theopolis
10/04/2020, 8:33 PMPrateek Kumar Nischal
10/04/2020, 8:36 PMtheopolis
10/04/2020, 8:49 PMPrateek Kumar Nischal
10/04/2020, 9:02 PM--disable_audit=false
--allow_unsafe
--audit_allow_config
--audit_allow_fim_events=true
--events_max=10000
--audit_backlog_limit=10000
--audit_backlog_wait_time=60000
--audit_persist
Type: Close ProcessID: 26465 ImagePath: /bin/bash Data: Close /etc/a.conf StateChange: True
Type: Write ProcessID: 26465 ImagePath: /bin/bash Data: Write /etc/a.conf StateChange: True
Type: Open ProcessID: 26465 ImagePath: /bin/bash Data: Open /etc/a.conf StateChange: True
so, osquery is getting them