2011-06-23
10:24 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Linux security events to look out for
Does anybody wish to share which specific Red Hat Linux security-related events to look out for (i.e. worthy of a correlation rule or a report), besides authentication events or user account management?
1 Reply
2011-06-23
01:30 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
I take it that you are already looking at sudo actions. The other thing you may want to look for are service failures and service/server reboots/restarts. A service restarting or a server rebooting outside of when you would normally expect it to occur.
