Expand description
Audit rule suppression / netlink audit tamper detection.
Functionsยง
- is_
audit_ tampered - Classify whether the kernel audit subsystem has been tampered with by comparing the expected audit daemon PID against the PID that actually owns the audit netlink socket.
- scan_
audit_ tampering - Scan for audit subsystem tampering.