<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wikicyber.org/index.php?action=history&amp;feed=atom&amp;title=Draft%3AUser_Auditing_-_Beginner</id>
	<title>Draft:User Auditing - Beginner - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wikicyber.org/index.php?action=history&amp;feed=atom&amp;title=Draft%3AUser_Auditing_-_Beginner"/>
	<link rel="alternate" type="text/html" href="https://wikicyber.org/index.php?title=Draft:User_Auditing_-_Beginner&amp;action=history"/>
	<updated>2026-09-24T04:43:54Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.46.0</generator>
	<entry>
		<id>https://wikicyber.org/index.php?title=Draft:User_Auditing_-_Beginner&amp;diff=174&amp;oldid=prev</id>
		<title>MigrationBot: Backfill (v3.0 review queue): added to the review queue</title>
		<link rel="alternate" type="text/html" href="https://wikicyber.org/index.php?title=Draft:User_Auditing_-_Beginner&amp;diff=174&amp;oldid=prev"/>
		<updated>2026-09-22T05:42:45Z</updated>

		<summary type="html">&lt;p&gt;Backfill (v3.0 review queue): added to the review queue&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw-interface=&quot;&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 05:42, 22 September 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l152&quot;&gt;Line 152:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 152:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Linux User Auditing|023]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Linux User Auditing|023]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Migrated from cypat.guide]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Migrated from cypat.guide]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[Category:Pending review]]&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;

&lt;!-- diff cache key wikicyber:diff:1.41:old-94:rev-174:php=table --&gt;
&lt;/table&gt;</summary>
		<author><name>MigrationBot</name></author>
	</entry>
	<entry>
		<id>https://wikicyber.org/index.php?title=Draft:User_Auditing_-_Beginner&amp;diff=94&amp;oldid=prev</id>
		<title>MigrationBot: Import from cypat.guide: docs/linux/user_auditing/intro_user_auditing.md</title>
		<link rel="alternate" type="text/html" href="https://wikicyber.org/index.php?title=Draft:User_Auditing_-_Beginner&amp;diff=94&amp;oldid=prev"/>
		<updated>2026-09-18T17:06:26Z</updated>

		<summary type="html">&lt;p&gt;Import from cypat.guide: docs/linux/user_auditing/intro_user_auditing.md&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Submit}}&lt;br /&gt;
&amp;lt;!-- Migrated from https://cypat.guide/docs/linux/user_auditing/intro_user_auditing (source: docs/linux/user_auditing/intro_user_auditing.md) --&amp;gt;&lt;br /&gt;
-----&lt;br /&gt;
&lt;br /&gt;
Author(s): c-bass&lt;br /&gt;
&lt;br /&gt;
Last Updated: 7-1-2025&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;mw-collapsible mw-collapsed wikitable&amp;quot; style=&amp;quot;width:100%&amp;quot;&lt;br /&gt;
! Recommended Prerequisites (click to expand)&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
None! This is an introductory article.&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Fundamental concepts ==&lt;br /&gt;
&lt;br /&gt;
=== Users ===&lt;br /&gt;
&lt;br /&gt;
A &amp;#039;&amp;#039;&amp;#039;user&amp;#039;&amp;#039;&amp;#039; on linux is just like a user on other operating systems, like MacOS or Windows: it&amp;#039;s an account that represents something (a person or a process) that can access the system. Every user gets a unique username, a password, a home folder (called a &amp;#039;&amp;#039;directory&amp;#039;&amp;#039; on linux), and a UID (User ID, a number used by the system to uniquely identify users).&lt;br /&gt;
&lt;br /&gt;
=== Groups ===&lt;br /&gt;
&lt;br /&gt;
Put simply, a &amp;#039;&amp;#039;&amp;#039;group&amp;#039;&amp;#039;&amp;#039; on linux is a collection of users that share the same permissions. This makes access control significantly easier. Say you have a set of users that need access to a directory-- you can put them all in a group and give the group itself, not the individual users, access to that directory. This is advantageous since if you need to give more users access in the future, you can simply add them to the group. Note this is a &amp;#039;&amp;#039;singular&amp;#039;&amp;#039; use of groups - there are many other uses - but this demonstrates the usefulness groups can have. Each group has a GID (Group ID), just like how each user has a UID.&lt;br /&gt;
&lt;br /&gt;
== Key files ==&lt;br /&gt;
&lt;br /&gt;
=== The /etc/passwd file ===&lt;br /&gt;
&lt;br /&gt;
The &amp;lt;code&amp;gt;/etc/passwd&amp;lt;/code&amp;gt; file stores user info. Let&amp;#039;s explore how it works:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;ubuntu@ubuntu:~$ cat /etc/passwd&lt;br /&gt;
