@clong Thanks for the article. It is really helpful. As you told that only three different syscall, can you tell me which three syscall it is able to monitor?
nishit
11/11/2017, 9:41 AM
@clong I know that go-audit will do better job in terms of syscall monitoring, but I just wanted to know whether it is possible using osquery to monitor syscall like auditd or go-audit does?