You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Tests with sample files (/var/lib/dpkg/status and /usr/local/Cellar)
3. Process
Implement using the Linux Audit Framework (system calls exec/execve) by default instead of reading /proc (requires modifying go-libaudit to allow multiple clients/subscribers)
4. Socket
Evaluate and possibly implement using the Linux Audit Framework (system calls connect/bind) by default instead of using netlink (requires modifying go-libaudit to allow multiple clients/subscribers)
Backlog for the Auditbeat system module.
General
processobject acrossprocess,socket, andloginmetricsetsCachebe thread safe (canFetch()ever be called concurrently?)?1. Login
2. Package
/var/lib/dpkg/statusand/usr/local/Cellar)3. Process
4. Socket
5. User
/etc/passwd,/etc/shadow, and/etc/groupfiles