root:x:0:0:root:/root:/bin/bash&lt;br /&gt;
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin&lt;br /&gt;
bin:x:2:2:bin:/bin:/usr/sbin/nologin&lt;br /&gt;
sys:x:3:3:sys:/dev:/usr/sbin/nologin&lt;br /&gt;
...&lt;br /&gt;
ubuntu:x:1000:1000:Ubuntu:/home/ubuntu:/bin/bash&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
There&amp;#039;s one line per user. The first user listed is the &amp;#039;&amp;#039;root user&amp;#039;&amp;#039;, having a UID of 0. This should be the only user to have this uid. The root user is an administration account with unrestricted access to the system. System users have UIDs below 1000 (like &amp;lt;code&amp;gt;daemon&amp;lt;/code&amp;gt; in the output above), and normal users (like the &amp;lt;code&amp;gt;ubuntu&amp;lt;/code&amp;gt; user above) have UIDs 1000 or greater.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;mw-collapsible mw-collapsed wikitable&amp;quot; style=&amp;quot;width:100%&amp;quot;&lt;br /&gt;
! What is a system user? (click to expand)&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
Many of the users above are &amp;#039;&amp;#039;system users&amp;#039;&amp;#039;, meaning they&amp;#039;re for system accounts and not meant for actual use. A user is a system user if it has a UID under 1000. System users exist because many programs/services need a user account to own their respective files. For instance, a webserver needs a system account to own files in &amp;lt;code&amp;gt;/var/www&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Each line in &amp;lt;code&amp;gt;/etc/passwd&amp;lt;/code&amp;gt; follows this format:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;username:password:UID:GID:comment:home_directory:shell&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
There are some important things to note about this:&lt;br /&gt;
&lt;br /&gt;
* Each user&amp;#039;s password isn&amp;#039;t stored in &amp;lt;code&amp;gt;/etc/passwd&amp;lt;/code&amp;gt;, instead a &amp;#039;&amp;#039;placeholder&amp;#039;&amp;#039; takes the password field. Typically that placeholder is &amp;lt;code&amp;gt;x&amp;lt;/code&amp;gt;, denoting the password hash is stored in another file (&amp;lt;code&amp;gt;/etc/shadow&amp;lt;/code&amp;gt;). The same goes for the &amp;lt;code&amp;gt;/etc/group&amp;lt;/code&amp;gt; file!&lt;br /&gt;
* While normal users have loginable shells, like &amp;lt;code&amp;gt;/bin/bash&amp;lt;/code&amp;gt;, system users by convention don&amp;#039;t have loginable shells, usually &amp;lt;code&amp;gt;/bin/false&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;/usr/sbin/nologin&amp;lt;/code&amp;gt;.&lt;br /&gt;
* A GID denotes a user&amp;#039;s &amp;#039;&amp;#039;primary group&amp;#039;&amp;#039;. Secondary groups (often called supplementary groups) are denoted by entries in &amp;lt;code&amp;gt;/etc/group&amp;lt;/code&amp;gt;. This&amp;#039;ll be explained more below!&lt;br /&gt;
&lt;br /&gt;
=== The /etc/group file ===&lt;br /&gt;
&lt;br /&gt;
Like how &amp;lt;code&amp;gt;/etc/passwd&amp;lt;/code&amp;gt; stores user info, the &amp;lt;code&amp;gt;/etc/group&amp;lt;/code&amp;gt; file stores group info.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;ubuntu@ubuntu:~$ cat /etc/group&lt;br /&gt;
root:x:0:&lt;br /&gt;
daemon:x:1:&lt;br /&gt;
bin:x:2:&lt;br /&gt;
sys:x:3:&lt;br /&gt;
...&lt;br /&gt;
sudo:x:27:ubuntu&lt;br /&gt;
...&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
Each line follows this structure:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;group:password:GID:users&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
A particularly important group is &amp;lt;code&amp;gt;sudo&amp;lt;/code&amp;gt;: any user in the &amp;lt;code&amp;gt;sudo&amp;lt;/code&amp;gt; group effectively has full access to the system.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;mw-collapsible mw-collapsed wikitable&amp;quot; style=&amp;quot;width:100%&amp;quot;&lt;br /&gt;
! What is a primary group? What is a supplementary group? (click to expand)&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
Every user has exactly one &amp;#039;&amp;#039;&amp;#039;primary group&amp;#039;&amp;#039;&amp;#039; that is assigned when the user account is created - this is the group that owns files when the user creates them. Users can also belong to multiple &amp;#039;&amp;#039;&amp;#039;supplementary groups&amp;#039;&amp;#039;&amp;#039; (also called secondary groups) which give them additional permissions beyond their primary group. For example, a user named &amp;amp;quot;josh&amp;amp;quot; might have &amp;amp;quot;josh&amp;amp;quot; as their primary group but also belong to supplementary groups like &amp;amp;quot;sudo&amp;amp;quot; and &amp;amp;quot;docker&amp;amp;quot; to access those specific services. Primary groups are denoted by a user&amp;#039;s GID in &amp;lt;code&amp;gt;/etc/passwd&amp;lt;/code&amp;gt;, and supplementary groups are denoted by entries in &amp;lt;code&amp;gt;/etc/group&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== The /etc/shadow file ===&lt;br /&gt;
