审计日志探幽
原名:analyzing-linux-audit-logs-for-intrusion
使用 Linux 审计框架(auditd)及 ausearch 和 aureport 工具进行系统审计和日志分析。
- 分类
- 开发提效
- 版本
- v1.0.0
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 1
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-08-18
- TRACE 评分
- 3.4 / 5
内容概览
- Investigating suspected unauthorized access or privilege escalation on Linux hosts - Hunting for evidence of exploitation, backdoor installation, or persistence mechanisms - Auditing compliance with security baselines (CIS, STIG, PCI-DSS) that require system call monitoring - Reconstructing a timeline of attacker actions during incident response - Detecting file tampering on critical system files such as /etc/passwd, /etc/shadow, or SSH keys Do not use for network-level intrusion detection; use Suricata or Zeek for network traffic analysis. Auditd operates at the kernel level on individual hosts. - Linux system with auditd package installed and the audit daemon running (systemctl status auditd) - Root or sudo access to configure audit rules and query logs - Audit rules deployed via /etc/audit/rules.d/ .rules or loaded with auditctl - Recommended: Neo23x0/auditd ruleset from GitHub for …