4 ms·
I like to see OS capable of full auditable logs of every app execution in the system (phone, mac, linux, windows) every .so, .dll use by each app a
by tkinom 6y ago
I like to see OS capable of full auditable logs of
every app execution in the system (phone, mac, linux, windows)
every .so, .dll use by each app and their hash/datetime creation.
every files/dirs creation / write/read by which app
every socket bind and connect requests.
and other privilege operations
There should be virus total type check on all app/.so/.dll.
There should be allow/forbid LIST for exec,file/dir access/socket, privilege ops access similar to typical firewall software - Not just for net, but also for app execution and files access.
"Default allow", "Default forbid - with log/notification" fully under user control.
like selinux, but with much better UI/UX (web base, build on top of ebpf?)
- 616c 6y agoIn Linux, not completely an answer to what you want auditd does a lot of it, but I rarely see it mentioned outside the government and military because of use of the STIG requirements. And to your point: the UI sucks as it just text-based config in its own format and no one likes it or reads the outputted logs in my experience, even the SOC people who should know it.