Recording fΓΌr meinen Talk
"Linux Audit Framework - An Introduction":
media.ccc.de/v/2023-269-linux-

Slides: talks.mrmcd.net/2023/talk/VSBR

@MRMCD Danke fΓΌr die geile Con und Props an @c3voc: Sound und Bild sind der Hammer.

#auditd #laurel #mrmcd23

Last updated 1 year ago

vPierre · @vPierre
28 followers · 923 posts · Server mas.to
vPierre · @vPierre
25 followers · 844 posts · Server mas.to
Peter Czanik · @PCzanik
264 followers · 354 posts · Server fosstodon.org
GateLinker · @gatelinker
3 followers · 24 posts · Server fosstodon.org

lesson learned:

fails to load rules files with line endings.
If a single rule file contains these characters, no rules are loaded at all.

Its easy to fix if you know it.

But when you add a single file to others with no visible difference and everything stops working, this can really drive you crazy.

#linux #auditd #crlf

Last updated 1 year ago

Robert · @xoxys
52 followers · 302 posts · Server social.tchncs.de

Does it "make sense" to exclude the remote user from I tend to answer "no" to this question, but the audit log is extremely noisy during an Ansible run. Is there a best practice recommendation for configuration management + auditd?

#secops #linux #sysadmin #auditd #ansible

Last updated 1 year ago

Antonio Sanz · @antoniosanzalc
288 followers · 291 posts · Server infosec.exchange

RT @_hillu@twitter.com

Just released v0.5.1 of Laurel, the plugin event post-processing plugin that generates useful, enriched JSON-based audit logs suitable for modern security monitoring setups.

github.com/threathunters-io/la

πŸ¦πŸ”—: twitter.com/_hillu/status/1619

#linux #auditd

Last updated 2 years ago

Hilko Bengen · @hillu
113 followers · 189 posts · Server infosec.exchange

Just released v0.5.1 of Laurel, the plugin event post-processing plugin that generates useful, enriched JSON-based audit logs suitable for modern security monitoring setups.

github.com/threathunters-io/la

#linux #auditd

Last updated 2 years ago

Peter Czanik · @PCzanik
173 followers · 102 posts · Server fosstodon.org

Looking inside shell sessions has been possible for quite some time, but not much convenient. You could use , or @sudoproject session recordings. Version 1.9.8 introduced log_subcmds, allowing you to log sub-commands with other sudo logs.

sudo.ws/posts/2022/05/looking-

#sudo #auditd

Last updated 2 years ago

ayedaemon · @ayedaemon
4 followers · 21 posts · Server social.linux.pizza

Server auditing is an important task to ensure platform-level security in an IT infrastructure.

I've written a blog post to provide an introduction to auditing in linux environment. The blog covers:

- Intro to linux auditing framework
- Configuring auditd service
- Inspecting audit logs
- Writing custom audit rules
- remote logging.

ayedaemon.github.io/post/2022/

Feel free to comment with corrections and opinions.

#auditd #security #audit #linux

Last updated 2 years ago

hillu · @hillu
79 followers · 32 posts · Server infosec.exchange

Just released version 0.5.0 of Laurel, the plugin for generating useful JSON-based audit logs suitable for SIEM usage. New features include message filtering, container id logging, trimming of long command lines, plus several bug fixes. github.com/threathunters-io/la

#linux #auditd

Last updated 2 years ago

Antonio Sanz · @antoniosanzalc
242 followers · 150 posts · Server infosec.exchange

RT @_hillu@twitter.com

Over the last few months, quite a few interesting features have been added to Laurel, the plugin for generating useful JSON-based audit logs for SIEM usage. Just published a 0.5.0-pre1 prerelease. github.com/threathunters-io/la

πŸ¦πŸ”—: twitter.com/_hillu/status/1599

#linux #auditd

Last updated 2 years ago

hillu · @hillu
78 followers · 27 posts · Server infosec.exchange

Over the last few months, quite a few interesting features have been added to Laurel, the plugin for generating useful JSON-based audit logs for SIEM usage. Just published a 0.5.0-pre1 prerelease. github.com/threathunters-io/la

#linux #auditd

Last updated 2 years ago

@tazwake Better, use linux auditd with some good ruleset: github.com/bfuzzy/auditd-attac

Pro tip: Do some formatting, because the standard event format is *hmmm* "challenging" to read and interpret: github.com/threathunters-io/la

Especially useful when sending to a SIEM.

#laurel #auditd #dfir #linux

Last updated 2 years ago

vPierre · @vPierre
18 followers · 477 posts · Server mas.to
vPierre · @vPierre
18 followers · 477 posts · Server mas.to
vPierre · @vPierre
18 followers · 477 posts · Server mas.to
vPierre · @vPierre
18 followers · 477 posts · Server mas.to
vPierre · @vPierre
18 followers · 477 posts · Server mas.to

RT @cyb3rops@twitter.com

For on you can use my best practice auditd configuration, which is still actively maintained and gets frequent updates via PR

If you've found ways to improve it, please provide them as pull request to help everyone else

github.com/Neo23x0/auditd

πŸ¦πŸ”—: twitter.com/cyb3rops/status/15

#Linux #auditd

Last updated 2 years ago

vPierre · @vPierre
18 followers · 477 posts · Server mas.to

RT @uptycs@twitter.com

What are the best resources for infrastructure security?bit.ly/3hVe1Ma

πŸ¦πŸ”—: twitter.com/uptycs/status/1301

#opensource #osquery #auditd #Linux

Last updated 2 years ago