Linux detection engineering with Auditd
ID: 0bd62dd7-353c-5ca9-8219-a5c3564ddd8a
STIX ID: report--0bd62dd7-353c-5ca9-8219-a5c3564ddd8a
Feed Name: Elastic Security Labs
This guide explains how to deploy and manage Linux Auditd and Elastic's Auditd Manager, how to write and troubleshoot Auditd rules, and illustrates detection/hunting examples (UDP reverse shells, Meterpreter file reads, FTP/RDP brute force, RWX memory regions) and ES|QL queries to increase Unix/Linux visibility and detection capabilities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
