auditd
| msgtype | Title | Description | Sample | Rule |
|---|---|---|---|---|
| 1005 | USERmsgtype 1005 | Message from userspace (deprecated) | Y | N |
| 1006 | LOGINmsgtype 1006 | Define the login ID and information | Y | N |
| 1100 | USER_ | User system access authentication | Y | Y |
| 1101 | USER_ | User system access authorization | Y | Y |
| 1102 | USER_ | User account attribute change | Y | N |
| 1103 | CRED_ | User credential acquired | Y | Y |
| 1104 | CRED_ | User credential disposed | Y | N |
| 1105 | USER_ | User session start | Y | Y |
| 1106 | USER_ | User session end | Y | Y |
| 1107 | USER_ | User space AVC (Access Vector Cache) message | Y | N |
| 1108 | USER_ | User account authentication token or attribute changed | Y | N |
| 1109 | USER_ | User account state error | Y | N |
| 1110 | CRED_ | User credential refreshed | Y | N |
| 1111 | USYS_ | User space system config change | Y | N |
| 1112 | USER_ | User login attempt (success or failure) | Y | Y |
| 1113 | USER_ | User has logged out | Y | N |
| 1114 | ADD_ | User account added | Y | Y |
| 1115 | DEL_ | User account deleted | Y | N |
| 1116 | ADD_ | Group account added | Y | N |
| 1117 | DEL_ | Group account deleted | Y | N |
| 1118 | DAC_ | User space DAC check results | N | N |
| 1119 | CHGRP_ | User space group ID changed | Y | N |
| 1120 | TESTmsgtype 1120 | Used for test success messages | N | N |
| 1121 | TRUSTED_ | Trusted app msg - freestyle text | Y | N |
| 1122 | USER_ | SELinux user space error | N | N |
| 1123 | USER_ | User shell command and args | Y | Y |
| 1124 | USER_ | Non-ICANON TTY input meaning | Y | Y |
| 1125 | CHUSER_ | Changed user ID supplemental data | N | N |
| 1126 | GRP_ | Authentication for group password | Y | N |
| 1127 | SYSTEM_ | System boot | Y | N |
| 1128 | SYSTEM_ | System shutdown | Y | N |
| 1129 | SYSTEM_ | System runlevel change | Y | N |
| 1130 | SERVICE_ | Service (daemon) start | Y | N |
| 1131 | SERVICE_ | Service (daemon) stop | Y | Y |
| 1132 | GRP_ | Group account attribute was modified | Y | N |
| 1133 | GRP_ | Group account password or PIN changed | Y | N |
| 1134 | MAC_ | User space MAC (Mandatory Access Control) decision results | N | N |
| 1135 | ACCT_ | User's account locked by admin | Y | N |
| 1136 | ACCT_ | User's account unlocked by admin | Y | N |
| 1137 | USER_ | User space hotplug device changes | Y | N |
| 1138 | SOFTWARE_ | Software update event | Y | N |
| 1200 | DAEMON_ | Daemon startup record | Y | Y |
| 1201 | DAEMON_ | Daemon normal stop record | Y | Y |
| 1202 | DAEMON_ | Daemon error stop record | Y | Y |
| 1203 | DAEMON_ | Daemon config change | Y | N |
| 1205 | DAEMON_ | Auditd should rotate logs | Y | N |
| 1206 | DAEMON_ | Auditd should resume logging | Y | N |
| 1207 | DAEMON_ | Auditd accepted remote connection | Y | N |
| 1208 | DAEMON_ | Auditd closed remote connection | Y | N |
| 1209 | DAEMON_ | Auditd internal error | N | N |
| 1300 | SYSCALLmsgtype 1300 | System call event information | Y | Y |
| 1302 | PATHmsgtype 1302 | Filename path information | Y | Y |
| 1303 | IPCmsgtype 1303 | System call IPC (Inter-Process Communication) object | Y | N |
| 1304 | SOCKETCALLmsgtype 1304 | System call socketcall arguments | Y | N |
| 1305 | CONFIG_ | Audit system configuration change | Y | N |
| 1306 | SOCKADDRmsgtype 1306 | System call socket address argument information | Y | N |
| 1307 | CWDmsgtype 1307 | Current working directory | Y | Y |
| 1309 | EXECVEmsgtype 1309 | Arguments supplied to the execve system call | Y | Y |
| 1311 | IPC_ | IPC new permissions record type | Y | N |
| 1312 | MQ_ | POSIX MQ open record type | Y | N |
| 1313 | MQ_ | POSIX MQ send/receive record type | Y | N |
| 1314 | MQ_ | POSIX MQ notify record type | Y | N |
| 1315 | MQ_ | POSIX MQ get/set attribute record type | Y | N |
| 1316 | KERNEL_ | For use by 3rd party modules | N | N |
| 1317 | FD_ | Information for pipe and socketpair system calls | Y | N |
| 1318 | OBJ_ | Target process information for ptrace, kill, tkill, and tgkill syscalls | Y | N |
| 1319 | TTYmsgtype 1319 | Input on an administrative TTY | Y | Y |
| 1320 | EOEmsgtype 1320 | End of multi-record event | Y | N |
| 1321 | BPRM_ | Information about file system capabilities increasing permissions | Y | Y |
| 1322 | CAPSETmsgtype 1322 | Record showing argument to sys_capset setting process-based capabilities | Y | N |
| 1323 | MMAPmsgtype 1323 | Mmap system call file descriptor and flags | Y | N |
| 1324 | NETFILTER_ | Packets traversing netfilter chains | Y | N |
| 1325 | NETFILTER_ | Netfilter chain modifications | Y | N |
| 1326 | SECCOMPmsgtype 1326 | Secure Computing event | Y | N |
| 1327 | PROCTITLEmsgtype 1327 | Process Title info | Y | Y |
| 1328 | FEATURE_ | Audit feature changed value | Y | N |
| 1330 | KERN_ | Kernel Module events | Y | N |
| 1331 | FANOTIFYmsgtype 1331 | Fanotify access decision | Y | N |
| 1332 | TIME_ | Timekeeping offset injected | Y | N |
| 1333 | TIME_ | NTP value adjustment | Y | N |
| 1334 | BPFmsgtype 1334 | BPF load/unload | Y | N |
| 1335 | EVENT_ | audit mcast sock join/part | Y | N |
| 1336 | URINGOPmsgtype 1336 | io_uring operation | Y | N |
| 1337 | OPENAT2msgtype 1337 | Record showing openat2 how args | Y | N |
| 1338 | DM_ | Device Mapper target control | Y | N |
| 1339 | DM_ | Device Mapper events | Y | N |
| 1400 | AVCmsgtype 1400 | SELinux AVC (Access Vector Cache) denial or grant | Y | N |
| 1401 | SELINUX_ | Internal SELinux errors | Y | N |
| 1402 | AVC_ | dentry, vfsmount pair from AVC | N | N |
| 1403 | MAC_ | SELinux Policy file load | Y | N |
| 1404 | MAC_ | SELinux mode (enforcing, permissive, off) changed | Y | N |
| 1405 | MAC_ | SELinux Boolean value modification | Y | N |
| 1406 | MAC_ | NetLabel: allow unlabeled traffic | Y | N |
| 1407 | MAC_ | NetLabel: add CIPSOv4 (Commercial Internet Protocol Security Option) DOI (Domain of Interpretation) entry | Y | N |
| 1408 | MAC_ | NetLabel: del CIPSOv4 (Commercial Internet Protocol Security Option) DOI (Domain of Interpretation) entry | Y | N |
| 1409 | MAC_ | NetLabel: add LSM (Linux Security Module) domain mapping | Y | N |
| 1410 | MAC_ | NetLabel: del LSM (Linux Security Module) domain mapping | Y | N |
| 1411 | MAC_ | Not used | N | N |
| 1412 | MAC_ | Not used | N | N |
| 1413 | MAC_ | Not used | N | N |
| 1414 | MAC_ | Not used | N | N |
| 1415 | MAC_ | Audit an IPsec event | Y | N |
| 1416 | MAC_ | NetLabel: add a static label | Y | N |
| 1417 | MAC_ | NetLabel: del a static label | Y | N |
| 1418 | MAC_ | NetLabel: add CALIPSO DOI (Domain of Interpretation) entry | Y | N |
| 1419 | MAC_ | NetLabel: delete CALIPSO DOI (Domain of Interpretation) entry | Y | N |
| 1420 | IPE_ | Integrity Policy Enforcement (IPE) access decision (denial or grant) | Y | N |
| 1421 | IPE_ | IPE active policy change | Y | N |
| 1422 | IPE_ | IPE policy load | Y | N |
| 1423 | LANDLOCK_ | Landlock access denial | Y | N |
| 1424 | LANDLOCK_ | Landlock domain allocation or deallocation status | Y | N |
| 1425 | MAC_ | Subject security contexts when multiple LSMs are active | N | N |
| 1426 | MAC_ | Object security contexts when multiple LSMs are active | N | N |
| 1500 | APPARMORmsgtype 1500 | AppArmor LSM audit event | N | N |
| 1501 | APPARMOR_ | AppArmor access decision logged in audit mode | N | N |
| 1502 | APPARMOR_ | AppArmor access allowed (complain or learning mode) | N | N |
| 1503 | APPARMOR_ | AppArmor access denied in enforce mode | N | N |
| 1504 | APPARMOR_ | AppArmor reserved audit type (unused in the current kernel) | N | N |
| 1505 | APPARMOR_ | AppArmor policy load or status change | N | N |
| 1506 | APPARMOR_ | AppArmor internal error | N | N |
| 1507 | APPARMOR_ | AppArmor access denied with task kill | N | N |
| 1700 | ANOM_ | Device changed promiscuous mode | Y | N |
| 1701 | ANOM_ | Process ended abnormally | Y | N |
| 1702 | ANOM_ | Suspicious use of file links | Y | N |
| 1703 | ANOM_ | Suspicious file creation | Y | N |
| 1800 | INTEGRITY_ | Data integrity verification | Y | N |
| 1801 | INTEGRITY_ | Metadata integrity verification | Y | N |
| 1802 | INTEGRITY_ | Integrity enable status | Y | N |
| 1803 | INTEGRITY_ | Integrity HASH type | N | N |
| 1804 | INTEGRITY_ | PCR (Platform Configuration Register) invalidation messages | Y | N |
| 1805 | INTEGRITY_ | Integrity Policy action | Y | N |
| 1806 | INTEGRITY_ | EVM XATTRS modifications | Y | N |
| 1807 | INTEGRITY_ | Integrity Policy rule | Y | N |
| 1808 | INTEGRITY_ | IMA appraisal of userspace-supplied data | Y | N |
| 2000 | KERNELmsgtype 2000 | Kernel audit status | N | N |
| 2100 | ANOM_ | Failed login limit reached | Y | N |
| 2101 | ANOM_ | Login attempted at bad time | Y | N |
| 2102 | ANOM_ | Maximum concurrent sessions reached | Y | N |
| 2103 | ANOM_ | Login attempted to watched account | Y | N |
| 2104 | ANOM_ | Login from forbidden location | Y | N |
| 2105 | ANOM_ | Max DAC (Discretionary Access Control) failures reached | Y | N |
| 2106 | ANOM_ | Max MAC (Mandatory Access Control) failures reached | Y | N |
| 2107 | ANOM_ | AMTU (Abstract Machine Test Utility) failure | Y | N |
| 2108 | ANOM_ | RBAC (Role-Based Access Control) self test failure | Y | N |
| 2109 | ANOM_ | RBAC (Role-Based Access Control) file integrity test failure | Y | N |
| 2110 | ANOM_ | Crypto system test failure | Y | N |
| 2111 | ANOM_ | Access of file or directory ended abnormally | Y | N |
| 2112 | ANOM_ | Execution of file ended abnormally | Y | N |
| 2113 | ANOM_ | Make an executable | Y | N |
| 2114 | ANOM_ | Adding a user account ended abnormally | Y | N |
| 2115 | ANOM_ | Deleting a user account ended abnormally | Y | N |
| 2116 | ANOM_ | Changing an account ended abnormally | Y | N |
| 2117 | ANOM_ | User became root | Y | N |
| 2118 | ANOM_ | Service acct attempted login | Y | N |
| 2119 | ANOM_ | Root login attempted | Y | N |
| 2120 | ANOM_ | Origin has too many failed login attempts | Y | N |
| 2121 | ANOM_ | The user session is bad | Y | N |
| 2200 | RESP_ | Anomaly not reacted to | Y | N |
| 2201 | RESP_ | Alert notification action (email or log): the email/log reactions are unimplemented FIXME stubs in upstream audisp-ids 3.x (reactions.c:370-372); emittable by custom plugins | Y | N |
| 2202 | RESP_ | Kill program | Y | N |
| 2203 | RESP_ | Terminate session | Y | N |
| 2204 | RESP_ | User account locked from remote access | Y | N |
| 2205 | RESP_ | User account locked for time | Y | N |
| 2206 | RESP_ | User account unlocked from time | Y | N |
| 2207 | RESP_ | User account was locked | Y | N |
| 2208 | RESP_ | Terminal was locked | Y | N |
| 2209 | RESP_ | Set an SELinux boolean | Y | N |
| 2210 | RESP_ | Execute a script | Y | N |
| 2211 | RESP_ | Go to single user mode | Y | N |
| 2212 | RESP_ | Take the system down | Y | N |
| 2213 | RESP_ | Remote address blocked by firewall rule (iptables or nftables depending on system configuration) | Y | N |
| 2214 | RESP_ | Address blocked for time | Y | N |
| 2215 | RESP_ | Address unblocked from timed | Y | N |
| 2300 | USER_ | User changed to a new SELinux role | Y | N |
| 2301 | ROLE_ | Administrator assigned user to SELinux role | Y | N |
| 2302 | ROLE_ | Administrator removed user from SELinux role | Y | N |
| 2303 | LABEL_ | Administrator is overriding a SELinux label | Y | N |
| 2304 | LABEL_ | Object level SELinux label modified | Y | N |
| 2305 | USER_ | Object exported with SELinux label | Y | N |
| 2306 | USER_ | Object exported without SELinux label | N | N |
| 2307 | DEV_ | Device was allocated | N | N |
| 2308 | DEV_ | Device was deallocated | N | N |
| 2309 | FS_ | Filesystem relabeled | Y | N |
| 2310 | USER_ | Userspace daemon loaded SELinux policy | Y | N |
| 2311 | ROLE_ | Administrator modified an SELinux role | N | N |
| 2312 | USER_ | Change made to MAC (Mandatory Access Control) policy | Y | N |
| 2313 | USER_ | Userspace daemon enforcing change | Y | N |
| 2400 | CRYPTO_ | Cryptographic test results | Y | N |
| 2401 | CRYPTO_ | Cryptographic attribute change | Y | N |
| 2402 | CRYPTO_ | Cryptographic officer login | Y | N |
| 2403 | CRYPTO_ | Cryptographic officer logout | Y | N |
| 2404 | CRYPTO_ | Create, delete, negotiate cryptographic key identifier | Y | N |
| 2405 | CRYPTO_ | Fail decrypt, encrypt or randomize operation | Y | N |
| 2406 | CRYPTO_ | Cryptographic replay attack detected | N | N |
| 2407 | CRYPTO_ | Parameters set during TLS session establishment | Y | N |
| 2408 | CRYPTO_ | Parameters related to IKE SA | Y | N |
| 2409 | CRYPTO_ | Parameters related to IPSEC SA | Y | N |
| 2500 | VIRT_ | Start, Pause, Stop VM | Y | N |
| 2501 | VIRT_ | Resource assignment | Y | N |
| 2502 | VIRT_ | Binding of label to VM | Y | N |
| 2503 | VIRT_ | Guest integrity results | N | N |
| 2504 | VIRT_ | Creation of guest image | N | N |
| 2505 | VIRT_ | Destruction of guest image | N | N |
| 2506 | VIRT_ | Inbound guest migration info | N | N |
| 2507 | VIRT_ | Outbound guest migration info | N | N |
USER msgtype 1005
#Description
Message from userspace (deprecated)
Fields #
| Name | Description |
|---|---|
text | free-form message text supplied by the sender (auditctl -m / audit_log_user_message) |
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "1000",
"exe": "/usr/sbin/auditctl",
"hostname": "?",
"pid": "2909",
"res": "success",
"ses": "1",
"subj": "unconfined_u:unconfined_r:auditctl_t:s0-s0:c0.c1023",
"terminal": "?",
"text": "CATALOG_RESP_DEMO",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=USER msg=audit(1781634271.615:539452): pid=2909 uid=0 auid=1000 ses=1 subj=unconfined_u:unconfined_r:auditctl_t:s0-s0:c0.c1023 msg='text=CATALOG_RESP_DEMO exe=\"/usr/sbin/auditctl\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"debian\""
],
"record_type": "USER"
}
LOGIN msgtype 1006
#Description
Define the login ID and information
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
subj | lspp subject's context string |
old-auid | audit login UID before this login record set it |
auid | login user ID |
tty | tty udevice the user is running programs on |
old-ses | session ID before this login record set it |
ses | login session ID |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"auid": "1003",
"old-auid": "4294967295",
"old-ses": "4294967295",
"pid": "51529",
"res": "1",
"ses": "17",
"subj": "unconfined",
"tty": "(none)",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=LOGIN msg=audit(1781632420.123:1880745): pid=51529 uid=0 subj=unconfined old-auid=4294967295 auid=1003 tty=(none) old-ses=4294967295 ses=17 res=1",
"UID=\"root\" OLD-AUID=\"unset\" AUID=\"r2usr\""
],
"record_type": "LOGIN"
}
References #
USER_AUTH msgtype 1100
#Description
User system access authentication
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
grantors | PAM modules that granted (or would deny) the operation |
acct | a user's account name |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"acct": "debian",
"addr": "10.2.20.61",
"auid": "4294967295",
"exe": "/usr/sbin/sshd",
"grantors": "pam_permit",
"hostname": "10.2.20.61",
"op": "PAM:authentication",
"pid": "996",
"res": "success",
"ses": "4294967295",
"subj": "system_u:system_r:sshd_t:s0",
"terminal": "ssh",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=USER_AUTH msg=audit(1781634177.456:177708): pid=996 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0 msg='op=PAM:authentication grantors=pam_permit acct=\"debian\" exe=\"/usr/sbin/sshd\" hostname=10.2.20.61 addr=10.2.20.61 terminal=ssh res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "USER_AUTH"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
prefix | eq | src_ | 1 rule | splunk |
type | in | user_auth | 1 rule | splunk |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Splunk #
T1110, T1110.001, T1110.003
USER_ACCT msgtype 1101
#Description
User system access authorization
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
grantors | PAM modules that granted (or would deny) the operation |
acct | a user's account name |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"acct": "root",
"addr": "?",
"auid": "4294967295",
"exe": "/usr/bin/sudo",
"grantors": "pam_permit",
"hostname": "?",
"op": "PAM:accounting",
"pid": "2759",
"res": "success",
"ses": "4294967295",
"subj": "system_u:system_r:initrc_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=USER_ACCT msg=audit(1781634264.630:525236): pid=2759 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:initrc_t:s0 msg='op=PAM:accounting grantors=pam_permit acct=\"root\" exe=\"/usr/bin/sudo\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "USER_ACCT"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
CommandLine | contains | .sh | 1 rule | splunk |
CommandLine | contains | list | 1 rule | splunk |
exe | in | /usr/bin/sudo | 1 rule | splunk |
type | in | cred_acq | 1 rule | splunk |
type | in | user_acct | 1 rule | splunk |
type | in | user_cmd | 1 rule | splunk |
USER_MGMT msgtype 1102
#Description
User account attribute change
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
op | the operation being performed that is audited |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "4294967295",
"exe": "/usr/sbin/useradd",
"hostname": "?",
"id": "1000",
"op": "add-home-dir",
"pid": "1264",
"res": "success",
"ses": "4294967295",
"subj": "system_u:system_r:unconfined_service_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"type=USER_MGMT msg=audit(1481076992.521:393): pid=1264 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:unconfined_service_t:s0 msg='op=add-home-dir id=1000 exe=\"/usr/sbin/useradd\" hostname=? addr=? terminal=? res=success'"
],
"record_type": "USER_MGMT"
}
Example keys not documented in the fields table: id
CRED_ACQ msgtype 1103
#Description
User credential acquired
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
grantors | PAM modules that granted (or would deny) the operation |
acct | a user's account name |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"acct": "debian",
"addr": "10.2.20.61",
"auid": "4294967295",
"exe": "/usr/sbin/sshd",
"grantors": "pam_permit",
"hostname": "10.2.20.61",
"op": "PAM:setcred",
"pid": "996",
"res": "success",
"ses": "4294967295",
"subj": "system_u:system_r:sshd_t:s0",
"terminal": "ssh",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=CRED_ACQ msg=audit(1781634177.503:178599): pid=996 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0 msg='op=PAM:setcred grantors=pam_permit acct=\"debian\" exe=\"/usr/sbin/sshd\" hostname=10.2.20.61 addr=10.2.20.61 terminal=ssh res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "CRED_ACQ"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
CommandLine | contains | .sh | 1 rule | splunk |
CommandLine | contains | list | 1 rule | splunk |
exe | in | /usr/bin/sudo | 1 rule | splunk |
type | in | cred_acq | 1 rule | splunk |
type | in | user_acct | 1 rule | splunk |
type | in | user_cmd | 1 rule | splunk |
CRED_DISP msgtype 1104
#Description
User credential disposed
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
grantors | PAM modules that granted (or would deny) the operation |
acct | a user's account name |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"acct": "root",
"addr": "?",
"auid": "1000",
"exe": "/usr/bin/sudo",
