You could combine FIM with a binary whitelisting t...
# general
g
You could combine FIM with a binary whitelisting tool, so only approved things can run as root.