linux - Auditing procfs -
i want keep track on important system changes on gnu/linux boxes, disabling pax, enabling traffic forwarding, icmp redirects, changing printk verbosity level , on. @ general these operations base on changes on /proc/sys/kernel/* files. , didn't find method of auditing procfs far. maybe setting watch rule 'write' syscalls /proc/sys/kernel/* value first argument (a0) feasible approach... wondering. there's no way of using wildcard in a0-3 auditd rules -f parameters, in worst case have create separate rule each important file in directory. i'll appreciate hints problem, in advance.
Comments
Post a Comment