logo

Linux detection engineering with Auditd

ID: 0bd62dd7-353c-5ca9-8219-a5c3564ddd8a

STIX ID: report--0bd62dd7-353c-5ca9-8219-a5c3564ddd8a

Feed Name: Elastic Security Labs

Date Published: 2024-04-09

Date Updated: 2026-04-27

...
...

This guide explains how to deploy and manage Linux Auditd and Elastic's Auditd Manager, how to write and troubleshoot Auditd rules, and illustrates detection/hunting examples (UDP reverse shells, Meterpreter file reads, FTP/RDP brute force, RWX memory regions) and ES|QL queries to increase Unix/Linux visibility and detection capabilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.