Here is a bash script that contains a list of useful auditd rules that can be implemented. The rules are added in /etc/auditd/rules.d/audit.rules using "sed", and each of them is added in a new line. The auditd service is then restarted in order to make the rules persistent. Is assumed that auditd service is installed
-
Notifications
You must be signed in to change notification settings - Fork 1
Camillolevi/auditd_baseline
Folders and files
Name | Name | Last commit message | Last commit date | |
---|---|---|---|---|
Repository files navigation
About
Auditd rules baseline that can be useful to log suspicious activities
Resources
Stars
Watchers
Forks
Releases
No releases published
Packages 0
No packages published