February 2020
Intermediate to advanced
666 pages
15h 45m
English
Creating rules to monitor when someone performs a certain action isn't hard, but the command syntax is a bit trickier than what we've seen so far. With this rule, we're going to be alerted every time Charlie either tries to open a file or tries to create a file:
[donnie@localhost ~]$ sudo auditctl -a always,exit -F arch=b64 -S openat -F auid=1006[sudo] password for donnie:[donnie@localhost ~]$ sudo auditctl -l-w /etc/passwd -p wa -k passwd_changes-w /secretcats -p rwxa -k secretcats_watch-a always,exit -F arch=b64 -S openat -F auid=1006[donnie@localhost ~]$
Here's the breakdown: