SELinux and Auditd
ID: 76787a38-7d07-5ed3-9c2f-ed777b679f6b
STIX ID: report--76787a38-7d07-5ed3-9c2f-ed777b679f6b
Feed Name: TrustedSec blog
An introductory blog post on SELinux and Auditd for CentOS 7/8 that demonstrates how to view SELinux contexts (ps -Z, ls -Z), manage booleans (getsebool, setsebool), inspect and extend policy files (selinux-policy-devel), and craft Auditd rules to monitor file changes and syscalls. The post highlights permissions like execmem/execheap and booleans such as deny_ptrace and deny_execmem, gives sample Auditd rules (e.g., watching /etc/passwd and logging root execve), and links multiple resources for deeper study.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