"grantors": "pam_permit",
"hostname": "?",
"op": "PAM:setcred",
"pid": "4342",
"res": "success",
"ses": "1",
"subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
"terminal": "?",
"uid": "1000"
},
"raw": [
"node=JD-debian-12-workstation type=CRED_DISP msg=audit(1781634357.202:597381): pid=4342 uid=1000 auid=1000 ses=1 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=PAM:setcred grantors=pam_permit acct=\"root\" exe=\"/usr/bin/sudo\" hostname=? addr=? terminal=? res=success'",
"UID=\"debian\" AUID=\"debian\""
],
"record_type": "CRED_DISP"
}
USER_START msgtype 1105
#Description
User session start
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
grantors | PAM modules that granted (or would deny) the operation |
acct | a user's account name |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"acct": "root",
"addr": "?",
"auid": "1000",
"exe": "/usr/bin/sudo",
"grantors": "pam_limits,pam_permit,pam_unix",
"hostname": "?",
"op": "PAM:session_open",
"pid": "4342",
"res": "success",
"ses": "1",
"subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
"terminal": "?",
"uid": "1000"
},
"raw": [
"node=JD-debian-12-workstation type=USER_START msg=audit(1781634338.070:594674): pid=4342 uid=1000 auid=1000 ses=1 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=PAM:session_open grantors=pam_limits,pam_permit,pam_unix acct=\"root\" exe=\"/usr/bin/sudo\" hostname=? addr=? terminal=? res=success'",
"UID=\"debian\" AUID=\"debian\""
],
"record_type": "USER_START"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
CommandLine | contains | .sh | 1 rule | splunk |
CommandLine | contains | list | 1 rule | splunk |
exe | in | /usr/bin/sudo | 1 rule | splunk |
prefix | eq | src_ | 1 rule | splunk |
type | in | cred_acq | 1 rule | splunk |
type | in | user_acct | 1 rule | splunk |
type | in | user_cmd | 1 rule | splunk |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Splunk #
T1078, T1078.001
USER_END msgtype 1106
#Description
User session end
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
grantors | PAM modules that granted (or would deny) the operation |
acct | a user's account name |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"acct": "root",
"addr": "?",
"auid": "1000",
"exe": "/usr/bin/sudo",
"grantors": "pam_limits,pam_permit,pam_unix",
"hostname": "?",
"op": "PAM:session_close",
"pid": "4342",
"res": "success",
"ses": "1",
"subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
"terminal": "?",
"uid": "1000"
},
"raw": [
"node=JD-debian-12-workstation type=USER_END msg=audit(1781634357.202:597371): pid=4342 uid=1000 auid=1000 ses=1 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=PAM:session_close grantors=pam_limits,pam_permit,pam_unix acct=\"root\" exe=\"/usr/bin/sudo\" hostname=? addr=? terminal=? res=success'",
"UID=\"debian\" AUID=\"debian\""
],
"record_type": "USER_END"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
CommandLine | contains | .sh | 1 rule | splunk |
CommandLine | contains | list | 1 rule | splunk |
exe | in | /usr/bin/sudo | 1 rule | splunk |
type | in | cred_acq | 1 rule | splunk |
type | in | user_acct | 1 rule | splunk |
type | in | user_cmd | 1 rule | splunk |
USER_AVC msgtype 1107
#Description
User space AVC (Access Vector Cache) message
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
msgtype | userspace AVC message type |
interface | D-Bus interface of the userspace AVC |
member | D-Bus member (method or signal) of the userspace AVC |
dest | D-Bus destination of the userspace AVC |
spid | sent process ID |
tpid | target process ID of the userspace AVC |
scontext | the subject's context string |
tcontext | the target's or object's context string |
tclass | target's object classification |
permissive | SELinux is in permissive mode |
exe | executable name |
sauid | sent login user ID |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "4294967295",
"dest": ":1.5",
"exe": "/usr/bin/dbus-daemon",
"hostname": "?",
"msgtype": "method_return",
"permissive": "1",
"pid": "504",
"sauid": "100",
"scontext": "system_u:system_r:systemd_logind_t:s0",
"ses": "4294967295",
"spid": "514",
"subj": "system_u:system_r:system_dbusd_t:s0",
"tclass": "dbus",
"tcontext": "system_u:system_r:virtd_t:s0",
"terminal": "?",
"tpid": "538",
"uid": "100"
},
"raw": [
"node=JD-debian-12-workstation type=USER_AVC msg=audit(1781634167.497:12119): pid=504 uid=100 auid=4294967295 ses=4294967295 subj=system_u:system_r:system_dbusd_t:s0 msg='avc: denied { send_msg } for msgtype=method_return dest=:1.5 spid=514 tpid=538 scontext=system_u:system_r:systemd_logind_t:s0 tcontext=system_u:system_r:virtd_t:s0 tclass=dbus permissive=1 exe=\"/usr/bin/dbus-daemon\" sauid=100 hostname=? addr=? terminal=?'",
"UID=\"messagebus\" AUID=\"unset\" SAUID=\"messagebus\""
],
"record_type": "USER_AVC"
}
USER_CHAUTHTOK msgtype 1108
#Description
User account authentication token or attribute changed
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
acct | a user's account name |
id | the numeric UID of the account (emitted when the name is unavailable; mutually exclusive with acct) |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"acct": "r2grp2",
"addr": "?",
"auid": "1000",
"exe": "/usr/bin/gpasswd",
"hostname": "?",
"op": "password",
"pid": "51492",
"res": "success",
"ses": "15",
"subj": "unconfined",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=USER_CHAUTHTOK msg=audit(1781632419.739:1879192): pid=51492 uid=0 auid=1000 ses=15 subj=unconfined msg='op=password of group r2grp2 removed by root acct=\"r2grp2\" exe=\"/usr/bin/gpasswd\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"debian\""
],
"record_type": "USER_CHAUTHTOK"
}
USER_ERR msgtype 1109
#Description
User account state error
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
grantors | PAM modules that granted (or would deny) the operation |
acct | a user's account name |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"acct": "?",
"addr": "127.0.0.1",
"auid": "4294967295",
"exe": "/usr/sbin/sshd",
"grantors": "?",
"hostname": "127.0.0.1",
"op": "PAM:bad_ident",
"pid": "29600",
"res": "failed",
"ses": "4294967295",
"subj": "unconfined",
"terminal": "ssh",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=USER_ERR msg=audit(1781630273.728:1288286): pid=29600 uid=0 auid=4294967295 ses=4294967295 subj=unconfined msg='op=PAM:bad_ident grantors=? acct=\"?\" exe=\"/usr/sbin/sshd\" hostname=127.0.0.1 addr=127.0.0.1 terminal=ssh res=failed'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "USER_ERR"
}
CRED_REFR msgtype 1110
#Description
User credential refreshed
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
grantors | PAM modules that granted (or would deny) the operation |
acct | a user's account name |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"acct": "root",
"addr": "?",
"auid": "1000",
"exe": "/usr/bin/sudo",
"grantors": "pam_permit",
"hostname": "?",
"op": "PAM:setcred",
"pid": "4342",
"res": "success",
"ses": "1",
"subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
"terminal": "?",
"uid": "1000"
},
"raw": [
"node=JD-debian-12-workstation type=CRED_REFR msg=audit(1781634338.070:594660): pid=4342 uid=1000 auid=1000 ses=1 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=PAM:setcred grantors=pam_permit acct=\"root\" exe=\"/usr/bin/sudo\" hostname=? addr=? terminal=? res=success'",
"UID=\"debian\" AUID=\"debian\""
],
"record_type": "CRED_REFR"
}
USYS_CONFIG msgtype 1111
#Description
User space system config change
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "4294967295",
"exe": "/usr/sbin/hwclock",
"hostname": "?",
"pid": "1232",
"res": "success",
"ses": "4294967295",
"subj": "system_u:system_r:unconfined_service_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"type=USYS_CONFIG msg=audit(1481076993.000:402): pid=1232 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:unconfined_service_t:s0 msg='changing system time exe=\"/usr/sbin/hwclock\" hostname=? addr=? terminal=? res=success'"
],
"record_type": "USYS_CONFIG"
}
USER_LOGIN msgtype 1112
#Description
User login attempt (success or failure)
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
acct | a user's account name |
id | the numeric UID of the account (emitted when the name is unavailable; mutually exclusive with acct) |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"acct": "debian",
"addr": "10.2.20.61",
"auid": "4294967295",
"exe": "/usr/sbin/sshd",
"hostname": "?",
"op": "login",
"pid": "996",
"res": "failed",
"ses": "4294967295",
"subj": "system_u:system_r:sshd_t:s0",
"terminal": "sshd",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=USER_LOGIN msg=audit(1781634177.416:176875): pid=996 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0 msg='op=login acct=\"debian\" exe=\"/usr/sbin/sshd\" hostname=? addr=10.2.20.61 terminal=sshd res=failed'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "USER_LOGIN"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
type | in | user_auth | 1 rule | splunk |
USER_LOGOUT msgtype 1113
#Description
User has logged out
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
op | the operation being performed that is audited |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "1000",
"exe": "/usr/sbin/sshd",
"hostname": "?",
"id": "1000",
"op": "login",
"pid": "1298",
"res": "success",
"ses": "1",
"subj": "system_u:system_r:sshd_t:s0-s0:c0.c1023",
"terminal": "/dev/pts/0",
"uid": "0"
},
"raw": [
"type=USER_LOGOUT msg=audit(1481077049.033:424): pid=1298 uid=0 auid=1000 ses=1 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=1000 exe=\"/usr/sbin/sshd\" hostname=? addr=? terminal=/dev/pts/0 res=success'"
],
"record_type": "USER_LOGOUT"
}
Example keys not documented in the fields table: id
ADD_USER msgtype 1114
#Description
User account added
Fields #
| Name | Description | Rules |
|---|---|---|
pid | process ID | |
uid | user ID | |
auid | login user ID | |
ses | login session ID | |
subj | lspp subject's context string | |
op | the operation being performed that is audited | |
id | the numeric UID of the account (emitted when the name is unavailable; mutually exclusive with acct) | |
exe | executable name | 1 detection rule |
hostname | the hostname that the user is connecting from | |
addr | the remote address that the user is connecting from | |
terminal | terminal name the user is running programs on | |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "1000",
"exe": "/usr/sbin/useradd",
"hostname": "?",
"id": "1004",
"op": "adding",
"pid": "2811",
"res": "success",
"ses": "1",
"subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=ADD_USER msg=audit(1781634268.083:529550): pid=2811 uid=0 auid=1000 ses=1 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=adding user id=1004 exe=\"/usr/sbin/useradd\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"debian\" ID=\"r3usr\""
],
"record_type": "ADD_USER"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
type | eq | add_user | 2 rules | sigma, splunk |
type | eq | syscall | 1 rule | sigma |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Splunk #
T1136, T1136.001
DEL_USER msgtype 1115
#Description
User account deleted
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
acct | a user's account name |
id | the numeric UID of the account (emitted when the name is unavailable; mutually exclusive with acct) |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "1000",
"exe": "/usr/sbin/userdel",
"hostname": "?",
"id": "1004",
"op": "deleting",
"pid": "2901",
"res": "success",
"ses": "1",
"subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=DEL_USER msg=audit(1781634271.403:539248): pid=2901 uid=0 auid=1000 ses=1 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=deleting user entries id=1004 exe=\"/usr/sbin/userdel\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"debian\" ID=\"r3usr\""
],
"record_type": "DEL_USER"
}
ADD_GROUP msgtype 1116
#Description
Group account added
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
acct | a user's account name |
id | the numeric GID of the group (emitted when the name is unavailable; mutually exclusive with acct) |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"acct": "r3usr",
"addr": "?",
"auid": "1000",
"exe": "/usr/sbin/useradd",
"hostname": "?",
"op": "adding",
"pid": "2811",
"res": "success",
"ses": "1",
"subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=ADD_GROUP msg=audit(1781634268.083:529538): pid=2811 uid=0 auid=1000 ses=1 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=adding group acct=\"r3usr\" exe=\"/usr/sbin/useradd\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"debian\""
],
"record_type": "ADD_GROUP"
}
DEL_GROUP msgtype 1117
#Description
Group account deleted
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
acct | a user's account name |
id | the numeric GID of the group (emitted when the name is unavailable; mutually exclusive with acct) |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"acct": "r3usr",
"addr": "?",
"auid": "1000",
"exe": "/usr/sbin/userdel",
"hostname": "?",
"op": "deleting",
"pid": "2901",
"res": "success",
"ses": "1",
"subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=DEL_GROUP msg=audit(1781634271.403:539258): pid=2901 uid=0 auid=1000 ses=1 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=deleting group acct=\"r3usr\" exe=\"/usr/sbin/userdel\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"debian\""
],
"record_type": "DEL_GROUP"
}
DAC_CHECK msgtype 1118
#Description
User space DAC check results
CHGRP_ID msgtype 1119
#Description
User space group ID changed
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "1000",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"pid": "28679",
"res": "success",
"ses": "1",
"subj": "unconfined",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=CHGRP_ID msg=audit(1781630189.242:1259446): pid=28679 uid=0 auid=1000 ses=1 subj=unconfined msg='chgrp-test-verify exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"debian\""
],
"record_type": "CHGRP_ID"
}
TEST msgtype 1120
#Description
Used for test success messages
TRUSTED_APP msgtype 1121
#Description
Trusted app msg - freestyle text
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
op | the operation being performed that is audited |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "1000",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"op": "catalog-sample",
"pid": "51615",
"res": "success",
"ses": "15",
"subj": "unconfined",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=TRUSTED_APP msg=audit(1781632421.163:1883922): pid=51615 uid=0 auid=1000 ses=15 subj=unconfined msg='op=catalog-sample trusted-app exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'"
],
"record_type": "TRUSTED_APP"
}
USER_SELINUX_ERR msgtype 1122
#Description
SELinux user space error
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
USER_CMD msgtype 1123
#Description
User shell command and args
Fields #
| Name | Description |
|---|---|
pid | Process ID |
uid | User ID |
auid | Audit user ID (login UID) |
ses | Session ID |
subj | SELinux security context of the subject |
cwd | Current working directory when the command ran |
cmd | Command that was executed |
exe | Executable that ran the command (sudo) |
terminal | Terminal |
res | Result (success or failed) |
Example Audit Record #
{
"fields": {
"auid": "4294967295",
"cmd": "6A757079746572206C6162202D2D5365727665724170702E616C6C6F775F72656D6F74655F6163636573733D74727565202D2D5365727665724170702E6F70656E5F62726F777365723D66616C7365202D2D4964656E7469747950726F76696465722E746F6B656E3D6D7974686963202D2D5365727665724170702E626173655F75726C3D2F6A757079746572202D2D5365727665724170702E64656661756C745F75726C3D2F6A757079746572202D2D706F72743D38383838202D2D69703D302E302E302E30",
"cwd": "/projects",
"exe": "/usr/bin/sudo",
"pid": "2759",
"res": "success",
"ses": "4294967295",
"subj": "system_u:system_r:initrc_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=USER_CMD msg=audit(1781634264.630:525243): pid=2759 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:initrc_t:s0 msg='cwd=\"/projects\" cmd=6A757079746572206C6162202D2D5365727665724170702E616C6C6F775F72656D6F74655F6163636573733D74727565202D2D5365727665724170702E6F70656E5F62726F777365723D66616C7365202D2D4964656E7469747950726F76696465722E746F6B656E3D6D7974686963202D2D5365727665724170702E626173655F75726C3D2F6A757079746572202D2D5365727665724170702E64656661756C745F75726C3D2F6A757079746572202D2D706F72743D38383838202D2D69703D302E302E302E30 exe=\"/usr/bin/sudo\" terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "USER_CMD"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
type | in | user_cmd | 2 rules | splunk |
type | in | cred_acq | 1 rule | splunk |
type | in | execve | 1 rule | splunk |
type | in | proctitle | 1 rule | splunk |
type | in | user_acct | 1 rule | splunk |
CommandLine | contains | .sh | 1 rule | splunk |
CommandLine | contains | list | 1 rule | splunk |
exe | in | /usr/bin/sudo | 1 rule | splunk |
USER_TTY msgtype 1124
#Description
Non-ICANON TTY input meaning
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
data | TTY text |
Example Audit Record #
{
"fields": {
"auid": "1000",
"data": "7375202D20616E647265775F6B726F68",
"pid": "28058",
"ses": "762",
"subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
"uid": "0"
},
"raw": [
"type=USER_TTY msg=audit(1491922681.082:1065050): pid=28058 uid=0 auid=1000 ses=762 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 data=7375202D20616E647265775F6B726F68"
],
"record_type": "USER_TTY"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
name | eq | /etc/pam.d/system-auth | 1 rule | sigma |
type | eq | path | 1 rule | sigma |
CHUSER_ID msgtype 1125
#Description
Changed user ID supplemental data
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
GRP_AUTH msgtype 1126
#Description
Authentication for group password
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "1000",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"pid": "28917",
"res": "success",
"ses": "1",
"subj": "unconfined",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=GRP_AUTH msg=audit(1781630215.758:1267010): pid=28917 uid=0 auid=1000 ses=1 subj=unconfined msg='grp-auth-test exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"debian\""
],
"record_type": "GRP_AUTH"
}
SYSTEM_BOOT msgtype 1127
#Description
System boot
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
comm | command line program name |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "4294967295",
"comm": "systemd-update-utmp",
"exe": "/usr/lib/systemd/systemd-update-utmp",
"hostname": "?",
"pid": "500",
"res": "success",
"ses": "4294967295",
"subj": "system_u:system_r:initrc_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=SYSTEM_BOOT msg=audit(1781634166.940:1739): pid=500 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:initrc_t:s0 msg=' comm=\"systemd-update-utmp\" exe=\"/usr/lib/systemd/systemd-update-utmp\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "SYSTEM_BOOT"
}
SYSTEM_SHUTDOWN msgtype 1128
#Description
System shutdown
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
comm | command line program name |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "4294967295",
