Apache-2.0, 1,369 commits, 44 tags since April 2023.
gitlab.com/ndaal_open_s...
#auditd #ndaal #opensource #linux #security
Apache-2.0, 1,369 commits, 44 tags since April 2023.
gitlab.com/ndaal_open_s...
#auditd #ndaal #opensource #linux #security
Rules:
-a always,exit -F arch=b64 -F path=/usr/bin/minerd -F perm=x -F key=T1496_Resource_Hijacking
Detect unauthorized ..
#ndaal #auditd #linux #opensource
gitlab.com/ndaal_open_s...
Rules:
-a always,exit -F arch=b64 -F path=/usr/bin/minerd -F perm=x -F key=T1496_Resource_Hijacking
Detect unauthorized ..
#ndaal #auditd #linux #opensource
gitlab.com/ndaal_open_s...
And granite in my auditd (for a different very text-centric problem) was basically dead last.
And granite in my auditd (for a different very text-centric problem) was basically dead last.
Auditd runs on most Linux servers and records almost nothing useful by default. This guide covers rules worth having, protecting the configuration, and querying the results with ausearch and aureport.
Auditd runs on most Linux servers and records almost nothing useful by default. This guide covers rules worth having, protecting the configuration, and querying the results with ausearch and aureport.
Although there is no one-size-fits-all solution, I've found that deploying an Elastic docker container and ingesting data really speeds things up.
www.linkedin.com/pulse/linux-...
Although there is no one-size-fits-all solution, I've found that deploying an Elastic docker container and ingesting data really speeds things up.
www.linkedin.com/pulse/linux-...
Apache-2.0, 1,369 commits, 44 tags since April 2023.
gitlab.com/ndaal_open_s...
#auditd #ndaal #opensource #linux #security
Apache-2.0, 1,369 commits, 44 tags since April 2023.
gitlab.com/ndaal_open_s...
#auditd #ndaal #opensource #linux #security
-> pberba.github.io/sec...
-> pberba.github.io/sec...
Apache-2.0, 1,369 commits, 44 tags since April 2023.
gitlab.com/ndaal_open_s...
#auditd #ndaal #opensource #linux #security
Apache-2.0, 1,369 commits, 44 tags since April 2023.
gitlab.com/ndaal_open_s...
#auditd #ndaal #opensource #linux #security
We are getting closer to the release now, aiming for it within the next two weeks. So far, we have tested:
❗️Non-EDRs for comparison purposes only:
Sysmon-for-Linux✅
Auditd (config: https://buff.ly/3Zmx8Hh)✅
♦️EDRs
CrowdStrike✅
Elastic✅
Continuing...👇
We are getting closer to the release now, aiming for it within the next two weeks. So far, we have tested:
❗️Non-EDRs for comparison purposes only:
Sysmon-for-Linux✅
Auditd (config: https://buff.ly/3Zmx8Hh)✅
♦️EDRs
CrowdStrike✅
Elastic✅
Continuing...👇
Apache-2.0, 1,369 commits, 44 tags since April 2023.
gitlab.com/ndaal_open_s...
#auditd #ndaal #opensource #linux #security
Apache-2.0, 1,369 commits, 44 tags since April 2023.
gitlab.com/ndaal_open_s...
#auditd #ndaal #opensource #linux #security
#golang
github.com/slackhq/go-...
#golang
github.com/slackhq/go-...
🗨️ The Linux Audit subsystem lets you track security-relevant activity based on preconfigured rules and generates log recor…
#unix
🗨️ The Linux Audit subsystem lets you track security-relevant activity based on preconfigured rules and generates log recor…
#unix
blog.badsectorlabs.com/last-week-in...
blog.badsectorlabs.com/last-week-in...
CrowdSec/Fail2Ban
IPSet
SSH keys
Auto updates
UFW
Hardening
Backups
Exploring: Tripwire, Auditd, Logwatch.
Long-term: Building a SIEM for future projects.
What tools would you add for a secure setup? #Cybersecurity #InfoSec #Bluesky
CrowdSec/Fail2Ban
IPSet
SSH keys
Auto updates
UFW
Hardening
Backups
Exploring: Tripwire, Auditd, Logwatch.
Long-term: Building a SIEM for future projects.
What tools would you add for a secure setup? #Cybersecurity #InfoSec #Bluesky
Impossible d'exécuter simplement nginx (permission denied) avec un utilisateur confiné (sysadm_u)...
Et aucun message d'erreur dans auditd, évidemment...
Impossible d'exécuter simplement nginx (permission denied) avec un utilisateur confiné (sysadm_u)...
Et aucun message d'erreur dans auditd, évidemment...
Security guide for configuring Linux Audit Framework (auditd) to log exe...
[ Read Full Article -> ] https://zyekh.com/blog/auditd-kernel-event-monitoring-and-dfir-logging.html
#Cybersecurity #Auditddfir
Security guide for configuring Linux Audit Framework (auditd) to log exe...
[ Read Full Article -> ] https://zyekh.com/blog/auditd-kernel-event-monitoring-and-dfir-logging.html
#Cybersecurity #Auditddfir
Liste des mises à jour : github.com/siderolabs/t...
En bref : k8s 1.33, boot en uefi(systemd) par défaut, plus de cgroup v1, les extensions sont devenues des « boot assets »
Liste des mises à jour : github.com/siderolabs/t...
En bref : k8s 1.33, boot en uefi(systemd) par défaut, plus de cgroup v1, les extensions sont devenues des « boot assets »
Een trainee.
Die gaat een ansible role maken voor auditd :)
Die gaat leren.
- Ansible
- Linux audit
- Logging.
Naast wat rand zakken als git ;)
Een trainee.
Die gaat een ansible role maken voor auditd :)
Die gaat leren.
- Ansible
- Linux audit
- Logging.
Naast wat rand zakken als git ;)
sudo auditctl -w ~/.zsh_history -p war -k zsh_history_watch
And then to view those logs later for troubleshooting:
ausearch -k zsh_history_watch
On MacOS, you could do something similar with: www.unix.com/man-page/osx...
sudo auditctl -w ~/.zsh_history -p war -k zsh_history_watch
And then to view those logs later for troubleshooting:
ausearch -k zsh_history_watch
On MacOS, you could do something similar with: www.unix.com/man-page/osx...