查看系统调用表:
ausyscall --dump
添加对kill系统调用的审计命令:
auditctl -a always,exit -F arch=b64 -S kill -k rule_kill_exec_command
查看audit审计日志:
tail -f /var/log/audit/audit.log
type=SYSCALL msg=audit(1549961725.237:2123): arch=c000003e syscall=62 success=yes exit=0 a0=532e a1=9 a2=0 a3=532e items=0 ppid=1980 pid=1990 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts1 ses=2 comm="bash" exe="/usr/bin/bash" subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key="rule_kill_exec_command"
type=OBJ_PID msg=audit(1549961725.237:2123): opid=21294 oauid=0 ouid=0 oses=1 obj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 ocomm="vim"
type=PROCTITLE msg=audit(1549961725.237:2123): proctitle="-bash"
参考:
https://www.cnblogs.com/pshell/p/7649189.html
https://www.cnblogs.com/bonelee/p/7803377.html
https://blog.csdn.net/shengzhadon/article/details/51567917