pirxthepilot
09/25/2018, 5:59 PMexecve
syscalls, is that correct? If so, is osquery not a good fit then if we want to log other syscalls (sethostname
, settimeofday
etc)? in our case we're trying to follow CIS standards and the benchmarks for audit require more than execve
.alessandrogario
09/25/2018, 7:43 PMpirxthepilot
09/25/2018, 7:50 PMalessandrogario
09/25/2018, 7:56 PM