[MEDIUM] auditd for file integrity & syscall audit #26

Closed
opened 2026-07-28 14:31:51 +00:00 by sorb · 1 comment
Owner

Monitor /etc, ~/.kube, /var/lib/rancher/k3s for sensitive file changes via auditd rules, output to syslog/centralized logging. Low overhead, good forensics/compliance signal.

Monitor `/etc`, `~/.kube`, `/var/lib/rancher/k3s` for sensitive file changes via auditd rules, output to syslog/centralized logging. Low overhead, good forensics/compliance signal.
sorb added the priority:mediumarea:security labels 2026-07-28 14:31:51 +00:00
Author
Owner

Migriert nach git.lab: axion1337.chat/axion1337.chat-gitops#26 (nur im Lab bzw. via VPN erreichbar — das Lab ist seit 2026-08-01 die Quelle der Wahrheit, siehe gitops#48). Weiterarbeit dort; dieses Gitea-Issue bleibt als Verweis stehen.

**Migriert nach git.lab**: [axion1337.chat/axion1337.chat-gitops#26](https://git.lab/axion1337.chat/axion1337.chat-gitops/-/issues/26) (nur im Lab bzw. via VPN erreichbar — das Lab ist seit 2026-08-01 die Quelle der Wahrheit, siehe gitops#48). Weiterarbeit dort; dieses Gitea-Issue bleibt als Verweis stehen.
sorb closed this issue 2026-08-01 14:26:05 +00:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sorb/axion1337.chat-gitops#26