perhaps obvious question: auditd and setuid/setgid?

John Jasen jjasen at gmail.com
Wed Sep 2 23:06:06 UTC 2015


I'm currently testing auditd with rules for setuid or setgid binaries on
the system.

I currently maintain the list via find, and pushing the results to a
audit.rules file.

I'm hoping there's a cleaner way, perhaps by triggering on the
appropriate syscall -- but have not discovered it.

Is there an easier method?






More information about the Linux-audit mailing list