logo

SELinux and Auditd

ID: 76787a38-7d07-5ed3-9c2f-ed777b679f6b

STIX ID: report--76787a38-7d07-5ed3-9c2f-ed777b679f6b

Feed Name: TrustedSec blog

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

An introductory blog post on SELinux and Auditd for CentOS 7/8 that demonstrates how to view SELinux contexts (ps -Z, ls -Z), manage booleans (getsebool, setsebool), inspect and extend policy files (selinux-policy-devel), and craft Auditd rules to monitor file changes and syscalls. The post highlights permissions like execmem/execheap and booleans such as deny_ptrace and deny_execmem, gives sample Auditd rules (e.g., watching /etc/passwd and logging root execve), and links multiple resources for deeper study.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.