Skip to content

Audit

1 page
  • auditd: file access and syscall logging

    In Posts 690 words 4 min

    LinuxSecurityAudit

    Linux doesn’t write every access to /etc/shadow or every unlink call to syslog. For incident investigation and compliance this is critical. auditd solves this: the Linux Audit kernel subsystem records system calls, file access, and more. Installation …

    Linux doesn’t write every access to /etc/shadow or every unlink call to syslog. For incident investigation and compliance this is critical. auditd solves this: the Linux Audit kernel subsystem records system calls, file access, and more. Installation …