Skip to content

mzpqnxow/auditd-ruleset

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

38 Commits
 
 
 
 

Repository files navigation

auditd-ruleset

This is an auditd based ruleset for carefully monitoring user accounts. Useful when ensuring that service accounts aren't being used interactively, for example a www-data type user

How to handle log output

Take a look at audisp-json and consider streaming into logstash

Quick guide to setting up audisp-json

Just look at all of the files in the repository, they are placed as they would need to be if on a system. And of course, build and install audisp-json ...

About

auditd based tripwire ruleset

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published