Case study · May 2026
Linux Security Audit Script
Bash · Linux · systemd
What it checks
- Filesystem: disk usage by mount point, the ten largest directories and a breakdown of
/var/log. - Processes and services: top CPU and memory consumers, and any failed systemd units.
- Networking: listening ports, the routing table and network interfaces.
- Users and permissions: recent logins, each user’s last login and sudo privileges.
Every run saves a timestamped log to ~/audit_logs/. Disk usage at 60% flags a warning and 80% flags critical. Any failed systemd unit is critical, a port bound to 0.0.0.0 or * is a warning, and a snap directory at 50G or more is a warning.
How it runs
A systemd oneshot service runs the script under my user account. The timer fires five minutes after boot and every hour after that, with Persistent=true so a missed run happens after a reboot.
What the first run found
- Open WebUI on
0.0.0.0:3000. My local Ollama front end was exposed to the whole network. I rebound it to127.0.0.1:3000. - Apache2 running and enabled on boot with nothing to serve. I stopped and disabled it.
- Snap storage at 54G. Disabled revisions had piled up across 30+ packages. After removing them it dropped to 30G, a 44% reduction.
Fixing all three took about ten minutes.