Git Product home page Git Product logo

bsmtrace's Introduction

OpenBSM

Build Status

Coverity Scan Build Status

Introduction

OpenBSM is an open-source implementation of Sun's BSM event auditing file format and API. Originally created for Apple Computer by McAfee Research, OpenBSM is now maintained by volunteers and through the generous contributions of several organizations.

OpenBSM includes several command line tools, including auditreduce(8) and praudit(8) for reducing and printing audit trails, as well as the libbsm(3) library to manage configuration files, generate audit records, and parse and print audit trails. It also includes the auditd(8) audit configuration daemon, and the auditdistd(8) audit-trail distribution daemon.

Coupled with a kernel audit implementation, OpenBSM can be used to maintain system audit streams, and is a foundation for a full audit-enabled system. Portions of OpenBSM, including include files and token-building routines, are reusable in a kernel audit implementation, and may be found in the FreeBSD and macOS kernels.

Contents

OpenBSM consists of several directories:

bin/           Audit-related command line tools and daemons
bsm/           Library header files for BSM
compat/        Compatibility code to build on various operating systems
etc/           Sample /etc/security configuration files
libauditd/     Common audit management functions for auditd and launchd
libbsm/        Implementation of BSM library interfaces and man pages
man/           System call and configuration file man pages
m4/            Input files for m4 macro text processor 
modules/       Directory for auditfilterd module source
sys/           System header files for BSM
test/          Test token sets and geneneration program
tools/         Tool directory, including audump to dump databases

The following programs are included with OpenBSM:

audit          Command line audit control tool
auditd         Audit management daemon
auditdistd     Audit trail distribution daemon
auditfilterd   Experimental event monitoring framework
auditreduce    Audit trail reduction tool
audump         Debugging tool to parse and print audit databases
praudit        Tool to print audit trails

Build and Installation

Please see the file INSTALL for build and installation instructions.

Contributions

The TrustedBSD Project would appreciate the contribution of bug fixes, enhancements, etc, under the same license found in the top-level LICENSE file. Please see the file CREDITS to learn more about who has contributed to the project.

Location

Information on OpenBSM may be found on the OpenBSM home page:

http://www.OpenBSM.org/

Information on TrustedBSD may be found on the TrustedBSD home page:

http://www.TrustedBSD.org/

bsmtrace's People

Contributors

allanjude avatar cbrueffer avatar csjayp avatar droe avatar kevans91 avatar mhalden avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

bsmtrace's Issues

Documentation?

Hi,

Is there any documentation for this? Google doesn't turn up much.

For instance, I run bsmtrace with a finite state machine matching logins. What does it do when it matches an event? Does it output information, notices, etc.? When I run it in foreground mode, I see the event was matched & it gives some information about it (auid, duration, priority, etc.). But how do I use this? Maybe pipe it to logger to send it into syslog? Is there some built in logging or notification functionality in bsmtrace? In other words, how do I use this to monitor the events it matches?

Edit:
I found this: https://people.freebsd.org/~csjp/bsmtrace/bsmtrace.txt

Looks somewhat outdated.

Is there any way to set the output fields, format, etc?

Make arrays dynamic

Hi,

We have a lot of filesystems defined in the configuration of bsmtrace on some systems and we have been running into bsmtrace crashing when some of the arrays run out of storage. Arrays should preferably be made to allocate memory dynamically.

We currently use this patch on our systems to get around this problem.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.