6
How to use Auditd file access logs?
(programming.dev)
c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.
THE RULES
Instance Rules
Community Rules
If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.
Learn about hacking
Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub
Notable mention to !cybersecuritymemes@lemmy.world
Pretty much yes, unfortunately. Because the process calling your target process is obviously created before, you'd need to proactively log all executions. :/
Welp
Guess I need to look for another way for my auditing desires.
On the other hand, considering such a thing can be easily done using
htop, I'd suppose it would be possible to add such a functionality toauditd(to include the whole tree and full executable paths).I feel like this functionality has considerable merit and would make the file access rules much more useful.