&lt;br /&gt;
The &amp;lt;code&amp;gt;/etc/shadow&amp;lt;/code&amp;gt; file stores password hashes and other important information.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;ubuntu@ubuntu:~$ sudo cat /etc/shadow&lt;br /&gt;
root:!:19827:0:99999:7:::&lt;br /&gt;
daemon:*:19790:0:99999:7:::&lt;br /&gt;
bin:*:19790:0:99999:7:::&lt;br /&gt;
sys:*:19790:0:99999:7:::&lt;br /&gt;
sync:*:19790:0:99999:7:::&lt;br /&gt;
...&lt;br /&gt;
ubuntu:&amp;lt;hash&amp;gt;:19827:0:99999:7:::&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
{| class=&amp;quot;mw-collapsible mw-collapsed wikitable&amp;quot; style=&amp;quot;width:100%&amp;quot;&lt;br /&gt;
! Why do we need sudo here, but not /etc/passwd and /etc/group? (click to expand)&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
Password hashes are &amp;#039;&amp;#039;incredibly&amp;#039;&amp;#039; sensitive information. If someone has an insecure password, it&amp;#039;s usually trivial to find it if you have their hash. For this reason, we need root permissions (granted through &amp;lt;code&amp;gt;sudo&amp;lt;/code&amp;gt;) to view the &amp;lt;code&amp;gt;/etc/shadow&amp;lt;/code&amp;gt; file. In contrast, the info in &amp;lt;code&amp;gt;/etc/passwd&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;/etc/group&amp;lt;/code&amp;gt; is less critical.&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
It&amp;#039;s beyond the scope of introductory user auditing to explain the structure of the &amp;lt;code&amp;gt;/etc/shadow&amp;lt;/code&amp;gt; file-- for now, just know it exists and what its purpose is.&lt;br /&gt;
&lt;br /&gt;
== Hardening ==&lt;br /&gt;
&lt;br /&gt;
=== User Auditing ===&lt;br /&gt;
&lt;br /&gt;
Since users are stored in &amp;lt;code&amp;gt;/etc/passwd&amp;lt;/code&amp;gt;, you can use this command to get a list of all users on the system with loginable shells:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;grep &amp;quot;/bin/.*sh$&amp;quot; /etc/passwd | cut -d: -f1&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
In a system hardening scenario, you&amp;#039;re usually given a list of authorized users: compare that list to the actual users present.&lt;br /&gt;
&lt;br /&gt;
For any users not supposed to be on the system, remove them:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;sudo deluser &amp;lt;user&amp;gt;&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
To remove their home directory too, use:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;sudo deluser --remove-home &amp;lt;user&amp;gt;&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&amp;lt;code&amp;gt;userdel&amp;lt;/code&amp;gt; also works if needs be, but &amp;lt;code&amp;gt;deluser&amp;lt;/code&amp;gt; is standard. Alternatively, simply remove the user&amp;#039;s entry in &amp;lt;code&amp;gt;/etc/passwd&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
If you need to add a user to the system, run:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;sudo adduser &amp;lt;user&amp;gt;&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&amp;lt;code&amp;gt;useradd&amp;lt;/code&amp;gt; also works in case &amp;lt;code&amp;gt;adduser&amp;lt;/code&amp;gt; isn&amp;#039;t available.&lt;br /&gt;
&lt;br /&gt;
=== Group Auditing ===&lt;br /&gt;
&lt;br /&gt;
Check the members of the sudo group:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;getent group sudo&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
Alternatively,&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;grep sudo /etc/group&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
In a system hardening scenario, compare this to known authorized admins. To remove an unauthorized admin (but keep them on the system), do:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;sudo deluser username sudo&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
Alternatively, you can modify the &amp;lt;code&amp;gt;/etc/group&amp;lt;/code&amp;gt; file and remove the user from the &amp;lt;code&amp;gt;sudo&amp;lt;/code&amp;gt; group manually.&lt;br /&gt;
&lt;br /&gt;
=== Other Hardening ===&lt;br /&gt;
&lt;br /&gt;
If a user has an insecure password, change it!&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;passwd &amp;lt;user&amp;gt;&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
It&amp;#039;ll then prompt you for the user&amp;#039;s new password.&lt;br /&gt;
&lt;br /&gt;
[[Category:Linux User Auditing|023]]&lt;br /&gt;
[[Category:Migrated from cypat.guide]]&lt;/div&gt;</summary>
		<author><name>MigrationBot</name></author>
	</entry>
</feed>