审计日志探幽

原名:analyzing-linux-audit-logs-for-intrusion

使用 Linux 审计框架(auditd)及 ausearch 和 aureport 工具进行系统审计和日志分析。

分类
开发提效
版本
v1.0.0
作者
弈韬(@ra1nzzz)
下载
1
收藏
0
发布
2026-08-18
更新
2026-08-18
TRACE 评分
3.4 / 5

内容概览

- Investigating suspected unauthorized access or privilege escalation on Linux hosts - Hunting for evidence of exploitation, backdoor installation, or persistence mechanisms - Auditing compliance with security baselines (CIS, STIG, PCI-DSS) that require system call monitoring - Reconstructing a timeline of attacker actions during incident response - Detecting file tampering on critical system files such as /etc/passwd, /etc/shadow, or SSH keys Do not use for network-level intrusion detection; use Suricata or Zeek for network traffic analysis. Auditd operates at the kernel level on individual hosts. - Linux system with auditd package installed and the audit daemon running (systemctl status auditd) - Root or sudo access to configure audit rules and query logs - Audit rules deployed via /etc/audit/rules.d/ .rules or loaded with auditctl - Recommended: Neo23x0/auditd ruleset from GitHub for …

查看 SKILL 详情