Posts tagged: #auditd
Reconstruct command lines from Linux audit.log: grouping records by event, EXECVE argument reassembly, hex-encoded arguments, auid and ses across sudo.
A worked Linux log investigation on a synthetic jump host: SSH password guessing, a login from a new IP, sudo -i, cron and systemd persistence, log tampering.
How the four Linux log families fit together in an investigation, what each one proves, where they disagree, and how to merge them into one timeline.