Sorry, I mistakenly believed that auditctl records the process tree on event generation automatically, but that's not the case. You'll need to add a rule that records execve events.
- Posts
- 10
- Comments
- 48
- Joined
- 2 yr. ago
- Posts
- 10
- Comments
- 48
- Joined
- 2 yr. ago
ich_iel @feddit.org ich🌿🧂iel
ich_iel @feddit.org ich💸iel
ich_iel @feddit.org ich👅🔌iel
AssholeDesign @lemmy.world They want to save me from putting on weight
Europe @feddit.org Stop Destroying Videogames needs more signatures!
ich_iel @feddit.org ich🍝💥iel
Privacy @lemmy.ml Unauthenticated RCE vs all GNU/Linux systems to be fully disclosed in 2 weeks with no working fix yet
Cybersecurity @sh.itjust.works Unauthenticated RCE vs all GNU/Linux systems to be fully disclosed in 2 weeks with no working fix yet
Linux @lemmy.ml Unauthenticated RCE vs all GNU/Linux systems to be fully disclosed in 2 weeks with no working fix yet
cats @lemmy.world Lumpi would like scritchies until the universe ends

Pretty much yes, unfortunately. Because the process calling your target process is obviously created before, you'd need to proactively log all executions. :/