auditing files which are executed?

Brennan, William C william.c.brennan at lmco.com
Mon Jan 21 17:08:17 UTC 2008


Steve Grubb wrote:
> 
> You use file watches:
>
> auditctl  -w /usr/sbin/stunnel  -p x  -k my-file-is-executed
>
> There are examples of this in the CAPP & LSPP rules. You can find this

> by 'rpm -ql audit | grep lspp'

Thanks Steve.  I completely overlooked the example files. 

-- Bill




More information about the Linux-audit mailing list