By
•
May 10, 2020
•
auditd
Daily Blog
linux
sunday funday
•
Hello Reader.
We've bounced from Windows to OSX and around the cloud. What we haven't done though is venture in the deep waters of Linux forensics. Today let's help out our fellow examiners who are in the trenches with few landmarks to lead their way in the linux forensics wasteland with this weeks challenge focused on Auditd.
The Prize:
The Rules:
$100 Amazon Giftcard
An apperance on the following week's Forensic Lunch!
The Challenge:
On a Linux system with Auditd enabled answer the following quesitons:
1. What new data sources does Auditd create
2. What tools support the data
3. What can an examiner determine from Auditd
4. How long is the data retained for