4 ms·
Look into auditd for logging execve() syscall instead. OSSEC can (directly) report or act on any thing reported through logs.
by MrSec 11y ago
Look into auditd for logging execve() syscall instead.
OSSEC can (directly) report or act on any thing reported through logs.
- rmdoss 11y agoAnd send it to Slack now as well: https://blog.sucuri.net/2016/01/server-security-integrating-ossec-with-slack-and-pagerduty.html https://blog.sucuri.net/2016/01/server-security-integrating-...