"comm": "systemd-update-utmp",
"exe": "/usr/lib/systemd/systemd-update-utmp",
"hostname": "?",
"pid": "1261",
"res": "success",
"ses": "4294967295",
"subj": "unconfined",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=SYSTEM_SHUTDOWN msg=audit(1781627515.990:129066): pid=1261 uid=0 auid=4294967295 ses=4294967295 subj=unconfined msg=' comm=\"systemd-update-utmp\" exe=\"/usr/lib/systemd/systemd-update-utmp\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "SYSTEM_SHUTDOWN"
}
SYSTEM_RUNLEVEL msgtype 1129
#Description
System runlevel change
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
old-level | previous system runlevel |
new-level | new system runlevel |
comm | command line program name |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "4294967295",
"comm": "systemd-update-utmp",
"exe": "/usr/lib/systemd/systemd-update-utmp",
"hostname": "?",
"new-level": "5",
"old-level": "N",
"pid": "3722",
"res": "success",
"ses": "4294967295",
"subj": "system_u:system_r:initrc_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=SYSTEM_RUNLEVEL msg=audit(1781634283.021:560212): pid=3722 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:initrc_t:s0 msg='old-level=N new-level=5 comm=\"systemd-update-utmp\" exe=\"/usr/lib/systemd/systemd-update-utmp\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "SYSTEM_RUNLEVEL"
}
SERVICE_START msgtype 1130
#Description
Service (daemon) start
Fields #
| Name | Description |
|---|---|
pid | Process ID of the service manager |
uid | User ID |
auid | Audit user ID (login UID) |
ses | Session ID |
unit | Name of the service unit started |
comm | Command name of the service manager |
exe | Executable of the service manager |
hostname | Hostname |
addr | Network address |
terminal | Terminal |
res | Result (success or failed) |
subj | lspp subject's context string |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "4294967295",
"comm": "systemd",
"exe": "/usr/lib/systemd/systemd",
"hostname": "?",
"pid": "1",
"res": "success",
"ses": "4294967295",
"subj": "system_u:system_r:init_t:s0",
"terminal": "?",
"uid": "0",
"unit": "auditd"
},
"raw": [
"node=JD-debian-12-workstation type=SERVICE_START msg=audit(1781634257.778:513027): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='unit=auditd comm=\"systemd\" exe=\"/usr/lib/systemd/systemd\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "SERVICE_START"
}
SERVICE_STOP msgtype 1131
#Description
Service (daemon) stop
Fields #
| Name | Description | Rules |
|---|---|---|
pid | Process ID of the service manager | |
uid | User ID | |
auid | Audit user ID (login UID) | |
ses | Session ID | |
unit | Name of the service unit stopped | 8 detection rules |
comm | Command name of the service manager | |
exe | Executable of the service manager | |
hostname | Hostname | |
addr | Network address | |
terminal | Terminal | |
res | Result (success or failed) | |
subj | lspp subject's context string |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "4294967295",
"comm": "systemd",
"exe": "/usr/lib/systemd/systemd",
"hostname": "?",
"pid": "1",
"res": "success",
"ses": "4294967295",
"subj": "system_u:system_r:init_t:s0",
"terminal": "?",
"uid": "0",
"unit": "systemd-update-utmp-runlevel"
},
"raw": [
"node=JD-debian-12-workstation type=SERVICE_STOP msg=audit(1781634283.045:560313): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='unit=systemd-update-utmp-runlevel comm=\"systemd\" exe=\"/usr/lib/systemd/systemd\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "SERVICE_STOP"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
type | eq | service_stop | 7 rules | sigma, splunk |
dc_host | lt | 3 | 1 rule | splunk |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1686Splunk #
T1489T1686osquery service, which may indicate an attempt to disable monitoring and evade detection. Osquery is a powerful tool used for querying system information and detecting…T1489
GRP_MGMT msgtype 1132
#Description
Group account attribute was modified
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
op | the operation being performed that is audited |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "4294967295",
"exe": "/usr/sbin/groupadd",
"hostname": "?",
"id": "1000",
"op": "add-shadow-group",
"pid": "1235",
"res": "success",
"ses": "4294967295",
"subj": "system_u:system_r:unconfined_service_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"type=GRP_MGMT msg=audit(1481076992.419:386): pid=1235 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:unconfined_service_t:s0 msg='op=add-shadow-group id=1000 exe=\"/usr/sbin/groupadd\" hostname=? addr=? terminal=? res=success'"
],
"record_type": "GRP_MGMT"
}
Example keys not documented in the fields table: id
GRP_CHAUTHTOK msgtype 1133
#Description
Group account password or PIN changed
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "1000",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"pid": "28917",
"res": "success",
"ses": "1",
"subj": "unconfined",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=GRP_CHAUTHTOK msg=audit(1781630215.758:1267003): pid=28917 uid=0 auid=1000 ses=1 subj=unconfined msg='grp-chauthtok-test exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"debian\""
],
"record_type": "GRP_CHAUTHTOK"
}
MAC_CHECK msgtype 1134
#Description
User space MAC (Mandatory Access Control) decision results
ACCT_LOCK msgtype 1135
#Description
User's account locked by admin
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "1000",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"pid": "29132",
"res": "success",
"ses": "1",
"subj": "unconfined",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=ACCT_LOCK msg=audit(1781630235.907:1273935): pid=29132 uid=0 auid=1000 ses=1 subj=unconfined msg='acct-lock-test exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"debian\""
],
"record_type": "ACCT_LOCK"
}
ACCT_UNLOCK msgtype 1136
#Description
User's account unlocked by admin
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "1000",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"pid": "29132",
"res": "success",
"ses": "1",
"subj": "unconfined",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=ACCT_UNLOCK msg=audit(1781630235.907:1273942): pid=29132 uid=0 auid=1000 ses=1 subj=unconfined msg='acct-unlock-test exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"debian\""
],
"record_type": "ACCT_UNLOCK"
}
USER_DEVICE msgtype 1137
#Description
User space hotplug device changes
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the device authorization action (inserted-device, removed-device, changed-authorization-state-for, discovered-device) |
device | the sysfs path of the USB device |
device_rule | hex-encoded usbguard rule describing the device (id, serial, name, hash, interface) |
exe | the daemon that emitted the record (usbguard-daemon) |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "4294967295",
"device": "/devices/pci0000:00/0000:00:01.2/usb1/1-2/1-2.3",
"device_rule": "626C6F636B20696420303632373A303030312073657269616C202238393132362D303030303A30303A30312E322D322E3322206E616D65202251454D5520555342204D6F75736522206861736820224A374576465164306F64682F636266675037566C364B714E6B66344953393449756E30734D64464655504D3D2220706172656E742D6861736820226144645272436B6B6C486E41737A485378755953704834456E7349442F6C745341477373564C68765478733D22207669612D706F72742022312D322E332220776974682D696E746572666163652030333A30313A303220776974682D636F6E6E6563742D747970652022756E6B6E6F776E22",
"exe": "/usr/sbin/usbguard-daemon",
"hostname": "?",
"op": "inserted-device",
"pid": "2297",
"res": "success",
"ses": "4294967295",
"subj": "system_u:system_r:init_t:s0-s15:c0.c1023",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=localhost type=USER_DEVICE msg=audit(1782740627.120:433): pid=2297 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0-s15:c0.c1023 msg='op=\"inserted-device\" device=\"/devices/pci0000:00/0000:00:01.2/usb1/1-2/1-2.3\" device_rule=626C6F636B20696420303632373A303030312073657269616C202238393132362D303030303A30303A30312E322D322E3322206E616D65202251454D5520555342204D6F75736522206861736820224A374576465164306F64682F636266675037566C364B714E6B66344953393449756E30734D64464655504D3D2220706172656E742D6861736820226144645272436B6B6C486E41737A485378755953704834456E7349442F6C745341477373564C68765478733D22207669612D706F72742022312D322E332220776974682D696E746572666163652030333A30313A303220776974682D636F6E6E6563742D747970652022756E6B6E6F776E22 exe=\"/usr/sbin/usbguard-daemon\" hostname=? addr=? terminal=? res=success'"
],
"record_type": "USER_DEVICE"
}
SOFTWARE_UPDATE msgtype 1138
#Description
Software update event
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the package operation (install, update, remove) |
sw | the full package NEVRA (name-epoch:version-release.arch) being installed, updated, or removed |
sw_type | the package-management backend that emitted the record (currently always rpm) |
key_enforce | whether package-signature enforcement was active |
gpg_res | GPG signature verification result |
root_dir | root directory the update applied to |
comm | the package-manager command that ran the transaction |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "1000",
"comm": "rpm",
"exe": "/usr/bin/rpm",
"gpg_res": "0",
"hostname": "?",
"key_enforce": "0",
"op": "install",
"pid": "803140",
"res": "success",
"root_dir": "/",
"ses": "241",
"subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
"sw": "dwh-probe-1.0-1.noarch",
"sw_type": "rpm",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=linux-audit-host type=SOFTWARE_UPDATE msg=audit(1783637823.949:22539443): pid=803140 uid=0 auid=1000 ses=241 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=install sw=\"dwh-probe-1.0-1.noarch\" sw_type=rpm key_enforce=0 gpg_res=0 root_dir=\"/\" comm=\"rpm\" exe=\"/usr/bin/rpm\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"labuser\""
],
"record_type": "SOFTWARE_UPDATE"
}
DAEMON_START msgtype 1200
#Description
Daemon startup record
Fields #
| Name | Description |
|---|---|
op | the operation being performed that is audited |
ver | audit daemon's version number |
format | audit log's format |
kernel | kernel's version number |
auid | login user ID |
pid | process ID |
uid | user ID |
ses | login session ID |
subj | lspp subject's context string |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"auid": "4294967295",
"format": "enriched",
"kernel": "6.1.0-44-amd64",
"op": "start",
"pid": "2322",
"res": "success",
"ses": "4294967295",
"subj": "system_u:system_r:auditd_t:s0",
"uid": "0",
"ver": "3.0.9"
},
"raw": [
"node=JD-debian-12-workstation type=DAEMON_START msg=audit(1781634257.573:708): op=start ver=3.0.9 format=enriched kernel=6.1.0-44-amd64 auid=4294967295 pid=2322 uid=0 ses=4294967295 subj=system_u:system_r:auditd_t:s0 res=success",
"AUID=\"unset\" UID=\"root\""
],
"record_type": "DAEMON_START"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Splunk #
T1685, T1685.004
DAEMON_END msgtype 1201
#Description
Daemon normal stop record
Fields #
| Name | Description |
|---|---|
op | the operation being performed that is audited |
auid | login user ID |
uid | user ID |
ses | login session ID |
pid | process ID |
subj | lspp subject's context string |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"auid": "-1",
"op": "terminate",
"pid": "-1",
"res": "success",
"ses": "-1",
"subj": "?",
"uid": "-1"
},
"raw": [
"node=JD-debian-12-workstation type=DAEMON_END msg=audit(1781634206.873:8602): op=terminate auid=-1 uid=-1 ses=-1 pid=-1 subj=? res=success",
"AUID=\"unset\" UID=\"unset\""
],
"record_type": "DAEMON_END"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Splunk #
T1685, T1685.004
DAEMON_ABORT msgtype 1202
#Description
Daemon error stop record
Fields #
| Name | Description |
|---|---|
op | the operation being performed that is audited |
auid | login user ID |
pid | process ID |
uid | user ID |
ses | login session ID |
subj | lspp subject's context string |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"auid": "0",
"op": "set-pid",
"pid": "791",
"res": "failed",
"ses": "12",
"subj": "unconfined",
"uid": "0"
},
"raw": [
"node=dw-disposable-vm type=DAEMON_ABORT msg=audit(1781731230.798:3442): op=set-pid auid=0 pid=791 uid=0 ses=12 subj=unconfined res=failed",
"AUID=\"root\" UID=\"root\""
],
"record_type": "DAEMON_ABORT"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Splunk #
T1685, T1685.004
DAEMON_CONFIG msgtype 1203
#Description
Daemon config change
Fields #
| Name | Description |
|---|---|
op | the operation being performed that is audited |
state | audit daemon configuration resulting state |
auid | login user ID |
uid | user ID |
ses | login session ID |
pid | process ID |
subj | lspp subject's context string |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"auid": "1000",
"op": "reconfigure",
"pid": "51449",
"res": "success",
"state": "changed",
"subj": "unconfined"
},
"raw": [
"node=JD-debian-12-workstation type=DAEMON_CONFIG msg=audit(1781632421.227:3346): op=reconfigure state=changed auid=1000 pid=51449 subj=unconfined res=success",
"AUID=\"debian\""
],
"record_type": "DAEMON_CONFIG"
}
DAEMON_ROTATE msgtype 1205
#Description
Auditd should rotate logs
Fields #
| Name | Description |
|---|---|
op | the operation being performed that is audited |
auid | login user ID |
uid | user ID |
ses | login session ID |
pid | process ID |
subj | lspp subject's context string |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"auid": "1000",
"op": "rotate-logs",
"pid": "51449",
"res": "success",
"ses": "15",
"subj": "unconfined",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=DAEMON_ROTATE msg=audit(1781632422.224:77): op=rotate-logs auid=1000 uid=0 ses=15 pid=51449 subj=unconfined res=success",
"AUID=\"debian\" UID=\"root\""
],
"record_type": "DAEMON_ROTATE"
}
DAEMON_RESUME msgtype 1206
#Description
Auditd should resume logging
Fields #
| Name | Description |
|---|---|
op | the operation being performed that is audited |
auid | login user ID |
uid | user ID |
ses | login session ID |
pid | process ID |
subj | lspp subject's context string |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"auid": "1000",
"op": "resume-logging",
"pid": "109949",
"res": "success",
"ses": "90",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=DAEMON_RESUME msg=audit(1781719930.237:7502): op=resume-logging auid=1000 uid=0 ses=90 pid=109949 res=success",
"AUID=\"debian\" UID=\"root\""
],
"record_type": "DAEMON_RESUME"
}
DAEMON_ACCEPT msgtype 1207
#Description
Auditd accepted remote connection
Fields #
| Name | Description |
|---|---|
op | the operation being performed that is audited |
addr | the remote address that the user is connecting from |
port | remote port of the audit connection |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "::ffff:127.0.0.1",
"port": "37074",
"res": "success"
},
"raw": [
"node=JD-debian-12-workstation type=DAEMON_ACCEPT msg=audit(1781635296.535:3244): addr=::ffff:127.0.0.1 port=37074 res=success"
],
"record_type": "DAEMON_ACCEPT"
}
DAEMON_CLOSE msgtype 1208
#Description
Auditd closed remote connection
Fields #
| Name | Description |
|---|---|
addr | the remote address that the user is connecting from |
port | remote port of the audit connection |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "::ffff:127.0.0.1",
"port": "57858",
"res": "success"
},
"raw": [
"node=JD-debian-12-workstation type=DAEMON_CLOSE msg=audit(1781641212.864:8400): addr=::ffff:127.0.0.1 port=57858 res=success"
],
"record_type": "DAEMON_CLOSE"
}
SYSCALL msgtype 1300
#Description
System call event information
How it fires #
This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:
-a always,exit -F arch=b64 -S execve -k execFields #
| Name | Description | Rules |
|---|---|---|
arch | CPU architecture (e.g. c000003e for x86_64) | |
syscall | System call number | 2 detection rules |
success | Whether the syscall succeeded (yes or no) | 2 detection rules |
exit | Exit value or errno of the syscall | |
a0 | First argument to the syscall (hex) | 10 detection rules |
a1 | Second argument to the syscall (hex) | |
a2 | Third argument to the syscall (hex) | |
a3 | Fourth argument to the syscall (hex) | |
items | Number of PATH records attached to this event | |
ppid | Parent process ID | |
pid | Process ID | |
auid | Audit user ID (login UID) | |
uid | User ID | 3 detection rules |
gid | Group ID | |
euid | Effective user ID | 1 detection rule |
suid | Saved set-user-ID | |
fsuid | File system user ID | |
egid | Effective group ID | |
sgid | Saved set-group-ID | |
fsgid | File system group ID | |
tty | Terminal associated with the process | |
ses | Session ID | |
comm | Command name of the process | 28 detection rules |
exe | Executable path of the process | 71 detection rules |
subj | lspp subject's context string | |
key | Audit rule key that triggered this record | 8 detection rules |
Example Audit Record #
{
"fields": {
"a0": "2442de3bf7e8",
"a1": "2442dd0f4cb0",
"a2": "2442dd889e60",
"a3": "0",
"arch": "c000003e",
"auid": "4294967295",
"comm": "iptables",
"egid": "0",
"euid": "0",
"exe": "/usr/sbin/xtables-nft-multi",
"exit": "0",
"fsgid": "0",
"fsuid": "0",
"gid": "0",
"items": "2",
"key": "T1059_exec",
"pid": "2407",
"ppid": "671",
"ses": "4294967295",
"sgid": "0",
"subj": "system_u:system_r:iptables_t:s0",
"success": "yes",
"suid": "0",
"syscall": "59",
"tty": "(none)",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=SYSCALL msg=audit(1781634257.762:512605): arch=c000003e syscall=59 success=yes exit=0 a0=2442de3bf7e8 a1=2442dd0f4cb0 a2=2442dd889e60 a3=0 items=2 ppid=671 pid=2407 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=\"iptables\" exe=\"/usr/sbin/xtables-nft-multi\" subj=system_u:system_r:iptables_t:s0 key=\"T1059_exec\"",
"ARCH=x86_64 SYSCALL=execve AUID=\"unset\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
"node=JD-debian-12-workstation type=EXECVE msg=audit(1781634257.762:512605): argc=13 a0=\"/usr/sbin/iptables\" a1=\"--wait\" a2=\"-t\" a3=\"raw\" a4=\"-C\" a5=\"PREROUTING\" a6=\"-d\" a7=\"172.18.0.6\" a8=\"!\" a9=\"-i\" a10=\"br-440f323861ca\" a11=\"-j\" a12=\"DROP\"",
"node=JD-debian-12-workstation type=CWD msg=audit(1781634257.762:512605): cwd=\"/\"",
"node=JD-debian-12-workstation type=PATH msg=audit(1781634257.762:512605): item=0 name=\"/usr/sbin/iptables\" inode=5537074 dev=fe:01 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:iptables_exec_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
"OUID=\"root\" OGID=\"root\"",
"node=JD-debian-12-workstation type=PATH msg=audit(1781634257.762:512605): item=1 name=\"/lib64/ld-linux-x86-64.so.2\" inode=5505708 dev=fe:01 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:ld_so_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
"OUID=\"root\" OGID=\"root\"",
"node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781634257.762:512605): proctitle=2F7573722F7362696E2F69707461626C6573002D2D77616974002D7400726177002D4300505245524F5554494E47002D64003137322E31382E302E360021002D690062722D343430663332333836316361002D6A0044524F50"
],
"record_type": "SYSCALL"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
type | eq | syscall | 26 rules | sigma, splunk |
type | eq | execve | 2 rules | sigma |
type | eq | add_user | 1 rule | sigma |
comm | eq | insmod | 2 rules | sigma, splunk |
comm | eq | split | 2 rules | sigma, splunk |
exe | in | /usr/bin/sudo | 1 rule | splunk |
uid | ne | 0 | 1 rule | splunk |
user | eq | root | 1 rule | splunk |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
syslog syscall with action code 5 (SYSLOG_ACTION_CLEAR), (4 is SYSLOG_ACTION_READ_CLEAR and 6 is SYSLOG_ACTION_CONSOLE_OFF) which clears the kernel ring buffer (dmesg logs). This can be used by attackers to hide traces after exploitation or privilege escalation. A common technique is running dmesg -c, which triggers this syscall internally.T1685, T1685.006T1547, T1547.006T1046Splunk #
T1053, T1053.002T1068split syscall, potentially indicating an attempt to evade detection by breaking large files into smaller parts. Attackers may use this…T1030
References #
PATH msgtype 1302
#Description
Filename path information
How it fires #
This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:
-w /etc/passwd -p wa -k identityFields #
| Name | Description | Rules |
|---|---|---|
item | Item number in the PATH record sequence | |
name | File or directory path | 73 detection rules |
inode | Inode number of the file | |
dev | Device identifier | |
mode | File permission mode (octal) | |
ouid | Owner user ID of the file | |
ogid | Owner group ID of the file | |
rdev | Device identifier for special files | |
obj | lspp object context string | |
nametype | Type of path operation (NORMAL, CREATE, DELETE, etc.) | 6 detection rules |
cap_fp | file permitted capability map | |
cap_fi | file inherited capability map | |
cap_fe | file assigned effective capability map | |
cap_fver | file system capabilities version number | |
cap_frootid | root user ID namespace owner of the file capability set |
Example Audit Record #
{
"fields": {
"cap_fe": "0",
"cap_fi": "0",
"cap_fp": "0",
"cap_frootid": "0",
"cap_fver": "0",
"dev": "fe:01",
"inode": "5537074",
"item": "0",
"mode": "0100755",
"name": "/usr/sbin/iptables",
"nametype": "NORMAL",
"obj": "system_u:object_r:iptables_exec_t:s0",
"ogid": "0",
"ouid": "0",
"rdev": "00:00"
},
"raw": [
"node=JD-debian-12-workstation type=SYSCALL msg=audit(1781634257.762:512605): arch=c000003e syscall=59 success=yes exit=0 a0=2442de3bf7e8 a1=2442dd0f4cb0 a2=2442dd889e60 a3=0 items=2 ppid=671 pid=2407 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=\"iptables\" exe=\"/usr/sbin/xtables-nft-multi\" subj=system_u:system_r:iptables_t:s0 key=\"T1059_exec\"",
"ARCH=x86_64 SYSCALL=execve AUID=\"unset\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
"node=JD-debian-12-workstation type=EXECVE msg=audit(1781634257.762:512605): argc=13 a0=\"/usr/sbin/iptables\" a1=\"--wait\" a2=\"-t\" a3=\"raw\" a4=\"-C\" a5=\"PREROUTING\" a6=\"-d\" a7=\"172.18.0.6\" a8=\"!\" a9=\"-i\" a10=\"br-440f323861ca\" a11=\"-j\" a12=\"DROP\"",
"node=JD-debian-12-workstation type=CWD msg=audit(1781634257.762:512605): cwd=\"/\"",
"node=JD-debian-12-workstation type=PATH msg=audit(1781634257.762:512605): item=0 name=\"/usr/sbin/iptables\" inode=5537074 dev=fe:01 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:iptables_exec_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
"OUID=\"root\" OGID=\"root\"",
"node=JD-debian-12-workstation type=PATH msg=audit(1781634257.762:512605): item=1 name=\"/lib64/ld-linux-x86-64.so.2\" inode=5505708 dev=fe:01 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:ld_so_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
"OUID=\"root\" OGID=\"root\"",
"node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781634257.762:512605): proctitle=2F7573722F7362696E2F69707461626C6573002D2D77616974002D7400726177002D4300505245524F5554494E47002D64003137322E31382E302E360021002D690062722D343430663332333836316361002D6A0044524F50"
],
"record_type": "PATH"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
type | eq | path | 19 rules | sigma, splunk |
type | eq | cwd | 7 rules | splunk |
type | eq | execve | 2 rules | sigma |
match_count | gt | 0 | 7 rules | splunk |
name | eq | /etc/issue | 2 rules | sigma |
name | eq | /etc/pam.d/system-auth | 2 rules | sigma |
nametype | eq | create | 2 rules | sigma, splunk |
a0 | eq | hostname | 1 rule | sigma |
a0 | eq | uname | 1 rule | sigma |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1685T1059, T1106T1574, T1574.001
References #
IPC msgtype 1303
#Description
System call IPC (Inter-Process Communication) object
How it fires #
This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:
-a always,exit -F arch=b64 -S shmget,semget,msgget -k ipcFields #
| Name | Description |
|---|---|
ouid | Owner user ID of the IPC object |
ogid | Owner group ID of the IPC object |
mode | Permission mode of the IPC object |
obj | SELinux context of the IPC object |
Example Audit Record #
{
"fields": {
"mode": "0600",
"ogid": "0",
"ouid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=SYSCALL msg=audit(1781632713.732:2113093): arch=c000003e syscall=66 success=yes exit=0 a0=0 a1=0 a2=10 a3=7fff00000001 items=0 ppid=56702 pid=56740 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=15 comm=\"cryptsetup\" exe=\"/usr/sbin/cryptsetup\" subj=unconfined key=\"cat_ipc\"",
"ARCH=x86_64 SYSCALL=semctl AUID=\"debian\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
"node=JD-debian-12-workstation type=IPC msg=audit(1781632713.732:2113093): ouid=0 ogid=0 mode=0600",
"OUID=\"root\" OGID=\"root\"",
"node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781632713.732:2113093): proctitle=63727970747365747570006C756B734F70656E002F746D702F7232622F6C756B736261636B00636174616C6F676C756B73002D"
],
"record_type": "IPC"
}
References #
SOCKETCALL msgtype 1304
#Description
System call socketcall arguments
How it fires #
This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:
-a always,exit -F arch=b32 -S socketcall -k netFields #
| Name | Description |
|---|---|
nargs | Number of arguments to the socket call |
a0 | First argument (hex) |
a1 | Second argument (hex) |
a2 | Third argument (hex) |
a3 | argument to the syscall (hex) |
a4 | argument to the syscall (hex) |
a5 | argument to the syscall (hex) |
Example Audit Record #
{
"fields": {
"a0": "3",
"a1": "ffde5b9c",
"a2": "10",
"nargs": "3"
},
"raw": [
"node=JD-debian-12-workstation type=SYSCALL msg=audit(1781731984.980:1214350): arch=40000003 syscall=102 success=no exit=-111 a0=3 a1=ffde5b60 a2=0 a3=eafe1ff4 items=0 ppid=37557 pid=37579 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=48 comm=\"sock32\" exe=\"/tmp/recap/sock32\" subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key=\"sockcap\"",
"ARCH=i386 SYSCALL=socketcall(connect) AUID=\"debian\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
"node=JD-debian-12-workstation type=SOCKETCALL msg=audit(1781731984.980:1214350): nargs=3 a0=3 a1=ffde5b9c a2=10",
"node=JD-debian-12-workstation type=SOCKADDR msg=audit(1781731984.980:1214350): saddr=020000097F0000010000000000000000",
"SADDR={ saddr_fam=inet laddr=127.0.0.1 lport=9 }",
"node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781731984.980:1214350): proctitle=\"/tmp/recap/sock32\""
],
"record_type": "SOCKETCALL"
}
References #
CONFIG_CHANGE msgtype 1305
#Description
Audit system configuration change
Fields #
| Name | Description |
|---|---|
auid | Audit user ID (login UID) that made the change |
ses | Session ID |
subj | lspp subject's context string |
op | Operation performed (e.g. add_rule, remove_rule) |
key | Audit rule key associated with the change |
list | Audit rule list affected |
res | Result of the operation (1 for success, 0 for failure) |
Example Audit Record #
{
"fields": {
"auid": "4294967295",
"key": "T1562_audit_log_tamper",
"list": "4",
"op": "remove_rule",
"res": "1",
"ses": "4294967295",
"subj": "system_u:system_r:auditctl_t:s0"
},
"raw": [
"node=JD-debian-12-workstation type=CONFIG_CHANGE msg=audit(1781634257.694:511157): auid=4294967295 ses=4294967295 subj=system_u:system_r:auditctl_t:s0 op=remove_rule key=\"T1562_audit_log_tamper\" list=4 res=1",
"AUID=\"unset\"",
"node=JD-debian-12-workstation type=SYSCALL msg=audit(1781634257.694:511157): arch=c000003e syscall=44 success=yes exit=1092 a0=3 a1=7fff5edbde00 a2=444 a3=0 items=0 ppid=2328 pid=2390 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=\"auditctl\" exe=\"/usr/sbin/auditctl\" subj=system_u:system_r:auditctl_t:s0 key=\"T1071_data_transfer\"",
"ARCH=x86_64 SYSCALL=sendto AUID=\"unset\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
"node=JD-debian-12-workstation type=SOCKADDR msg=audit(1781634257.694:511157): saddr=100000000000000000000000",
"SADDR={ saddr_fam=netlink nlnk-fam=16 nlnk-pid=0 }",
"node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781634257.694:511157): proctitle=2F7362696E2F617564697463746C002D52002F6574632F61756469742F61756469742E72756C6573"
],
"record_type": "CONFIG_CHANGE"
}
References #
SOCKADDR msgtype 1306
#Description
System call socket address argument information
How it fires #
This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:
-a always,exit -F arch=b64 -S connect,accept,bind -k netFields #
| Name | Description |
|---|---|
saddr | Socket address structure (hex-encoded) |
Example Audit Record #
{
"fields": {
"saddr": "100000000000000000000000"
},
"raw": [
"node=JD-debian-12-workstation type=SYSCALL msg=audit(1781634257.690:510675): arch=c000003e syscall=45 success=yes exit=1092 a0=3 a1=7fff5edc2590 a2=231c a3=40 items=0 ppid=2328 pid=2390 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=\"auditctl\" exe=\"/usr/sbin/auditctl\" subj=system_u:system_r:auditctl_t:s0 key=\"T1071_data_transfer\"",
"ARCH=x86_64 SYSCALL=recvfrom AUID=\"unset\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
"node=JD-debian-12-workstation type=SOCKADDR msg=audit(1781634257.690:510675): saddr=100000000000000000000000",
"SADDR={ saddr_fam=netlink nlnk-fam=16 nlnk-pid=0 }",
"node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781634257.690:510675): proctitle=2F7362696E2F617564697463746C002D52002F6574632F61756469742F61756469742E72756C6573"
],
"record_type": "SOCKADDR"
}
References #
CWD msgtype 1307
#Description
Current working directory
How it fires #
This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:
-a always,exit -F arch=b64 -S execve -k execFields #
| Name | Description |
|---|---|
cwd | Current working directory |
Example Audit Record #
{
"fields": {
"cwd": "/"
},
"raw": [
"node=JD-debian-12-workstation type=SYSCALL msg=audit(1781634257.762:512605): arch=c000003e syscall=59 success=yes exit=0 a0=2442de3bf7e8 a1=2442dd0f4cb0 a2=2442dd889e60 a3=0 items=2 ppid=671 pid=2407 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=\"iptables\" exe=\"/usr/sbin/xtables-nft-multi\" subj=system_u:system_r:iptables_t:s0 key=\"T1059_exec\"",
"ARCH=x86_64 SYSCALL=execve AUID=\"unset\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
"node=JD-debian-12-workstation type=EXECVE msg=audit(1781634257.762:512605): argc=13 a0=\"/usr/sbin/iptables\" a1=\"--wait\" a2=\"-t\" a3=\"raw\" a4=\"-C\" a5=\"PREROUTING\" a6=\"-d\" a7=\"172.18.0.6\" a8=\"!\" a9=\"-i\" a10=\"br-440f323861ca\" a11=\"-j\" a12=\"DROP\"",
"node=JD-debian-12-workstation type=CWD msg=audit(1781634257.762:512605): cwd=\"/\"",
"node=JD-debian-12-workstation type=PATH msg=audit(1781634257.762:512605): item=0 name=\"/usr/sbin/iptables\" inode=5537074 dev=fe:01 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:iptables_exec_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
"OUID=\"root\" OGID=\"root\"",
"node=JD-debian-12-workstation type=PATH msg=audit(1781634257.762:512605): item=1 name=\"/lib64/ld-linux-x86-64.so.2\" inode=5505708 dev=fe:01 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:ld_so_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
"OUID=\"root\" OGID=\"root\"",
"node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781634257.762:512605): proctitle=2F7573722F7362696E2F69707461626C6573002D2D77616974002D7400726177002D4300505245524F5554494E47002D64003137322E31382E302E360021002D690062722D343430663332333836316361002D6A0044524F50"
],
"record_type": "CWD"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
match_count | gt | 0 | 7 rules | splunk |
type | eq | cwd | 7 rules | splunk |
type | eq | path | 7 rules | splunk |
nametype | eq | create | 1 rule | splunk |
References #
EXECVE msgtype 1309
#Description
Arguments supplied to the execve system call
How it fires #
This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:
-a always,exit -F arch=b64 -S execve -k execFields #
| Name | Description | Rules |
|---|---|---|
argc | Number of command-line arguments | |
a0 | First command-line argument (the program path) | 56 detection rules |
a1 | Second command-line argument | 51 detection rules |
a2 | Third command-line argument | 17 detection rules |
a3 | Fourth command-line argument | 11 detection rules |
Example Audit Record #
{
"fields": {
"a0": "/usr/sbin/iptables",
"a1": "--wait",
"a10": "br-440f323861ca",
"a11": "-j",
"a12": "DROP",
"a2": "-t",
"a3": "raw",
"a4": "-C",
"a5": "PREROUTING",
"a6": "-d",
"a7": "172.18.0.6",
"a8": "!",
"a9": "-i",
"argc": "13"
},
"raw": [
"node=JD-debian-12-workstation type=SYSCALL msg=audit(1781634257.762:512605): arch=c000003e syscall=59 success=yes exit=0 a0=2442de3bf7e8 a1=2442dd0f4cb0 a2=2442dd889e60 a3=0 items=2 ppid=671 pid=2407 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=\"iptables\" exe=\"/usr/sbin/xtables-nft-multi\" subj=system_u:system_r:iptables_t:s0 key=\"T1059_exec\"",
"ARCH=x86_64 SYSCALL=execve AUID=\"unset\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
"node=JD-debian-12-workstation type=EXECVE msg=audit(1781634257.762:512605): argc=13 a0=\"/usr/sbin/iptables\" a1=\"--wait\" a2=\"-t\" a3=\"raw\" a4=\"-C\" a5=\"PREROUTING\" a6=\"-d\" a7=\"172.18.0.6\" a8=\"!\" a9=\"-i\" a10=\"br-440f323861ca\" a11=\"-j\" a12=\"DROP\"",
"node=JD-debian-12-workstation type=CWD msg=audit(1781634257.762:512605): cwd=\"/\"",
"node=JD-debian-12-workstation type=PATH msg=audit(1781634257.762:512605): item=0 name=\"/usr/sbin/iptables\" inode=5537074 dev=fe:01 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:iptables_exec_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
"OUID=\"root\" OGID=\"root\"",
"node=JD-debian-12-workstation type=PATH msg=audit(1781634257.762:512605): item=1 name=\"/lib64/ld-linux-x86-64.so.2\" inode=5505708 dev=fe:01 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:ld_so_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
"OUID=\"root\" OGID=\"root\"",
"node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781634257.762:512605): proctitle=2F7573722F7362696E2F69707461626C6573002D2D77616974002D7400726177002D4300505245524F5554494E47002D64003137322E31382E302E360021002D690062722D343430663332333836316361002D6A0044524F50"
],
"record_type": "EXECVE"
}
Example keys not documented in the fields table: a10, a11, a12, a4, a5, a6, a7, a8, a9
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
type | eq | execve | 37 rules | sigma, splunk |
type | eq | proctitle | 6 rules | splunk |
type | eq | syscall | 3 rules | sigma, splunk |
execve_command | in | *find* | 7 rules | splunk |
execve_command | in | *grep* | 7 rules | splunk |
a1 | ends_with | .jpg | 3 rules | sigma |
a1 | ends_with | .png | 3 rules | sigma |
a1 | eq | -sel | 2 rules | sigma |
a1 | eq | -selection | 2 rules | sigma |
a1 | eq | /bin/sh | 2 rules | sigma |
a0 | eq | cp | 2 rules | sigma |
a0 | eq | hostname | 2 rules | sigma |
a0 | eq | steghide | 2 rules | sigma |
a0 | eq | uname | 2 rules | sigma |
a0 | eq | xclip | 2 rules | sigma |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1027, T1027.001T1686T1083, T1548Splunk #
T1140T1115split syscall, potentially indicating an attempt to evade detection by breaking large files into smaller parts. Attackers may use this…T1030
References #
IPC_SET_PERM msgtype 1311
#Description
IPC new permissions record type
How it fires #
This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:
-a always,exit -F arch=b64 -S shmctl,semctl,msgctl -k ipcFields #
| Name | Description |
|---|---|
qbytes | ipc objects quantity of bytes |
ouid | file owner user ID |
ogid | file owner group ID |
mode | Landlock domain enforcement mode (enforcing) |
Example Audit Record #
{
"fields": {
"mode": "0600",
"ogid": "0",
"ouid": "0",
"qbytes": "0"
},
"raw": [
"node=JD-debian-12-workstation type=SYSCALL msg=audit(1781632420.555:1883815): arch=c000003e syscall=31 success=yes exit=0 a0=2 a1=1 a2=7f3361005c30 a3=10 items=0 ppid=51449 pid=51615 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=15 comm=\"python3\" exe=\"/usr/bin/python3.11\" subj=unconfined key=\"cat_ipc\"",
"ARCH=x86_64 SYSCALL=shmctl AUID=\"debian\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
"node=JD-debian-12-workstation type=IPC msg=audit(1781632420.555:1883815): ouid=0 ogid=0 mode=0600",
"OUID=\"root\" OGID=\"root\"",
"node=JD-debian-12-workstation type=IPC_SET_PERM msg=audit(1781632420.555:1883815): qbytes=0 ouid=0 ogid=0 mode=0600",
"OUID=\"root\" OGID=\"root\"",
"node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781632420.555:1883815): proctitle=707974686F6E33002F746D702F726F756E64322E7079"
],
"record_type": "IPC_SET_PERM"
}
References #
MQ_OPEN msgtype 1312
#Description
POSIX MQ open record type
How it fires #
This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:
-a always,exit -F arch=b64 -S mq_open -k posixmqFields #
| Name | Description |
|---|---|
oflag | open syscall flags |
mode | Landlock domain enforcement mode (enforcing) |
mq_flags | POSIX message queue flags |
mq_maxmsg | maximum number of messages on the POSIX message queue |
mq_msgsize | maximum message size on the POSIX message queue |
mq_curmsgs | current number of messages on the POSIX message queue |
Example Audit Record #
{
"fields": {
"mode": "0600",
"mq_curmsgs": "0",
"mq_flags": "0x0",
"mq_maxmsg": "10",
"mq_msgsize": "64",
"oflag": "0x42"
},
"raw": [
"node=JD-debian-12-workstation type=SYSCALL msg=audit(1781632420.559:1883818): arch=c000003e syscall=240 success=yes exit=3 a0=7f3360b29a61 a1=42 a2=180 a3=7f3360b2cb30 items=2 ppid=51449 pid=51615 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=15 comm=\"python3\" exe=\"/usr/bin/python3.11\" subj=unconfined key=\"cat_mq\"",
"ARCH=x86_64 SYSCALL=mq_open AUID=\"debian\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
"node=JD-debian-12-workstation type=MQ_OPEN msg=audit(1781632420.559:1883818): oflag=0x42 mode=0600 mq_flags=0x0 mq_maxmsg=10 mq_msgsize=64 mq_curmsgs=0",
"node=JD-debian-12-workstation type=CWD msg=audit(1781632420.559:1883818): cwd=\"/home/debian\"",
"node=JD-debian-12-workstation type=PATH msg=audit(1781632420.559:1883818): item=0 name=\"catalog_q2\" inode=264781 dev=00:13 mode=0100600 ouid=0 ogid=0 rdev=00:00 nametype=CREATE cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
"OUID=\"root\" OGID=\"root\"",
"node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781632420.559:1883818): proctitle=707974686F6E33002F746D702F726F756E64322E7079"
],
"record_type": "MQ_OPEN"
}
References #
MQ_SENDRECV msgtype 1313
#Description
POSIX MQ send/receive record type
How it fires #
This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:
-a always,exit -F arch=b64 -S mq_timedsend,mq_timedreceive -k posixmqFields #
| Name | Description |
|---|---|
mqdes | POSIX message queue descriptor |
msg_len | message length for the message-queue send or receive |
msg_prio | message priority for the message-queue send or receive |
abs_timeout_sec | absolute timeout seconds for the message queue operation |
abs_timeout_nsec | absolute timeout nanoseconds for the message queue operation |
Example Audit Record #
{
"fields": {
"abs_timeout_nsec": "0",
"abs_timeout_sec": "1781632422",
"mqdes": "3",
"msg_len": "18",
"msg_prio": "0"
},
"raw": [
"node=JD-debian-12-workstation type=SYSCALL msg=audit(1781632420.559:1883819): arch=c000003e syscall=242 success=yes exit=0 a0=3 a1=7f3360b1b190 a2=12 a3=0 items=1 ppid=51449 pid=51615 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=15 comm=\"python3\" exe=\"/usr/bin/python3.11\" subj=unconfined key=\"cat_mq\"",
"ARCH=x86_64 SYSCALL=mq_timedsend AUID=\"debian\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
"node=JD-debian-12-workstation type=MQ_SENDRECV msg=audit(1781632420.559:1883819): mqdes=3 msg_len=18 msg_prio=0 abs_timeout_sec=1781632422 abs_timeout_nsec=0",
"node=JD-debian-12-workstation type=CWD msg=audit(1781632420.559:1883819): cwd=\"/home/debian\"",
"node=JD-debian-12-workstation type=PATH msg=audit(1781632420.559:1883819): item=0 name=(null) inode=264781 dev=00:13 mode=0100600 ouid=0 ogid=0 rdev=00:00 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
"OUID=\"root\" OGID=\"root\"",
"node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781632420.559:1883819): proctitle=707974686F6E33002F746D702F726F756E64322E7079"
],
"record_type": "MQ_SENDRECV"
}
References #
MQ_NOTIFY msgtype 1314
#Description
POSIX MQ notify record type
How it fires #
This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:
-a always,exit -F arch=b64 -S mq_notify -k posixmqFields #
| Name | Description |
|---|---|
mqdes | POSIX message queue descriptor |
sigev_signo | signal number |
Example Audit Record #
{
"fields": {
"mqdes": "3",
"sigev_signo": "0"
},
"raw": [
"node=JD-debian-12-workstation type=SYSCALL msg=audit(1781632420.559:1883821): arch=c000003e syscall=244 success=yes exit=0 a0=3 a1=0 a2=7f3360b1b3f0 a3=0 items=0 ppid=51449 pid=51615 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=15 comm=\"python3\" exe=\"/usr/bin/python3.11\" subj=unconfined key=\"cat_mq\"",
"ARCH=x86_64 SYSCALL=mq_notify AUID=\"debian\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
"node=JD-debian-12-workstation type=MQ_NOTIFY msg=audit(1781632420.559:1883821): mqdes=3 sigev_signo=0",
"node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781632420.559:1883821): proctitle=707974686F6E33002F746D702F726F756E64322E7079"
],
"record_type": "MQ_NOTIFY"
}
References #
MQ_GETSETATTR msgtype 1315
#Description
POSIX MQ get/set attribute record type
How it fires #
This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:
-a always,exit -F arch=b64 -S mq_getsetattr -k posixmqFields #
| Name | Description |
|---|---|
mqdes | POSIX message queue descriptor |
mq_flags | POSIX message queue flags |
mq_maxmsg | maximum number of messages on the POSIX message queue |
mq_msgsize | maximum message size on the POSIX message queue |
mq_curmsgs | current number of messages on the POSIX message queue |
Example Audit Record #
{
"fields": {
"mq_curmsgs": "0",
"mq_flags": "0x0",
"mq_maxmsg": "10",
"mq_msgsize": "64",
"mqdes": "3"
},
"raw": [
"node=JD-debian-12-workstation type=SYSCALL msg=audit(1781632420.559:1883823): arch=c000003e syscall=245 success=yes exit=0 a0=3 a1=7f3360b56cb0 a2=0 a3=0 items=0 ppid=51449 pid=51615 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=15 comm=\"python3\" exe=\"/usr/bin/python3.11\" subj=unconfined key=\"cat_mq\"",
"ARCH=x86_64 SYSCALL=mq_getsetattr AUID=\"debian\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
"node=JD-debian-12-workstation type=MQ_GETSETATTR msg=audit(1781632420.559:1883823): mqdes=3 mq_flags=0x0 mq_maxmsg=10 mq_msgsize=64 mq_curmsgs=0 ",
"node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781632420.559:1883823): proctitle=707974686F6E33002F746D702F726F756E64322E7079"
],
"record_type": "MQ_GETSETATTR"
}
References #
KERNEL_OTHER msgtype 1316
#Description
For use by 3rd party modules
FD_PAIR msgtype 1317
#Description
Information for pipe and socketpair system calls
How it fires #
This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:
-a always,exit -F arch=b64 -S pipe,pipe2,socketpair -k fdpairFields #
| Name | Description |
|---|---|
fd0 | first file descriptor of the created pair |
fd1 | second file descriptor of the created pair |
Example Audit Record #
{
"fields": {
"fd0": "7",
"fd1": "9"
},
"raw": [
"node=JD-debian-12-workstation type=SYSCALL msg=audit(1781634258.158:513530): arch=c000003e syscall=53 success=yes exit=0 a0=1 a1=80001 a2=0 a3=c00012f078 items=0 ppid=1121 pid=2466 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=\"runc\" exe=\"/usr/bin/runc\" subj=system_u:system_r:initrc_t:s0 key=\"cat_fdpair\"",
"ARCH=x86_64 SYSCALL=socketpair AUID=\"unset\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
"node=JD-debian-12-workstation type=FD_PAIR msg=audit(1781634258.158:513530): fd0=7 fd1=9",
"node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781634258.158:513530): proctitle=72756E63002D2D726F6F74002F7661722F72756E2F646F636B65722F72756E74696D652D72756E632F6D6F6279002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6D6F62792F36616133383239633966356566636632623230353437336565"
],
"record_type": "FD_PAIR"
}
References #
OBJ_PID msgtype 1318
#Description
Target process information for ptrace, kill, tkill, and tgkill syscalls
How it fires #
This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:
-a always,exit -F arch=b64 -S ptrace -k ptraceFields #
| Name | Description |
|---|---|
opid | object's process ID |
oauid | object's login user ID |
ouid | file owner user ID |
oses | object's session ID |
obj | lspp object context string |
ocomm | object's command line name |
Example Audit Record #
{
"fields": {
"oauid": "-1",
"obj": "system_u:system_r:initrc_t:s0",
"ocomm": "dockerd",
"opid": "671",
"oses": "-1",
"ouid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=SYSCALL msg=audit(1781634257.750:512329): arch=c000003e syscall=234 success=yes exit=0 a0=29f a1=8b9 a2=17 a3=7ffed2507080 items=0 ppid=1 pid=671 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=\"dockerd\" exe=\"/usr/bin/dockerd\" subj=system_u:system_r:initrc_t:s0 key=\"T1489_process_kill\"",
"ARCH=x86_64 SYSCALL=tgkill AUID=\"unset\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
"node=JD-debian-12-workstation type=OBJ_PID msg=audit(1781634257.750:512329): opid=671 oauid=-1 ouid=0 oses=-1 obj=system_u:system_r:initrc_t:s0 ocomm=\"dockerd\"",
"OAUID=\"unset\" OUID=\"root\"",
"node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781634257.750:512329): proctitle=2F7573722F62696E2F646F636B657264002D480066643A2F2F002D2D636F6E7461696E6572643D2F72756E2F636F6E7461696E6572642F636F6E7461696E6572642E736F636B"
],
"record_type": "OBJ_PID"
}
References #
TTY msgtype 1319
#Description
Input on an administrative TTY
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
major | device major number |
minor | device minor number |
comm | command line program name |
data | TTY text |
Example Audit Record #
{
"fields": {
"auid": "1000",
"comm": "bash",
"data": "69640A657869740A",
"major": "136",
"minor": "0",
"pid": "32503",
"ses": "1",
"uid": "1003"
},
"raw": [
"node=JD-debian-12-workstation type=TTY msg=audit(1781630540.940:1378859): tty pid=32503 uid=1003 auid=1000 ses=1 major=136 minor=0 comm=\"bash\" data=69640A657869740A",
"UID=\"testlogout123\" AUID=\"debian\""
],
"record_type": "TTY"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
name | eq | /etc/pam.d/system-auth | 1 rule | sigma |
type | eq | path | 1 rule | sigma |
References #
EOE msgtype 1320
#BPRM_FCAPS msgtype 1321
#Description
Information about file system capabilities increasing permissions
How it fires #
This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:
-a always,exit -F arch=b64 -S execve -k filecapsFields #
| Name | Description |
|---|---|
fver | file system capabilities version number |
fp | file assigned permitted capability map |
fi | file assigned inherited capability map |
fe | file assigned effective capability map |
old_pp | old process permitted capability map |
old_pi | old process inherited capability map |
old_pe | old process effective capability map |
old_pa | old process ambient capability map |
pp | process permitted capability map |
pi | process inherited capability map |
pe | process effective capability map |
pa | process ambient capability map |
frootid | root user ID namespace owner of the file capability set |
Example Audit Record #
{
"fields": {
"fe": "0",
"fi": "0",
"fp": "0",
"frootid": "0",
"fver": "0",
"old_pa": "0",
"old_pe": "000001f7fdffffff",
"old_pi": "0",
"old_pp": "000001f7fdffffff",
"pa": "0",
"pe": "000001f7fdffffff",
"pi": "0",
"pp": "000001f7fdffffff"
},
"raw": [
"node=JD-debian-12-workstation type=SYSCALL msg=audit(1781634257.766:512777): arch=c000003e syscall=59 success=yes exit=0 a0=5611885bc330 a1=56118918c5a0 a2=5611891898d0 a3=0 items=3 ppid=2408 pid=2410 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=\"ifupdown-hotplu\" exe=\"/usr/bin/dash\" subj=system_u:system_r:udev_t:s0 key=\"T1059_exec\"",
"ARCH=x86_64 SYSCALL=execve AUID=\"unset\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
"node=JD-debian-12-workstation type=BPRM_FCAPS msg=audit(1781634257.766:512777): fver=0 fp=0 fi=0 fe=0 old_pp=000001f7fdffffff old_pi=0 old_pe=000001f7fdffffff old_pa=0 pp=000001f7fdffffff pi=0 pe=000001f7fdffffff pa=0 frootid=0",
"node=JD-debian-12-workstation type=EXECVE msg=audit(1781634257.766:512777): argc=3 a0=\"/bin/sh\" a1=\"-e\" a2=\"/lib/udev/ifupdown-hotplug\"",
"node=JD-debian-12-workstation type=CWD msg=audit(1781634257.766:512777): cwd=\"/\"",
"node=JD-debian-12-workstation type=PATH msg=audit(1781634257.766:512777): item=0 name=\"/lib/udev/ifupdown-hotplug\" inode=5512454 dev=fe:01 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:bin_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
"OUID=\"root\" OGID=\"root\"",
"node=JD-debian-12-workstation type=PATH msg=audit(1781634257.766:512777): item=1 name=\"/bin/sh\" inode=5506763 dev=fe:01 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:shell_exec_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
"OUID=\"root\" OGID=\"root\"",
"node=JD-debian-12-workstation type=PATH msg=audit(1781634257.766:512777): item=2 name=\"/lib64/ld-linux-x86-64.so.2\" inode=5505708 dev=fe:01 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:ld_so_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
"OUID=\"root\" OGID=\"root\"",
"node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781634257.766:512777): proctitle=\"(spawn)\""
],
"record_type": "BPRM_FCAPS"
}
References #
CAPSET msgtype 1322
#Description
Record showing argument to sys_capset setting process-based capabilities
How it fires #
This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:
-a always,exit -F arch=b64 -S capset -k capsFields #
| Name | Description |
|---|---|
pid | process ID |
cap_pi | process inherited capability map |
cap_pp | process permitted capability map |
cap_pe | process effective capability map |
cap_pa | process ambient capability map |
Example Audit Record #
{
"fields": {
"cap_pa": "0",
"cap_pe": "00000000a80425fb",
"cap_pi": "00000000a80425fb",
"cap_pp": "00000000a80425fb",
"pid": "2474"
},
"raw": [
"node=JD-debian-12-workstation type=SYSCALL msg=audit(1781634258.214:513610): arch=c000003e syscall=126 success=yes exit=0 a0=c000098570 a1=c000098578 a2=0 a3=0 items=0 ppid=2466 pid=2474 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=\"runc:[2:INIT]\" exe=\"/runc\" subj=system_u:system_r:initrc_t:s0 key=\"T1548_capabilities\"",
"ARCH=x86_64 SYSCALL=capset AUID=\"unset\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
"node=JD-debian-12-workstation type=CAPSET msg=audit(1781634258.214:513610): pid=2474 cap_pi=00000000a80425fb cap_pp=00000000a80425fb cap_pe=00000000a80425fb cap_pa=0",
"node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781634258.214:513610): proctitle=72756E6300696E6974"
],
"record_type": "CAPSET"
}
References #
MMAP msgtype 1323
#Description
Mmap system call file descriptor and flags
How it fires #
This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:
-a always,exit -F arch=b64 -S mmap -k mmapFields #
| Name | Description |
|---|---|
fd | file descriptor number |
flags | mmap syscall flags |
Example Audit Record #
{
"fields": {
"fd": "3",
"flags": "0x812"
},
"raw": [
"node=JD-debian-12-workstation type=SYSCALL msg=audit(1781634257.762:512610): arch=c000003e syscall=9 success=yes exit=140067170054144 a0=7f63edea7000 a1=8000 a2=5 a3=812 items=0 ppid=671 pid=2407 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=\"iptables\" exe=\"/usr/sbin/xtables-nft-multi\" subj=system_u:system_r:iptables_t:s0 key=\"T1055_mmap_exec\"",
"ARCH=x86_64 SYSCALL=mmap AUID=\"unset\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
"node=JD-debian-12-workstation type=MMAP msg=audit(1781634257.762:512610): fd=3 flags=0x812",
"node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781634257.762:512610): proctitle=2F7573722F7362696E2F69707461626C6573002D2D77616974002D7400726177002D4300505245524F5554494E47002D64003137322E31382E302E360021002D690062722D343430663332333836316361002D6A0044524F50"
],
"record_type": "MMAP"
}
References #
NETFILTER_PKT msgtype 1324
#Description
Packets traversing netfilter chains
Fields #
| Name | Description |
|---|---|
mark | netfilter packet mark |
saddr | struct socket address structure |
daddr | remote IP address |
proto | network protocol |
sport | local port number |
dport | remote port number |
Example Audit Record #
{
"fields": {
"daddr": "127.0.0.1",
"mark": "0x0",
"proto": "1",
"saddr": "127.0.0.1"
},
"raw": [
"node=JD-debian-12-workstation type=NETFILTER_PKT msg=audit(1781632714.004:2114926): mark=0x0 saddr=127.0.0.1 daddr=127.0.0.1 proto=1"
],
"record_type": "NETFILTER_PKT"
}
NETFILTER_CFG msgtype 1325
#Description
Netfilter chain modifications
Fields #
| Name | Description |
|---|---|
table | Netfilter table name |
family | Address family (e.g. 2 for IPv4, 10 for IPv6) |
entries | Number of entries in the table |
op | the operation being performed that is audited |
pid | process ID |
subj | lspp subject's context string |
comm | command line program name |
Example Audit Record #
{
"fields": {
"comm": "iptables",
"entries": "1",
"family": "2",
"op": "nft_register_rule",
"pid": "2409",
"subj": "system_u:system_r:iptables_t:s0",
"table": "raw:106"
},
"raw": [
"node=JD-debian-12-workstation type=NETFILTER_CFG msg=audit(1781634257.766:512779): table=raw:106 family=2 entries=1 op=nft_register_rule pid=2409 subj=system_u:system_r:iptables_t:s0 comm=\"iptables\"",
"node=JD-debian-12-workstation type=SYSCALL msg=audit(1781634257.766:512779): arch=c000003e syscall=46 success=yes exit=396 a0=3 a1=7fff72384f90 a2=0 a3=7fff72384f7c items=0 ppid=671 pid=2409 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=\"iptables\" exe=\"/usr/sbin/xtables-nft-multi\" subj=system_u:system_r:iptables_t:s0 key=\"T1071_msg_transfer\"",
"ARCH=x86_64 SYSCALL=sendmsg AUID=\"unset\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
"node=JD-debian-12-workstation type=SOCKADDR msg=audit(1781634257.766:512779): saddr=100000000000000000000000",
"SADDR={ saddr_fam=netlink nlnk-fam=16 nlnk-pid=0 }",
"node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781634257.766:512779): proctitle=2F7573722F7362696E2F69707461626C6573002D2D77616974002D7400726177002D4100505245524F5554494E47002D64003137322E31382E302E360021002D690062722D343430663332333836316361002D6A0044524F50"
],
"record_type": "NETFILTER_CFG"
}
References #
SECCOMP msgtype 1326
#Description
Secure Computing event
Fields #
| Name | Description |
|---|---|
auid | login user ID |
uid | user ID |
gid | group ID |
ses | login session ID |
subj | lspp subject's context string |
pid | process ID |
comm | command line program name |
exe | executable name |
sig | signal number |
arch | the elf architecture flags |
syscall | syscall number in effect when the event occurred |
compat | is_compat_task result |
ip | network address of a printer |
code | seccomp action code |
Example Audit Record #
{
"fields": {
"arch": "c000003e",
"auid": "4294967295",
"code": "0x7ffc0000",
"comm": "true",
"compat": "0",
"exe": "/usr/bin/true",
"gid": "0",
"ip": "0x7f13da9bb917",
"pid": "5052",
"ses": "4294967295",
"sig": "0",
"subj": "unconfined",
"syscall": "3",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=SECCOMP msg=audit(1781627806.180:583840): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=5052 comm=\"true\" exe=\"/usr/bin/true\" sig=0 arch=c000003e syscall=3 compat=0 ip=0x7f13da9bb917 code=0x7ffc0000",
"AUID=\"unset\" UID=\"root\" GID=\"root\" ARCH=x86_64 SYSCALL=close"
],
"record_type": "SECCOMP"
}
References #
PROCTITLE msgtype 1327
#Description
Process Title info
How it fires #
This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:
-a always,exit -F arch=b64 -S execve -k execFields #
| Name | Description | Rules |
|---|---|---|
proctitle | Process title (hex-encoded command line) | 59 detection rules |
Example Audit Record #
{
"fields": {
"proctitle": "2F7573722F7362696E2F69707461626C6573002D2D77616974002D7400726177002D4300505245524F5554494E47002D64003137322E31382E302E360021002D690062722D343430663332333836316361002D6A0044524F50"
},
"raw": [
"node=JD-debian-12-workstation type=SYSCALL msg=audit(1781634257.762:512605): arch=c000003e syscall=59 success=yes exit=0 a0=2442de3bf7e8 a1=2442dd0f4cb0 a2=2442dd889e60 a3=0 items=2 ppid=671 pid=2407 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=\"iptables\" exe=\"/usr/sbin/xtables-nft-multi\" subj=system_u:system_r:iptables_t:s0 key=\"T1059_exec\"",
"ARCH=x86_64 SYSCALL=execve AUID=\"unset\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
"node=JD-debian-12-workstation type=EXECVE msg=audit(1781634257.762:512605): argc=13 a0=\"/usr/sbin/iptables\" a1=\"--wait\" a2=\"-t\" a3=\"raw\" a4=\"-C\" a5=\"PREROUTING\" a6=\"-d\" a7=\"172.18.0.6\" a8=\"!\" a9=\"-i\" a10=\"br-440f323861ca\" a11=\"-j\" a12=\"DROP\"",
"node=JD-debian-12-workstation type=CWD msg=audit(1781634257.762:512605): cwd=\"/\"",
"node=JD-debian-12-workstation type=PATH msg=audit(1781634257.762:512605): item=0 name=\"/usr/sbin/iptables\" inode=5537074 dev=fe:01 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:iptables_exec_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
"OUID=\"root\" OGID=\"root\"",
"node=JD-debian-12-workstation type=PATH msg=audit(1781634257.762:512605): item=1 name=\"/lib64/ld-linux-x86-64.so.2\" inode=5505708 dev=fe:01 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:ld_so_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
"OUID=\"root\" OGID=\"root\"",
"node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781634257.762:512605): proctitle=2F7573722F7362696E2F69707461626C6573002D2D77616974002D7400726177002D4300505245524F5554494E47002D64003137322E31382E302E360021002D690062722D343430663332333836316361002D6A0044524F50"
],
"record_type": "PROCTITLE"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
type | eq | execve | 6 rules | splunk |
type | eq | proctitle | 6 rules | splunk |
type | in | execve | 2 rules | splunk |
type | in | proctitle | 2 rules | splunk |
type | in | user_cmd | 1 rule | splunk |
proctitle | in | *service * | 2 rules | splunk |
proctitle | in | *systemctl * | 2 rules | splunk |
CommandLine | is_not_null | | 1 rule | splunk |
c_process | lt | 3 | 1 rule | splunk |
dc_host | eq | 1 | 1 rule | splunk |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Splunk #
T1136, T1136.001T1480T1222, T1222.002
References #
FEATURE_CHANGE msgtype 1328
#Description
Audit feature changed value
Fields #
| Name | Description |
|---|---|
ppid | parent process ID |
pid | process ID |
auid | login user ID |
uid | user ID |
gid | group ID |
euid | effective user ID |
suid | sent user ID |
fsuid | file system user ID |
egid | effective group ID |
sgid | set group ID |
fsgid | file system group ID |
tty | tty udevice the user is running programs on |
ses | login session ID |
comm | command line program name |
exe | executable name |
subj | lspp subject's context string |
feature | kernel feature being changed |
old | previous value |
new | new value |
old_lock | feature lock state before the change |
new_lock | feature lock state after the change |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"auid": "1000",
"comm": "auditctl",
"egid": "0",
"euid": "0",
"exe": "/usr/sbin/auditctl",
"feature": "loginuid_immutable",
"fsgid": "0",
"fsuid": "0",
"gid": "0",
"new": "1",
"new_lock": "1",
"old": "0",
"old_lock": "0",
"pid": "33977",
"ppid": "33976",
"res": "1",
"ses": "1",
"sgid": "0",
"subj": "unconfined",
"suid": "0",
"tty": "(none)",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=FEATURE_CHANGE msg=audit(1781630669.800:1417007): ppid=33976 pid=33977 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=\"auditctl\" exe=\"/usr/sbin/auditctl\" subj=unconfined feature=loginuid_immutable old=0 new=1 old_lock=0 new_lock=1 res=1",
"AUID=\"debian\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\""
],
"record_type": "FEATURE_CHANGE"
}
References #
KERN_MODULE msgtype 1330
#Description
Kernel Module events
How it fires #
This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:
-a always,exit -F arch=b64 -S init_module,finit_module,delete_module -k modulesFields #
| Name | Description |
|---|---|
name | file name in avcs |
Example Audit Record #
{
"fields": {
"name": "nft_compat"
},
"raw": [
"node=JD-debian-12-workstation type=SYSCALL msg=audit(1781634171.392:79211): arch=c000003e syscall=313 success=yes exit=0 a0=0 a1=5566b4fed4a0 a2=0 a3=0 items=0 ppid=35 pid=701 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=\"modprobe\" exe=\"/usr/bin/kmod\" subj=system_u:system_r:kmod_t:s0 key=\"T1547_kernel_modules\"",
"ARCH=x86_64 SYSCALL=finit_module AUID=\"unset\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
"node=JD-debian-12-workstation type=KERN_MODULE msg=audit(1781634171.392:79211): name=\"nft_compat\"",
"node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781634171.392:79211): proctitle=2F7362696E2F6D6F6470726F6265002D71002D2D006E666E65746C696E6B2D7375627379732D3131"
],
"record_type": "KERN_MODULE"
}
References #
FANOTIFY msgtype 1331
#Description
Fanotify access decision
Fields #
| Name | Description |
|---|---|
resp | fanotify permission response (allow or deny) |
fan_type | fanotify response info type |
fan_info | fanotify audit rule number |
subj_trust | fanotify subject trust value (0 no, 1 yes, 2 unknown) |
obj_trust | fanotify object trust value (0 no, 1 yes, 2 unknown) |
Example Audit Record #
{
"fields": {
"fan_info": "2A",
"fan_type": "1",
"obj_trust": "0",
"resp": "1",
"subj_trust": "0"
},
"raw": [
"node=JD-debian-12-workstation type=FANOTIFY msg=audit(1781717953.135:245162): resp=1 fan_type=1 fan_info=2A subj_trust=0 obj_trust=0",
"node=JD-debian-12-workstation type=SYSCALL msg=audit(1781717953.135:245162): arch=c000003e syscall=257 success=yes exit=4 a0=ffffff9c a1=710119527dd0 a2=80000 a3=0 items=1 ppid=90046 pid=90047 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=59 comm=\"python3\" exe=\"/usr/bin/python3.11\" subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key=\"fanotify\"",
"ARCH=x86_64 SYSCALL=openat AUID=\"debian\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
"node=JD-debian-12-workstation type=CWD msg=audit(1781717953.135:245162): cwd=\"/home/debian\"",
"node=JD-debian-12-workstation type=PATH msg=audit(1781717953.135:245162): item=0 name=\"/tmp/fant\" inode=1835017 dev=fd:01 mode=0100644 ouid=0 ogid=0 rdev=00:00 obj=unconfined_u:object_r:user_tmp_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
"OUID=\"root\" OGID=\"root\"",
"node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781717953.135:245162): proctitle=707974686F6E33002D"
],
"record_type": "FANOTIFY"
}
References #
TIME_INJOFFSET msgtype 1332
#Description
Timekeeping offset injected
How it fires #
This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:
-a always,exit -F arch=b64 -S clock_settime,settimeofday -k time-changeFields #
| Name | Description |
|---|---|
sec | seconds component of the time change |
nsec | nanoseconds component of the time change |
Example Audit Record #
{
"fields": {
"nsec": "398226411",
"sec": "-1"
},
"raw": [
"node=JD-debian-12-workstation type=SYSCALL msg=audit(1781627806.598:582950): arch=c000003e syscall=164 success=yes exit=0 a0=7f5df5e12380 a1=0 a2=3befff30 a3=7f5df5db4bc0 items=0 ppid=4981 pid=4982 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=\"python3\" exe=\"/usr/bin/python3.11\" subj=unconfined key=\"T1070_time_change\"",
"ARCH=x86_64 SYSCALL=settimeofday AUID=\"debian\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
"node=JD-debian-12-workstation type=TIME_INJOFFSET msg=audit(1781627806.598:582950): sec=-1 nsec=398226411",
"node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781627806.598:582950): proctitle=7375646F002F7573722F62696E2F707974686F6E33002D"
],
"record_type": "TIME_INJOFFSET"
}
References #
TIME_ADJNTPVAL msgtype 1333
#Description
NTP value adjustment
How it fires #
This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:
-a always,exit -F arch=b64 -S adjtimex,clock_adjtime -k time-changeFields #
| Name | Description |
|---|---|
op | the operation being performed that is audited |
old | previous value |
new | new value |
Example Audit Record #
{
"fields": {
"new": "138842102107734",
"old": "-721856555751",
"op": "offset"
},
"raw": [
"node=JD-debian-12-workstation type=SYSCALL msg=audit(1781634263.290:518491): arch=c000003e syscall=305 success=yes exit=0 a0=0 a1=7ffc08480930 a2=0 a3=7ffc0858d080 items=0 ppid=1 pid=453 auid=4294967295 uid=996 gid=996 euid=996 suid=996 fsuid=996 egid=996 sgid=996 fsgid=996 tty=(none) ses=4294967295 comm=\"systemd-timesyn\" exe=\"/usr/lib/systemd/systemd-timesyncd\" subj=system_u:system_r:ntpd_t:s0 key=\"cat_time\"",
"ARCH=x86_64 SYSCALL=clock_adjtime AUID=\"unset\" UID=\"systemd-timesync\" GID=\"systemd-timesync\" EUID=\"systemd-timesync\" SUID=\"systemd-timesync\" FSUID=\"systemd-timesync\" EGID=\"systemd-timesync\" SGID=\"systemd-timesync\" FSGID=\"systemd-timesync\"",
"node=JD-debian-12-workstation type=TIME_ADJNTPVAL msg=audit(1781634263.290:518491): op=offset old=-721856555751 new=138842102107734",
"node=JD-debian-12-workstation type=TIME_ADJNTPVAL msg=audit(1781634263.290:518491): op=freq old=-87703970381824 new=47884019957760",
"node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781634263.290:518491): proctitle=\"/lib/systemd/systemd-timesyncd\""
],
"record_type": "TIME_ADJNTPVAL"
}
References #
BPF msgtype 1334
#Description
BPF load/unload
Fields #
| Name | Description |
|---|---|
prog-id | BPF program ID |
op | the operation being performed that is audited |
Example Audit Record #
{
"fields": {
"op": "LOAD",
"prog-id": "81"
},
"raw": [
"node=JD-debian-12-workstation type=BPF msg=audit(1781634257.694:511163): prog-id=81 op=LOAD",
"node=JD-debian-12-workstation type=SYSCALL msg=audit(1781634257.694:511163): arch=c000003e syscall=321 success=yes exit=85 a0=5 a1=7ffc318bf920 a2=90 a3=4 items=0 ppid=0 pid=1 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=\"systemd\" exe=\"/usr/lib/systemd/systemd\" subj=system_u:system_r:init_t:s0 key=\"cat_bpf\"",
"ARCH=x86_64 SYSCALL=bpf AUID=\"unset\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
"node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781634257.694:511163): proctitle=\"/sbin/init\""
],
"record_type": "BPF"
}
References #
EVENT_LISTENER msgtype 1335
#Description
audit mcast sock join/part
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
tty | tty udevice the user is running programs on |
ses | login session ID |
subj | lspp subject's context string |
comm | command line program name |
exe | executable name |
nl-mcgrp | audit netlink multicast group joined or left |
op | the operation being performed that is audited |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"auid": "4294967295",
"comm": "systemd",
"exe": "/usr/lib/systemd/systemd",
"nl-mcgrp": "1",
"op": "connect",
"pid": "1",
"res": "1",
"ses": "4294967295",
"subj": "system_u:system_r:init_t:s0",
"tty": "(none)",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=EVENT_LISTENER msg=audit(1781634165.636:9): pid=1 uid=0 auid=4294967295 tty=(none) ses=4294967295 subj=system_u:system_r:init_t:s0 comm=\"systemd\" exe=\"/usr/lib/systemd/systemd\" nl-mcgrp=1 op=connect res=1",
"UID=\"root\" AUID=\"unset\"",
"node=JD-debian-12-workstation type=SYSCALL msg=audit(1781634165.636:9): arch=c000003e syscall=49 success=yes exit=0 a0=20 a1=55b6f362dc40 a2=c a3=7ffc318bfd84 items=0 ppid=0 pid=1 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=\"systemd\" exe=\"/usr/lib/systemd/systemd\" subj=system_u:system_r:init_t:s0 key=(null)",
"ARCH=x86_64 SYSCALL=bind AUID=\"unset\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
"node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781634165.636:9): proctitle=\"/sbin/init\""
],
"record_type": "EVENT_LISTENER"
}
References #
URINGOP msgtype 1336
#Description
io_uring operation
How it fires #
This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:
-a always,exit -F arch=b64 -S io_uring_enter -k uringFields #
| Name | Description |
|---|---|
uring_op | io_uring operation code |
success | whether the syscall was successful or not |
exit | syscall exit code |
items | the number of path records in the event |
ppid | parent process ID |
pid | process ID |
uid | user ID |
gid | group ID |
euid | effective user ID |
suid | sent user ID |
fsuid | file system user ID |
egid | effective group ID |
sgid | set group ID |
fsgid | file system group ID |
subj | lspp subject's context string |
key | key assigned from triggered audit rule |
Example Audit Record #
{
"fields": {
"egid": "0",
"euid": "0",
"exit": "0",
"fsgid": "0",
"fsuid": "0",
"gid": "0",
"items": "1",
"key": "uringcap",
"pid": "38669",
"ppid": "38651",
"sgid": "0",
"subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
"success": "yes",
"suid": "0",
"uid": "0",
"uring_op": "18"
},
"raw": [
"node=JD-debian-12-workstation type=URINGOP msg=audit(1781732081.383:1214470): uring_op=18 success=yes exit=0 items=1 ppid=38651 pid=38669 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key=\"uringcap\"",
"UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
"node=JD-debian-12-workstation type=SYSCALL msg=audit(1781732081.383:1214470): arch=c000003e syscall=426 success=yes exit=1 a0=3 a1=1 a2=1 a3=1 items=1 ppid=38651 pid=38669 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=54 comm=\"uring\" exe=\"/tmp/recap/uring\" subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key=\"uringcap\"",
"ARCH=x86_64 SYSCALL=io_uring_enter AUID=\"debian\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
"node=JD-debian-12-workstation type=CWD msg=audit(1781732081.383:1214470): cwd=\"/home/debian\"",
"node=JD-debian-12-workstation type=PATH msg=audit(1781732081.383:1214470): item=0 name=\"/etc/hostname\" inode=11010243 dev=fd:01 mode=0100644 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:net_conf_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
"OUID=\"root\" OGID=\"root\"",
"node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781732081.383:1214470): proctitle=\"/tmp/recap/uring\""
],
"record_type": "URINGOP"
}
References #
OPENAT2 msgtype 1337
#Description
Record showing openat2 how args
How it fires #
This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:
-a always,exit -F arch=b64 -S openat2 -k openFields #
| Name | Description |
|---|---|
oflag | open syscall flags |
mode | Landlock domain enforcement mode (enforcing) |
resolve | openat2 RESOLVE_* flags |
Example Audit Record #
{
"fields": {
"mode": "00",
"oflag": "012000000",
"resolve": "0x14"
},
"raw": [
"node=JD-debian-12-workstation type=SYSCALL msg=audit(1781634257.690:510676): arch=c000003e syscall=437 success=yes exit=12 a0=ffffffffffffff9c a1=c00015de3a a2=c000140d88 a3=18 items=1 ppid=2351 pid=2392 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=\"runc:[2:INIT]\" exe=\"/runc\" subj=system_u:system_r:initrc_t:s0 key=\"cat_openat2\"",
"ARCH=x86_64 SYSCALL=openat2 AUID=\"unset\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
"node=JD-debian-12-workstation type=OPENAT2 msg=audit(1781634257.690:510676): oflag=012000000 mode=00 resolve=0x14",
"node=JD-debian-12-workstation type=CWD msg=audit(1781634257.690:510676): cwd=\"/var/lib/docker/rootfs/overlayfs/5532208236a5c5797a9da401566d1b5a1b0fc8324846bcf558a1b2d96fff977e\"",
"node=JD-debian-12-workstation type=PATH msg=audit(1781634257.690:510676): item=0 name=\".\" inode=4755763 dev=00:35 mode=040755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:var_lib_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
"OUID=\"root\" OGID=\"root\"",
"node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781634257.690:510676): proctitle=72756E6300696E6974"
],
"record_type": "OPENAT2"
}
References #
DM_CTRL msgtype 1338
#Description
Device Mapper target control
Fields #
| Name | Description |
|---|---|
module | device-mapper target or kernel module name |
op | the operation being performed that is audited |
ppid | parent process ID |
pid | process ID |
auid | login user ID |
uid | user ID |
gid | group ID |
euid | effective user ID |
suid | sent user ID |
fsuid | file system user ID |
egid | effective group ID |
sgid | set group ID |
fsgid | file system group ID |
tty | tty udevice the user is running programs on |
ses | login session ID |
comm | command line program name |
exe | executable name |
subj | lspp subject's context string |
dev | device identifier |
error_msg | device-mapper target error text on failure, or the literal string success when the operation succeeded |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"auid": "1000",
"comm": "cryptsetup",
"dev": "253:0",
"egid": "0",
"error_msg": "success",
"euid": "0",
"exe": "/usr/sbin/cryptsetup",
"fsgid": "0",
"fsuid": "0",
"gid": "0",
"module": "crypt",
"op": "dtr",
"pid": "56754",
"ppid": "56702",
"res": "1",
"ses": "15",
"sgid": "0",
"subj": "unconfined",
"suid": "0",
"tty": "(none)",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=UNKNOWN[1338] msg=audit(1781632713.768:2113664): module=crypt op=dtr ppid=56702 pid=56754 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=15 comm=\"cryptsetup\" exe=\"/usr/sbin/cryptsetup\" subj=unconfined dev=253:0 error_msg='success' res=1",
"AUID=\"debian\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\""
],
"record_type": "DM_CTRL"
}
References #
DM_EVENT msgtype 1339
#Description
Device Mapper events
Fields #
| Name | Description |
|---|---|
module | device-mapper target or kernel module name |
op | the operation being performed that is audited |
dev | device identifier |
sector | device-mapper device sector |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"dev": "7:0",
"module": "verity",
"op": "verify-data",
"res": "0",
"sector": "100"
},
"raw": [
"node=JD-debian-12-workstation type=UNKNOWN[1339] msg=audit(1781674379.650:245044): module=verity op=verify-data dev=7:0 sector=100 res=0"
],
"record_type": "DM_EVENT"
}
References #
AVC msgtype 1400
#Description
SELinux AVC (Access Vector Cache) denial or grant
Fields #
| Name | Description |
|---|---|
pid | Process ID of the subject |
comm | Command name of the subject |
path | Target path, when the full path is resolved |
name | Target object name, when the full path is not resolved |
dev | Device of the target object |
ino | Inode number of the target object |
scontext | SELinux security context of the subject |
tcontext | SELinux security context of the target object |
tclass | Object class of the target (file, dir, sock_file, ...) |
permissive | SELinux mode at decision time (1 permissive, 0 enforcing) |
ioctlcmd | The request argument to the ioctl syscall |
Example Audit Record #
{
"fields": {
"comm": "avcprobe",
"dev": "vda1",
"ino": "2",
"name": "/",
"permissive": "1",
"pid": "107789",
"scontext": "unconfined_u:unconfined_r:dwbad_t:s0-s0:c0.c1023",
"tclass": "dir",
"tcontext": "system_u:object_r:root_t:s0"
},
"raw": [
"node=JD-debian-12-workstation type=AVC msg=audit(1781738979.016:2269224): avc: denied { search } for pid=107789 comm=\"avcprobe\" name=\"/\" dev=\"vda1\" ino=2 scontext=unconfined_u:unconfined_r:dwbad_t:s0-s0:c0.c1023 tcontext=system_u:object_r:root_t:s0 tclass=dir permissive=1",
"node=JD-debian-12-workstation type=AVC msg=audit(1781738979.016:2269224): avc: denied { search } for pid=107789 comm=\"avcprobe\" name=\"etc\" dev=\"vda1\" ino=11010049 scontext=unconfined_u:unconfined_r:dwbad_t:s0-s0:c0.c1023 tcontext=system_u:object_r:etc_t:s0 tclass=dir permissive=1",
"node=JD-debian-12-workstation type=AVC msg=audit(1781738979.016:2269224): avc: denied { read } for pid=107789 comm=\"avcprobe\" name=\"passwd\" dev=\"vda1\" ino=11011862 scontext=unconfined_u:unconfined_r:dwbad_t:s0-s0:c0.c1023 tcontext=system_u:object_r:etc_t:s0 tclass=file permissive=1",
"node=JD-debian-12-workstation type=AVC msg=audit(1781738979.016:2269224): avc: denied { open } for pid=107789 comm=\"avcprobe\" path=\"/etc/passwd\" dev=\"vda1\" ino=11011862 scontext=unconfined_u:unconfined_r:dwbad_t:s0-s0:c0.c1023 tcontext=system_u:object_r:etc_t:s0 tclass=file permissive=1",
"node=JD-debian-12-workstation type=SYSCALL msg=audit(1781738979.016:2269224): arch=c000003e syscall=257 success=yes exit=3 a0=ffffff9c a1=479004 a2=0 a3=22347680 items=1 ppid=107769 pid=107789 auid=1000 uid=1000 gid=1000 euid=1000 suid=1000 fsuid=1000 egid=1000 sgid=1000 fsgid=1000 tty=(none) ses=91 comm=\"avcprobe\" exe=\"/tmp/dwcap/avcprobe\" subj=unconfined_u:unconfined_r:dwbad_t:s0-s0:c0.c1023 key=\"dwavc\"",
"ARCH=x86_64 SYSCALL=openat AUID=\"debian\" UID=\"debian\" GID=\"debian\" EUID=\"debian\" SUID=\"debian\" FSUID=\"debian\" EGID=\"debian\" SGID=\"debian\" FSGID=\"debian\"",
"node=JD-debian-12-workstation type=CWD msg=audit(1781738979.016:2269224): cwd=\"/home/debian\"",
"node=JD-debian-12-workstation type=PATH msg=audit(1781738979.016:2269224): item=0 name=\"/etc/passwd\" inode=11011862 dev=fd:01 mode=0100644 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:etc_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
"OUID=\"root\" OGID=\"root\"",
"node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781738979.016:2269224): proctitle=\"/tmp/dwcap/avcprobe\""
],
"record_type": "AVC"
}
References #
SELINUX_ERR msgtype 1401
#Description
Internal SELinux errors
Fields #
| Name | Description |
|---|---|
op | the operation being performed that is audited |
reason | reason for the operation |
scontext | the subject's context string |
tcontext | the target's or object's context string |
tclass | target's object classification |
perms | SELinux permissions involved in the error |
seresult | SELinux access decision result |
oldcontext | SELinux context before the error |
newcontext | SELinux context after the error |
taskcontext | SELinux context of the acting task |
invalid_context | the SELinux context that failed validation |
Example Audit Record #
{
"fields": {
"invalid_context": "unconfined_u:unconfined_r:dwbad_t:s0-s0:c0.c1023",
"op": "security_compute_sid",
"scontext": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
"tclass": "process",
"tcontext": "unconfined_u:object_r:dwexec_t:s0"
},
"raw": [
"node=JD-debian-12-workstation type=SELINUX_ERR msg=audit(1781732167.209:1214562): op=security_compute_sid invalid_context=\"unconfined_u:unconfined_r:dwbad_t:s0-s0:c0.c1023\" scontext=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:dwexec_t:s0 tclass=process",
"node=JD-debian-12-workstation type=SYSCALL msg=audit(1781732167.209:1214562): arch=c000003e syscall=59 success=yes exit=0 a0=5bec7c15fa40 a1=5bec7c163d40 a2=5bec7c161240 a3=45fdd64043621a67 items=1 ppid=39588 pid=39651 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=58 comm=\"dwtrig\" exe=\"/tmp/dwtrig\" subj=unconfined_u:unconfined_r:dwbad_t:s0-s0:c0.c1023 key=\"selerr2\"",
"ARCH=x86_64 SYSCALL=execve AUID=\"debian\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
"node=JD-debian-12-workstation type=EXECVE msg=audit(1781732167.209:1214562): argc=1 a0=\"/tmp/dwtrig\"",
"node=JD-debian-12-workstation type=CWD msg=audit(1781732167.209:1214562): cwd=\"/tmp/recap\"",
"node=JD-debian-12-workstation type=PATH msg=audit(1781732167.209:1214562): item=0 name=\"/tmp/dwtrig\" inode=1835021 dev=fd:01 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=unconfined_u:object_r:dwexec_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
"OUID=\"root\" OGID=\"root\"",
"node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781732167.209:1214562): proctitle=\"/tmp/dwtrig\""
],
"record_type": "SELINUX_ERR"
}
References #
AVC_PATH msgtype 1402
#Description
dentry, vfsmount pair from AVC
MAC_POLICY_LOAD msgtype 1403
#Description
SELinux Policy file load
Fields #
| Name | Description |
|---|---|
auid | login user ID |
ses | login session ID |
lsm | security module that produced the record (selinux, apparmor, ...) |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"auid": "1000",
"lsm": "selinux",
"res": "1",
"ses": "1"
},
"raw": [
"node=JD-debian-12-workstation type=MAC_POLICY_LOAD msg=audit(1781634271.083:538063): auid=1000 ses=1 lsm=selinux res=1",
"AUID=\"debian\""
],
"record_type": "MAC_POLICY_LOAD"
}
References #
MAC_STATUS msgtype 1404
#Description
SELinux mode (enforcing, permissive, off) changed
Fields #
| Name | Description |
|---|---|
enforcing | whether enforcing mode is active (1) or permissive (0) |
old_enforcing | MAC enforcing state before this change |
auid | login user ID |
ses | login session ID |
enabled | MAC enabled state (1 enabled, 0 disabled) |
old-enabled | MAC enabled state before this change |
lsm | security module that produced the record (selinux, apparmor, ...) |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"auid": "1000",
"enabled": "1",
"enforcing": "0",
"lsm": "selinux",
"old-enabled": "1",
"old_enforcing": "1",
"res": "1",
"ses": "1"
},
"raw": [
"node=JD-debian-12-workstation type=MAC_STATUS msg=audit(1781635211.620:942490): enforcing=0 old_enforcing=1 auid=1000 ses=1 enabled=1 old-enabled=1 lsm=selinux res=1",
"AUID=\"debian\""
],
"record_type": "MAC_STATUS"
}
MAC_CONFIG_CHANGE msgtype 1405
#Description
SELinux Boolean value modification
Fields #
| Name | Description |
|---|---|
bool | name of SELinux boolean |
val | value associated with the operation |
old_val | configuration value before the change |
auid | login user ID |
ses | login session ID |
Example Audit Record #
{
"fields": {
"auid": "1000",
"bool": "aide_mmap_files",
"old_val": "1",
"ses": "1",
"val": "0"
},
"raw": [
"node=JD-debian-12-workstation type=MAC_CONFIG_CHANGE msg=audit(1781634267.951:529349): bool=aide_mmap_files val=0 old_val=1 auid=1000 ses=1",
"AUID=\"debian\""
],
"record_type": "MAC_CONFIG_CHANGE"
}
References #
MAC_UNLBL_ALLOW msgtype 1406
#Description
NetLabel: allow unlabeled traffic
Fields #
| Name | Description |
|---|---|
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
unlbl_accept | NetLabel unlabeled-traffic accept flag |
old | previous value |
Example Audit Record #
{
"fields": {
"auid": "0",
"old": "0",
"ses": "0",
"subj": "kernel",
"unlbl_accept": "1"
},
"raw": [
"node=JD-debian-12-workstation type=MAC_UNLBL_ALLOW msg=audit(1781634163.940:3): netlabel: auid=0 ses=0 subj=kernel unlbl_accept=1 old=0",
"AUID=\"root\""
],
"record_type": "MAC_UNLBL_ALLOW"
}
References #
MAC_CIPSOV4_ADD msgtype 1407
#Description
NetLabel: add CIPSOv4 (Commercial Internet Protocol Security Option) DOI (Domain of Interpretation) entry
Fields #
| Name | Description |
|---|---|
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
cipso_doi | CIPSO domain of interpretation |
cipso_type | CIPSO mapping type |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"auid": "1000",
"cipso_doi": "100",
"cipso_type": "pass",
"res": "1",
"ses": "15",
"subj": "unconfined"
},
"raw": [
"node=JD-debian-12-workstation type=MAC_CIPSOV4_ADD msg=audit(1781632713.492:2112345): netlabel: auid=1000 ses=15 subj=unconfined cipso_doi=100 cipso_type=pass res=1",
"AUID=\"debian\"",
"node=JD-debian-12-workstation type=SYSCALL msg=audit(1781632713.492:2112345): arch=c000003e syscall=46 success=yes exit=48 a0=3 a1=7ffe48408fb0 a2=0 a3=7f749dc3a050 items=0 ppid=56702 pid=56718 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=15 comm=\"netlabelctl\" exe=\"/usr/sbin/netlabelctl\" subj=unconfined key=\"T1071_msg_transfer\"",
"ARCH=x86_64 SYSCALL=sendmsg AUID=\"debian\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
"node=JD-debian-12-workstation type=SOCKADDR msg=audit(1781632713.492:2112345): saddr=100000000000000000000000",
"SADDR={ saddr_fam=netlink nlnk-fam=16 nlnk-pid=0 }",
"node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781632713.492:2112345): proctitle=6E65746C6162656C63746C00636970736F763400616464007061737300646F693A31303000746167733A31006C6576656C733A303D30"
],
"record_type": "MAC_CIPSOV4_ADD"
}
References #
MAC_CIPSOV4_DEL msgtype 1408
#Description
NetLabel: del CIPSOv4 (Commercial Internet Protocol Security Option) DOI (Domain of Interpretation) entry
Fields #
| Name | Description |
|---|---|
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
cipso_doi | CIPSO domain of interpretation |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"auid": "1000",
"cipso_doi": "100",
"res": "1",
"ses": "15",
"subj": "unconfined"
},
"raw": [
"node=JD-debian-12-workstation type=MAC_CIPSOV4_DEL msg=audit(1781632713.512:2112730): netlabel: auid=1000 ses=15 subj=unconfined cipso_doi=100 res=1",
"AUID=\"debian\"",
"node=JD-debian-12-workstation type=SYSCALL msg=audit(1781632713.512:2112730): arch=c000003e syscall=46 success=yes exit=28 a0=3 a1=7ffdb3875560 a2=0 a3=7f164ef2f050 items=0 ppid=56702 pid=56730 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=15 comm=\"netlabelctl\" exe=\"/usr/sbin/netlabelctl\" subj=unconfined key=\"T1071_msg_transfer\"",
"ARCH=x86_64 SYSCALL=sendmsg AUID=\"debian\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
"node=JD-debian-12-workstation type=SOCKADDR msg=audit(1781632713.512:2112730): saddr=100000000000000000000000",
"SADDR={ saddr_fam=netlink nlnk-fam=16 nlnk-pid=0 }",
"node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781632713.512:2112730): proctitle=6E65746C6162656C63746C00636970736F76340064656C00646F693A313030"
],
"record_type": "MAC_CIPSOV4_DEL"
}
References #
MAC_MAP_ADD msgtype 1409
#Description
NetLabel: add LSM (Linux Security Module) domain mapping
Fields #
| Name | Description |
|---|---|
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
nlbl_domain | NetLabel domain mapping name |
nlbl_protocol | NetLabel protocol for the domain mapping |
cipso_doi | CIPSO domain of interpretation |
calipso_doi | CALIPSO domain of interpretation |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"auid": "0",
"nlbl_domain": "(default)",
"nlbl_protocol": "unlbl",
"res": "1",
"ses": "0",
"subj": "kernel"
},
"raw": [
"node=JD-debian-12-workstation type=MAC_MAP_ADD msg=audit(1781634163.940:2): netlabel: auid=0 ses=0 subj=kernel nlbl_domain=(default) nlbl_protocol=unlbl res=1",
"AUID=\"root\""
],
"record_type": "MAC_MAP_ADD"
}
References #
MAC_MAP_DEL msgtype 1410
#Description
NetLabel: del LSM (Linux Security Module) domain mapping
Fields #
| Name | Description |
|---|---|
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
nlbl_domain | NetLabel domain mapping name |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"auid": "1000",
"nlbl_domain": "catalog.test",
"res": "1",
"ses": "15",
"subj": "unconfined"
},
"raw": [
"node=JD-debian-12-workstation type=MAC_MAP_DEL msg=audit(1781632713.508:2112660): netlabel: auid=1000 ses=15 subj=unconfined nlbl_domain=catalog.test res=1",
"AUID=\"debian\"",
"node=JD-debian-12-workstation type=SYSCALL msg=audit(1781632713.508:2112660): arch=c000003e syscall=46 success=yes exit=40 a0=3 a1=7ffe062e4fc0 a2=0 a3=7fde3f195050 items=0 ppid=56702 pid=56728 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=15 comm=\"netlabelctl\" exe=\"/usr/sbin/netlabelctl\" subj=unconfined key=\"T1071_msg_transfer\"",
"ARCH=x86_64 SYSCALL=sendmsg AUID=\"debian\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
"node=JD-debian-12-workstation type=SOCKADDR msg=audit(1781632713.508:2112660): saddr=100000000000000000000000",
"SADDR={ saddr_fam=netlink nlnk-fam=16 nlnk-pid=0 }",
"node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781632713.508:2112660): proctitle=6E65746C6162656C63746C006D61700064656C00646F6D61696E3A636174616C6F672E74657374"
],
"record_type": "MAC_MAP_DEL"
}
References #
MAC_IPSEC_ADDSA msgtype 1411
#Description
Not used
MAC_IPSEC_DELSA msgtype 1412
#Description
Not used
MAC_IPSEC_ADDSPD msgtype 1413
#Description
Not used
MAC_IPSEC_DELSPD msgtype 1414
#Description
Not used
MAC_IPSEC_EVENT msgtype 1415
#Description
Audit an IPsec event
Fields #
| Name | Description |
|---|---|
op | the operation being performed that is audited |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
src | source address of the IPsec security association |
dst | destination address of the IPsec security association |
spi | IPsec Security Parameter Index |
src_prefixlen | source address prefix length |
dst_prefixlen | destination address prefix length |
sec_obj | security context label of the IPsec object |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"auid": "1000",
"dst": "192.0.2.2",
"op": "SAD-add",
"res": "1",
"ses": "15",
"spi": "1(0x1)",
"src": "192.0.2.1",
"subj": "unconfined"
},
"raw": [
"node=JD-debian-12-workstation type=MAC_IPSEC_EVENT msg=audit(1781632420.375:1883324): op=SAD-add auid=1000 ses=15 subj=unconfined src=192.0.2.1 dst=192.0.2.2 spi=1(0x1) res=1",
"AUID=\"debian\"",
"node=JD-debian-12-workstation type=SYSCALL msg=audit(1781632420.375:1883324): arch=c000003e syscall=46 success=yes exit=432 a0=4 a1=7ffdf4dabb80 a2=0 a3=7ffdf4dabc04 items=0 ppid=51449 pid=51553 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=15 comm=\"ip\" exe=\"/usr/bin/ip\" subj=unconfined key=\"T1071_msg_transfer\"",
"ARCH=x86_64 SYSCALL=sendmsg AUID=\"debian\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
"node=JD-debian-12-workstation type=SOCKADDR msg=audit(1781632420.375:1883324): saddr=100000000000000000000000",
"SADDR={ saddr_fam=netlink nlnk-fam=16 nlnk-pid=0 }",
"node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781632420.375:1883324): proctitle=6970007866726D0073746174650061646400737263003139322E302E322E3100647374003139322E302E322E320070726F746F006573700073706900307831006D6F6465007472616E73706F72740061757468007368613235360030783031303230333034303530363037303830393061306230633064306530663130313131"
],
"record_type": "MAC_IPSEC_EVENT"
}
MAC_UNLBL_STCADD msgtype 1416
#Description
NetLabel: add a static label
Fields #
| Name | Description |
|---|---|
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
netif | network interface the static NetLabel mapping is bound to (absent for default all-interface entries) |
src | source address of the static NetLabel unlabeled-traffic mapping |
src_prefixlen | source address prefix length |
sec_obj | LSM security context assigned to unlabeled traffic matching this static NetLabel mapping |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"auid": "1000",
"res": "1",
"sec_obj": "system_u:object_r:unlabeled_t:s0",
"ses": "1",
"src": "198.51.100.0",
"src_prefixlen": "24",
"subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023"
},
"raw": [
"node=JD-debian-12-workstation type=MAC_UNLBL_STCADD msg=audit(1781635211.640:942744): netlabel: auid=1000 ses=1 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 src=198.51.100.0 src_prefixlen=24 sec_obj=system_u:object_r:unlabeled_t:s0 res=1",
"AUID=\"debian\""
],
"record_type": "MAC_UNLBL_STCADD"
}
References #
MAC_UNLBL_STCDEL msgtype 1417
#Description
NetLabel: del a static label
Fields #
| Name | Description |
|---|---|
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
netif | network interface the static NetLabel mapping is bound to (absent for default all-interface entries) |
src | source address of the static NetLabel unlabeled-traffic mapping |
src_prefixlen | source address prefix length |
sec_obj | LSM security context assigned to unlabeled traffic matching this static NetLabel mapping |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"auid": "1000",
"res": "1",
"sec_obj": "system_u:object_r:unlabeled_t:s0",
"ses": "1",
"src": "198.51.100.0",
"src_prefixlen": "24",
"subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023"
},
"raw": [
"node=JD-debian-12-workstation type=MAC_UNLBL_STCDEL msg=audit(1781635211.644:942826): netlabel: auid=1000 ses=1 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 src=198.51.100.0 src_prefixlen=24 sec_obj=system_u:object_r:unlabeled_t:s0 res=1",
"AUID=\"debian\""
],
"record_type": "MAC_UNLBL_STCDEL"
}
References #
MAC_CALIPSO_ADD msgtype 1418
#Description
NetLabel: add CALIPSO DOI (Domain of Interpretation) entry
Fields #
| Name | Description |
|---|---|
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
calipso_doi | CALIPSO domain of interpretation |
calipso_type | CALIPSO mapping type |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"auid": "1000",
"calipso_doi": "200",
"calipso_type": "pass",
"res": "1",
"ses": "15",
"subj": "unconfined"
},
"raw": [
"node=JD-debian-12-workstation type=MAC_CALIPSO_ADD msg=audit(1781632713.500:2112517): netlabel: auid=1000 ses=15 subj=unconfined calipso_doi=200 calipso_type=pass res=1",
"AUID=\"debian\"",
"node=JD-debian-12-workstation type=SYSCALL msg=audit(1781632713.500:2112517): arch=c000003e syscall=46 success=yes exit=36 a0=3 a1=7ffd0bc59260 a2=0 a3=7f524c214050 items=0 ppid=56702 pid=56724 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=15 comm=\"netlabelctl\" exe=\"/usr/sbin/netlabelctl\" subj=unconfined key=\"T1071_msg_transfer\"",
"ARCH=x86_64 SYSCALL=sendmsg AUID=\"debian\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
"node=JD-debian-12-workstation type=SOCKADDR msg=audit(1781632713.500:2112517): saddr=100000000000000000000000",
"SADDR={ saddr_fam=netlink nlnk-fam=16 nlnk-pid=0 }",
"node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781632713.500:2112517): proctitle=6E65746C6162656C63746C0063616C6970736F00616464007061737300646F693A323030"
],
"record_type": "MAC_CALIPSO_ADD"
}
References #
MAC_CALIPSO_DEL msgtype 1419
#Description
NetLabel: delete CALIPSO DOI (Domain of Interpretation) entry
Fields #
| Name | Description |
|---|---|
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
calipso_doi | CALIPSO domain of interpretation |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"auid": "1000",
"calipso_doi": "200",
"res": "1",
"ses": "15",
"subj": "unconfined"
},
"raw": [
"node=JD-debian-12-workstation type=MAC_CALIPSO_DEL msg=audit(1781632713.516:2112798): netlabel: auid=1000 ses=15 subj=unconfined calipso_doi=200 res=1",
"AUID=\"debian\"",
"node=JD-debian-12-workstation type=SYSCALL msg=audit(1781632713.516:2112798): arch=c000003e syscall=46 success=yes exit=28 a0=3 a1=7ffddedd1830 a2=0 a3=7f1209fc6050 items=0 ppid=56702 pid=56732 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=15 comm=\"netlabelctl\" exe=\"/usr/sbin/netlabelctl\" subj=unconfined key=\"T1071_msg_transfer\"",
"ARCH=x86_64 SYSCALL=sendmsg AUID=\"debian\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
"node=JD-debian-12-workstation type=SOCKADDR msg=audit(1781632713.516:2112798): saddr=100000000000000000000000",
"SADDR={ saddr_fam=netlink nlnk-fam=16 nlnk-pid=0 }",
"node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781632713.516:2112798): proctitle=6E65746C6162656C63746C0063616C6970736F0064656C00646F693A323030"
],
"record_type": "MAC_CALIPSO_DEL"
}
References #
IPE_ACCESS msgtype 1420
#Description
Integrity Policy Enforcement (IPE) access decision (denial or grant)
Fields #
| Name | Description |
|---|---|
ipe_op | IPE operation being evaluated |
ipe_hook | IPE enforcement hook point |
enforcing | whether enforcing mode is active (1) or permissive (0) |
pid | process ID |
comm | command line program name |
path | file system path name |
dev | device identifier |
ino | inode number |
rule | the policy rule that matched, quoted verbatim; the op= and action= (ALLOW/DENY) tokens inside the quotes are sub-tokens of this value, not independent record fields |
Example Audit Record #
{
"fields": {
"comm": "kexec",
"dev": "vda1",
"enforcing": "1",
"ino": "2490727",
"ipe_hook": "KERNEL_READ",
"ipe_op": "KEXEC_IMAGE",
"path": "/boot/vmlinuz-6.19.14-ipe2",
"pid": "5215",
"rule": "op=KEXEC_IMAGE action=DENY"
},
"raw": [
"node=JD-debian-12-workstation type=UNKNOWN[1420] msg=audit(1781728753.988:612193): ipe_op=KEXEC_IMAGE ipe_hook=KERNEL_READ enforcing=1 pid=5215 comm=\"kexec\" path=\"/boot/vmlinuz-6.19.14-ipe2\" dev=\"vda1\" ino=2490727 rule=\"op=KEXEC_IMAGE action=DENY\""
],
"record_type": "IPE_ACCESS"
}
References #
IPE_CONFIG_CHANGE msgtype 1421
#Description
IPE active policy change
Fields #
| Name | Description |
|---|---|
old_active_pol_name | previously active IPE policy name |
old_active_pol_version | previously active IPE policy version |
old_policy_digest | content digest of the previously active IPE policy |
new_active_pol_name | newly active IPE policy name |
new_active_pol_version | newly active IPE policy version |
new_policy_digest | content digest of the newly active IPE policy |
