Sorry, I mistakenly believed that auditctl records the process tree on event generation automatically, but that's not the case. You'll need to add a rule that records execve events.
- Posts
- 10
- Comments
- 52
- Joined
- 2 yr. ago
- Posts
- 10
- Comments
- 52
- Joined
- 2 yr. ago
ich_iel @feddit.org ich🌿🧂iel
ich_iel @feddit.org ich💸iel
ich_iel @feddit.org ich👅🔌iel
AssholeDesign @lemmy.world They want to save me from putting on weight
Europe @feddit.org Stop Destroying Videogames needs more signatures!
ich_iel @feddit.org ich🍝💥iel
PC Master Race @lemmy.world Is my AiO block getting eaten by corrosion?
Privacy @lemmy.ml Unauthenticated RCE vs all GNU/Linux systems to be fully disclosed in 2 weeks with no working fix yet
Linux @lemmy.ml Unauthenticated RCE vs all GNU/Linux systems to be fully disclosed in 2 weeks with no working fix yet
cats @lemmy.world Lumpi would like scritchies until the universe ends
Pretty much yes, unfortunately. Because the process calling your target process is obviously created before, you'd need to proactively log all executions. :/