<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Auditd on RGROSEC</title><link>https://aegrah.github.io/tags/auditd.html</link><description>Recent content in Auditd on RGROSEC</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>Copyright © Ruben Groenewoud</copyright><lastBuildDate>Tue, 09 Apr 2024 12:00:00 +0200</lastBuildDate><atom:link href="https://aegrah.github.io/tags/auditd/index.xml" rel="self" type="application/rss+xml"/><item><title>Linux detection engineering with Auditd</title><link>https://aegrah.github.io/post/2024-04-09-linux-detection-engineering-with-auditd.html</link><pubDate>Tue, 09 Apr 2024 12:00:00 +0200</pubDate><guid>https://aegrah.github.io/post/2024-04-09-linux-detection-engineering-with-auditd.html</guid><description>
In this article, I explore how to effectively use Auditd and Auditd Manager for detection engineering. I’ll demonstrate Auditd's powerful features, guide you through the setup process, and show you how to create and modify rules to capture specific behaviors. You'll also learn how to interpret the logs and discover how Auditd Manager, an Elastic integration, enhances Auditd's utility by streamlining its management.
Are you interested in this research? The full paper is available at Elastic Security Labs!</description></item></channel></rss>