Browsing All Posts published on »October, 2016«

Quickly Enable Linux Audit

October 27, 2016


We are going to log all commands. All events will be logged under /var/log/audit/audit.log. COMMANDS # chkconfig auditd on # service auditd start # auditctl -a exit,always -F arch=b32 -S execve # auditctl -a exit,always -F arch=b64 -S execve HELPFUL COMMANDS aureport -x --summary ausearch -i    (Human Readable) HELPFUL LINK For more details visit official […]