public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
* Monitoring "root-level" commands
@ 2016-05-18 12:18 Warron S French
  2016-05-18 12:42 ` Steve Grubb
  0 siblings, 1 reply; 2+ messages in thread
From: Warron S French @ 2016-05-18 12:18 UTC (permalink / raw)
  To: linux-audit@redhat.com


[-- Attachment #1.1: Type: text/plain, Size: 584 bytes --]

My Special Security Team, not being UNIX/Linux savvy asked me if I could put into place audit rules that monitor "Root-Level" commands.

I don't know of any specific identifier for such a term, and the closest thing I could come up with was monitoring those files that fall under /usr/sbin/ and /sbin/; does anyone else have any thoughts about how to approach this task?

I figured I would use a rule such as:
-w /sbin/   -p rawx  -k watch_root_commands                (I used rawx, to account for replacement by a hacker)


Thank you in advance,

Warron French, MBA, SCSA

[-- Attachment #1.2: Type: text/html, Size: 2906 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2016-05-18 12:42 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2016-05-18 12:18 Monitoring "root-level" commands Warron S French
2016-05-18 12:42 ` Steve Grubb

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox