Skip to main content

User-Audit

Description​

This agnostic script is built to retrieve specific or multiple users auditing for information username, SID, and status.

Requirements​

  • PowerShell V5

Usage​

  1. Retrieve the users "Username", "SID", and "Status" provided in the -pattern. The script matches the string provided in -pattern and fetches the list of users that contains the provided string in it.

Returns users audit that contains 'Test' in it.

.\User-Audit.ps1 -Pattern 'Test'
This will fetch any users containing the "Test" string. If the agent is a Domain Controller, it will audit the domain accounts; otherwise, it will audit the local accounts containing a test string

Returns users audit that contains 'Test' or 'Pro' in it.

.\User-Audit.ps1 -Pattern 'Test, Pro'
This will fetch any users containing a "Test" or "Pro" string. If the agent is a Domain Controller, it will audit the domain accounts; otherwise, it will audit the local accounts containing a "test" or "pro" string.

Parameters​

ParameterAliasRequiredExampleTypeDescription
PatternTrueTest,ProStringThe name of the specific/multiple user(s) pattern to match and find the user detail of matching string.

Output​

  • Script Log

Changelog​

2025-04-10​

  • Initial version of the document