list-units
systemctl list-unit-files | grep -v masked | grep -v static | grep -v disabled | grep -v indirect | grep -v generated
# look for unexplained files
apt-get install -y cruft-ng
cat << 'EOF' >> /etc/cruft/ignore
# 2023 Jakob Meng, <jakobmeng@web.de>
/.snapshots
/opt
/home
/root
/var/lib
/var/www
EOF
cruft-ng > /tmp/$(hostname)_cruft_report_$(date +%Y%m%d)
(
cd /
umask 337 # u=r,g=r,o=
# Disk analysis
OUT="/tmp/disk_analysis_$(hostname)_$(date '+%Y%m%d%H%M%S')"
(
set -x
lshw -class disk
for dev in a b c d e f g h i j k l m n o p q r s t u v w x y z; do [ -e /dev/sd${dev} ] && { sgdisk --print /dev/sd${dev}; smartctl -A /dev/sd${dev}; } ; done
which mdadm >/dev/null && \
mdadm --detail --scan --verbose
which pvscan >/dev/null && \
{ pvscan; vgdisplay --verbose; lvdisplay --verbose; }
ls -l /dev/disk/by-id/
ls -l /dev/disk/by-uuid/
which storcli64 >/dev/null && \
storcli64 /call /eall /sall show
) >"${OUT}.txt" 2>&1