auid | login user ID |
ses | login session ID |
lsm | security module that produced the record (always ipe) |
res | result of the audited operation (hardcoded 1; activation only audits on success) |
Example Audit Record #
{
"fields": {
"auid": "1000",
"lsm": "ipe",
"new_active_pol_name": "dwipe2",
"new_active_pol_version": "1.0.0",
"new_policy_digest": "sha256:51304269195B26473ACFAF49F0392662A180346AFEA5BFA6D09DD95D748A6B9F",
"old_active_pol_name": "dwipe",
"old_active_pol_version": "1.0.0",
"old_policy_digest": "sha256:1CEE14128A111BD8D0A157CFE6025AB6119DF0589039DA709A949286ABBC6CA5",
"res": "1",
"ses": "27"
},
"raw": [
"node=JD-debian-12-workstation type=UNKNOWN[1421] msg=audit(1781728753.955:612192): old_active_pol_name=\"dwipe\" old_active_pol_version=1.0.0 old_policy_digest=sha256:1CEE14128A111BD8D0A157CFE6025AB6119DF0589039DA709A949286ABBC6CA5 new_active_pol_name=\"dwipe2\" new_active_pol_version=1.0.0 new_policy_digest=sha256:51304269195B26473ACFAF49F0392662A180346AFEA5BFA6D09DD95D748A6B9F auid=1000 ses=27 lsm=ipe res=1",
"AUID=\"debian\""
],
"record_type": "IPE_CONFIG_CHANGE"
}
References #
IPE_POLICY_LOAD msgtype 1422
#Description
IPE policy load
Fields #
| Name | Description |
|---|---|
policy_name | IPE policy name |
policy_version | IPE policy version |
policy_digest | IPE policy content digest |
auid | login user ID |
ses | login session ID |
lsm | security module that produced the record (selinux, apparmor, ...) |
res | result of the audited operation(success/fail) |
errno | error code of the audited operation |
Example Audit Record #
{
"fields": {
"auid": "1000",
"errno": "0",
"lsm": "ipe",
"policy_digest": "sha256:51304269195B26473ACFAF49F0392662A180346AFEA5BFA6D09DD95D748A6B9F",
"policy_name": "dwipe2",
"policy_version": "1.0.0",
"res": "1",
"ses": "27"
},
"raw": [
"node=JD-debian-12-workstation type=UNKNOWN[1422] msg=audit(1781728753.951:612191): policy_name=\"dwipe2\" policy_version=1.0.0 policy_digest=sha256:51304269195B26473ACFAF49F0392662A180346AFEA5BFA6D09DD95D748A6B9F auid=1000 ses=27 lsm=ipe res=1 errno=0",
"AUID=\"debian\""
],
"record_type": "IPE_POLICY_LOAD"
}
References #
LANDLOCK_ACCESS msgtype 1423
#Description
Landlock access denial
Fields #
| Name | Description |
|---|---|
domain | Landlock domain identifier |
blockers | Landlock access rights that blocked the operation |
path | file system path name |
dev | device identifier |
ino | inode number |
Example Audit Record #
{
"fields": {
"blockers": "fs.read_file",
"dev": "vda1",
"domain": "1dd9c92db",
"ino": "11011796",
"path": "/etc/ld.so.cache"
},
"raw": [
"node=JD-debian-12-workstation type=UNKNOWN[1423] msg=audit(1781666556.057:244234): domain=1dd9c92db blockers=fs.read_file path=\"/etc/ld.so.cache\" dev=\"vda1\" ino=11011796",
"node=JD-debian-12-workstation type=UNKNOWN[1424] msg=audit(1781666556.057:244234): domain=1dd9c92db status=allocated mode=enforcing pid=6720 uid=1000 exe=\"/tmp/sb2\" comm=\"sb2\"",
"UID=\"debian\""
],
"record_type": "LANDLOCK_ACCESS"
}
References #
LANDLOCK_DOMAIN msgtype 1424
#Description
Landlock domain allocation or deallocation status
Fields #
| Name | Description |
|---|---|
domain | Landlock domain identifier |
status | Landlock domain status (allocated or deallocated) |
mode | Landlock domain enforcement mode (enforcing) |
pid | process ID |
uid | user ID |
exe | executable name |
comm | command line program name |
denials | count of Landlock denials attributed to the domain |
Example Audit Record #
{
"fields": {
"denials": "2",
"domain": "1dd9c92e9",
"status": "deallocated"
},
"raw": [
"node=JD-debian-12-workstation type=UNKNOWN[1424] msg=audit(1781666597.958:244302): domain=1dd9c92e9 status=deallocated denials=2"
],
"record_type": "LANDLOCK_DOMAIN"
}
References #
MAC_TASK_CONTEXTS msgtype 1425
#Description
Subject security contexts when multiple LSMs are active
References #
MAC_OBJ_CONTEXTS msgtype 1426
#Description
Object security contexts when multiple LSMs are active
References #
APPARMOR msgtype 1500
#Description
AppArmor LSM audit event
APPARMOR_AUDIT msgtype 1501
#Description
AppArmor access decision logged in audit mode
APPARMOR_ALLOWED msgtype 1502
#Description
AppArmor access allowed (complain or learning mode)
APPARMOR_DENIED msgtype 1503
#Description
AppArmor access denied in enforce mode
APPARMOR_HINT msgtype 1504
#Description
AppArmor reserved audit type (unused in the current kernel)
APPARMOR_STATUS msgtype 1505
#Description
AppArmor policy load or status change
APPARMOR_ERROR msgtype 1506
#Description
AppArmor internal error
APPARMOR_KILL msgtype 1507
#Description
AppArmor access denied with task kill
ANOM_PROMISCUOUS msgtype 1700
#Description
Device changed promiscuous mode
Fields #
| Name | Description |
|---|---|
dev | Network device name |
prom | Promiscuous mode state (256 for on, 0 for off) |
old_prom | Previous promiscuous mode state |
auid | Audit user ID (login UID) |
uid | User ID |
gid | Group ID |
ses | Session ID |
Example Audit Record #
{
"fields": {
"auid": "4294967295",
"dev": "vethe2919bc",
"gid": "0",
"old_prom": "0",
"prom": "256",
"ses": "4294967295",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=ANOM_PROMISCUOUS msg=audit(1781634257.762:512597): dev=vethe2919bc prom=256 old_prom=0 auid=4294967295 uid=0 gid=0 ses=4294967295",
"AUID=\"unset\" UID=\"root\" GID=\"root\"",
"node=JD-debian-12-workstation type=SYSCALL msg=audit(1781634257.762:512597): arch=c000003e syscall=44 success=yes exit=40 a0=f a1=2442de196c00 a2=28 a3=0 items=0 ppid=1 pid=671 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=\"dockerd\" exe=\"/usr/bin/dockerd\" subj=system_u:system_r:initrc_t:s0 key=\"T1071_data_transfer\"",
"ARCH=x86_64 SYSCALL=sendto AUID=\"unset\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
"node=JD-debian-12-workstation type=SOCKADDR msg=audit(1781634257.762:512597): saddr=100000000000000000000000",
"SADDR={ saddr_fam=netlink nlnk-fam=16 nlnk-pid=0 }",
"node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781634257.762:512597): proctitle=2F7573722F62696E2F646F636B657264002D480066643A2F2F002D2D636F6E7461696E6572643D2F72756E2F636F6E7461696E6572642F636F6E7461696E6572642E736F636B"
],
"record_type": "ANOM_PROMISCUOUS"
}
References #
ANOM_ABEND msgtype 1701
#Description
Process ended abnormally
Fields #
| Name | Description |
|---|---|
auid | login user ID |
uid | user ID |
gid | group ID |
ses | login session ID |
subj | lspp subject's context string |
pid | process ID |
comm | command line program name |
exe | executable name |
sig | signal number |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"auid": "1000",
"comm": "python3",
"exe": "/usr/bin/python3.11",
"gid": "0",
"pid": "2916",
"res": "1",
"ses": "1",
"sig": "6",
"subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=ANOM_ABEND msg=audit(1781634272.640:540321): auid=1000 uid=0 gid=0 ses=1 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 pid=2916 comm=\"python3\" exe=\"/usr/bin/python3.11\" sig=6 res=1",
"AUID=\"debian\" UID=\"root\" GID=\"root\""
],
"record_type": "ANOM_ABEND"
}
References #
ANOM_LINK msgtype 1702
#Description
Suspicious use of file links
Fields #
| Name | Description |
|---|---|
op | the operation being performed that is audited |
ppid | parent process ID |
pid | process ID |
auid | login user ID |
uid | user ID |
gid | group ID |
euid | effective user ID |
suid | sent user ID |
fsuid | file system user ID |
egid | effective group ID |
sgid | set group ID |
fsgid | file system group ID |
tty | tty udevice the user is running programs on |
ses | login session ID |
comm | command line program name |
exe | executable name |
subj | lspp subject's context string |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"auid": "1000",
"comm": "python3",
"egid": "65534",
"euid": "65534",
"exe": "/usr/bin/python3.11",
"fsgid": "65534",
"fsuid": "65534",
"gid": "65534",
"op": "linkat",
"pid": "2923",
"ppid": "2922",
"res": "0",
"ses": "1",
"sgid": "65534",
"subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
"suid": "65534",
"tty": "(none)",
"uid": "65534"
},
"raw": [
"node=JD-debian-12-workstation type=ANOM_LINK msg=audit(1781634272.680:540622): op=linkat ppid=2922 pid=2923 auid=1000 uid=65534 gid=65534 euid=65534 suid=65534 fsuid=65534 egid=65534 sgid=65534 fsgid=65534 tty=(none) ses=1 comm=\"python3\" exe=\"/usr/bin/python3.11\" subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 res=0",
"AUID=\"debian\" UID=\"nobody\" GID=\"nogroup\" EUID=\"nobody\" SUID=\"nobody\" FSUID=\"nobody\" EGID=\"nogroup\" SGID=\"nogroup\" FSGID=\"nogroup\"",
"node=JD-debian-12-workstation type=SYSCALL msg=audit(1781634272.680:540622): arch=c000003e syscall=86 success=no exit=-1 a0=7fd459e6e570 a1=7fd459e6e540 a2=0 a3=7fd459e9ba18 items=2 ppid=2922 pid=2923 auid=1000 uid=65534 gid=65534 euid=65534 suid=65534 fsuid=65534 egid=65534 sgid=65534 fsgid=65534 tty=(none) ses=1 comm=\"python3\" exe=\"/usr/bin/python3.11\" subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key=\"T1136_identity_file\"",
"ARCH=x86_64 SYSCALL=link AUID=\"debian\" UID=\"nobody\" GID=\"nogroup\" EUID=\"nobody\" SUID=\"nobody\" FSUID=\"nobody\" EGID=\"nogroup\" SGID=\"nogroup\" FSGID=\"nogroup\"",
"node=JD-debian-12-workstation type=CWD msg=audit(1781634272.680:540622): cwd=\"/home/debian\"",
"node=JD-debian-12-workstation type=PATH msg=audit(1781634272.680:540622): item=0 name=\"/tmp/\" inode=1835009 dev=fe:01 mode=041777 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:tmp_t:s0 nametype=PARENT cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
"OUID=\"root\" OGID=\"root\"",
"node=JD-debian-12-workstation type=PATH msg=audit(1781634272.680:540622): item=1 name=\"/etc/passwd\" inode=11011764 dev=fe:01 mode=0100644 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:etc_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
"OUID=\"root\" OGID=\"root\"",
"node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781634272.680:540622): proctitle=7375646F002D75006E6F626F647900707974686F6E33002D6300696D706F7274206F730A7472793A206F732E6C696E6B28272F6574632F706173737764272C272F746D702F72336C696E6B27290A657863657074204F534572726F723A2070617373"
],
"record_type": "ANOM_LINK"
}
References #
ANOM_CREAT msgtype 1703
#Description
Suspicious file creation
Fields #
| Name | Description |
|---|---|
op | the operation being performed that is audited |
ppid | parent process ID |
pid | process ID |
auid | login user ID |
uid | user ID |
gid | group ID |
euid | effective user ID |
suid | sent user ID |
fsuid | file system user ID |
egid | effective group ID |
sgid | set group ID |
fsgid | file system group ID |
tty | tty udevice the user is running programs on |
ses | login session ID |
comm | command line program name |
exe | executable name |
subj | lspp subject's context string |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"auid": "1000",
"comm": "bash",
"egid": "65534",
"euid": "65534",
"exe": "/usr/bin/bash",
"fsgid": "65534",
"fsuid": "65534",
"gid": "65534",
"op": "sticky_create",
"pid": "84413",
"ppid": "84412",
"res": "0",
"ses": "49",
"sgid": "65534",
"subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
"suid": "65534",
"tty": "(none)",
"uid": "65534"
},
"raw": [
"node=JD-debian-12-workstation type=ANOM_CREAT msg=audit(1781674283.166:244935): op=sticky_create ppid=84412 pid=84413 auid=1000 uid=65534 gid=65534 euid=65534 suid=65534 fsuid=65534 egid=65534 sgid=65534 fsgid=65534 tty=(none) ses=49 comm=\"bash\" exe=\"/usr/bin/bash\" subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 res=0",
"AUID=\"debian\" UID=\"nobody\" GID=\"nogroup\" EUID=\"nobody\" SUID=\"nobody\" FSUID=\"nobody\" EGID=\"nogroup\" SGID=\"nogroup\" FSGID=\"nogroup\"",
"node=JD-debian-12-workstation type=SYSCALL msg=audit(1781674283.166:244935): arch=c000003e syscall=257 success=no exit=-13 a0=ffffff9c a1=634277626d20 a2=241 a3=1b6 items=1 ppid=84412 pid=84413 auid=1000 uid=65534 gid=65534 euid=65534 suid=65534 fsuid=65534 egid=65534 sgid=65534 fsgid=65534 tty=(none) ses=49 comm=\"bash\" exe=\"/usr/bin/bash\" subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key=\"anomcreat\"",
"ARCH=x86_64 SYSCALL=openat AUID=\"debian\" UID=\"nobody\" GID=\"nogroup\" EUID=\"nobody\" SUID=\"nobody\" FSUID=\"nobody\" EGID=\"nogroup\" SGID=\"nogroup\" FSGID=\"nogroup\"",
"node=JD-debian-12-workstation type=CWD msg=audit(1781674283.166:244935): cwd=\"/home/debian\"",
"node=JD-debian-12-workstation type=PATH msg=audit(1781674283.166:244935): item=0 name=\"/tmp/stickytest/victim\" inode=4757372 dev=fd:01 mode=0100666 ouid=1 ogid=1 rdev=00:00 obj=unconfined_u:object_r:user_tmp_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
"OUID=\"daemon\" OGID=\"daemon\"",
"node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781674283.166:244935): proctitle=62617368002D63006563686F20686178203E202F746D702F737469636B79746573742F76696374696D"
],
"record_type": "ANOM_CREAT"
}
References #
INTEGRITY_DATA msgtype 1800
#Description
Data integrity verification
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
cause | reason the integrity operation produced this result |
comm | command line program name |
name | file name in avcs |
dev | device identifier |
ino | inode number |
res | result of the audited operation(success/fail) |
errno | error code of the audited operation |
Example Audit Record #
{
"fields": {
"auid": "4294967295",
"cause": "missing-hash",
"comm": "erts_dios_2",
"dev": "overlay",
"errno": "0",
"ino": "3816158",
"name": "/opt/erlang/lib/erlang/lib/kernel-9.2.4.10/ebin/inet6_tcp.beam",
"op": "appraise_data",
"pid": "1464",
"res": "0",
"ses": "4294967295",
"subj": "system_u:system_r:initrc_t:s0",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=INTEGRITY_DATA msg=audit(1781635478.877:552310): pid=1464 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:initrc_t:s0 op=appraise_data cause=missing-hash comm=\"erts_dios_2\" name=\"/opt/erlang/lib/erlang/lib/kernel-9.2.4.10/ebin/inet6_tcp.beam\" dev=\"overlay\" ino=3816158 res=0 errno=0",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "INTEGRITY_DATA"
}
INTEGRITY_METADATA msgtype 1801
#Description
Metadata integrity verification
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
cause | reason the integrity operation produced this result |
comm | command line program name |
name | file name in avcs |
dev | device identifier |
ino | inode number |
res | result of the audited operation(success/fail) |
errno | error code of the audited operation |
Example Audit Record #
{
"fields": {
"auid": "4294967295",
"cause": "no_label",
"comm": "dockerd",
"dev": "vda1",
"errno": "0",
"ino": "4756199",
"name": "hostname",
"op": "appraise_metadata",
"pid": "737",
"res": "0",
"ses": "4294967295",
"subj": "system_u:system_r:initrc_t:s0",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=INTEGRITY_METADATA msg=audit(1781644799.132:3070202): pid=737 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:initrc_t:s0 op=appraise_metadata cause=no_label comm=\"dockerd\" name=\"hostname\" dev=\"vda1\" ino=4756199 res=0 errno=0",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "INTEGRITY_METADATA"
}
References #
INTEGRITY_STATUS msgtype 1802
#Description
Integrity enable status
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
cause | reason the integrity operation produced this result |
comm | command line program name |
res | result of the audited operation(success/fail) |
errno | error code of the audited operation |
Example Audit Record #
{
"fields": {
"auid": "1000",
"cause": "completed",
"comm": "tee",
"errno": "0",
"op": "policy_update",
"pid": "76552",
"res": "1",
"ses": "15",
"subj": "unconfined",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=INTEGRITY_STATUS msg=audit(1781633139.102:2169048): pid=76552 uid=0 auid=1000 ses=15 subj=unconfined op=policy_update cause=completed comm=\"tee\" res=1 errno=0",
"UID=\"root\" AUID=\"debian\""
],
"record_type": "INTEGRITY_STATUS"
}
INTEGRITY_HASH msgtype 1803
#Description
Integrity HASH type
INTEGRITY_PCR msgtype 1804
#Description
PCR (Platform Configuration Register) invalidation messages
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
cause | reason the integrity operation produced this result |
comm | command line program name |
name | file name in avcs |
dev | device identifier |
ino | inode number |
res | result of the audited operation(success/fail) |
errno | error code of the audited operation |
Example Audit Record #
{
"fields": {
"auid": "4294967295",
"cause": "open_writers",
"comm": "journalctl",
"dev": "vda1",
"errno": "0",
"ino": "2887054",
"name": "/var/log/journal/370e939bc3344c2e8efe8cb82c4bc43a/system.journal",
"op": "invalid_pcr",
"pid": "744",
"res": "1",
"ses": "4294967295",
"subj": "system_u:system_r:initrc_t:s0",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=INTEGRITY_PCR msg=audit(1781635957.029:400312): pid=744 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:initrc_t:s0 op=invalid_pcr cause=open_writers comm=\"journalctl\" name=\"/var/log/journal/370e939bc3344c2e8efe8cb82c4bc43a/system.journal\" dev=\"vda1\" ino=2887054 res=1 errno=0",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "INTEGRITY_PCR"
}
INTEGRITY_RULE msgtype 1805
#Description
Integrity Policy action
Fields #
| Name | Description |
|---|---|
file | file name |
hash | hash of the measured file (from an IMA policy rule with the audit action) |
ppid | parent process ID |
pid | process ID |
auid | login user ID |
uid | user ID |
gid | group ID |
euid | effective user ID |
suid | sent user ID |
fsuid | file system user ID |
egid | effective group ID |
sgid | set group ID |
fsgid | file system group ID |
tty | tty udevice the user is running programs on |
ses | login session ID |
comm | command line program name |
exe | executable name |
subj | lspp subject's context string |
Example Audit Record #
{
"fields": {
"auid": "4294967295",
"comm": "sh",
"egid": "0",
"euid": "0",
"exe": "/bin/busybox",
"file": "/health_check.sh",
"fsgid": "0",
"fsuid": "0",
"gid": "0",
"hash": "sha256:38744345348ee83905d0f018826d9baa84704d55c3ed1babe13c62e32064be3a",
"pid": "76553",
"ppid": "76539",
"ses": "4294967295",
"sgid": "0",
"subj": "unconfined",
"suid": "0",
"tty": "(none)",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=INTEGRITY_RULE msg=audit(1781633139.126:2169049): file=\"/health_check.sh\" hash=\"sha256:38744345348ee83905d0f018826d9baa84704d55c3ed1babe13c62e32064be3a\" ppid=76539 pid=76553 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=\"sh\" exe=\"/bin/busybox\" subj=unconfined",
"AUID=\"unset\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\""
],
"record_type": "INTEGRITY_RULE"
}
References #
INTEGRITY_EVM_XATTR msgtype 1806
#Description
EVM XATTRS modifications
Fields #
| Name | Description |
|---|---|
xattr | extended attribute name involved in the EVM operation |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"res": "0",
"xattr": "security.detectionwiki"
},
"raw": [
"node=JD-debian-12-workstation type=INTEGRITY_EVM_XATTR msg=audit(1781674118.342:244839): xattr=\"security.detectionwiki\" res=0"
],
"record_type": "INTEGRITY_EVM_XATTR"
}
References #
INTEGRITY_POLICY_RULE msgtype 1807
#Description
Integrity Policy rule
Fields #
| Name | Description |
|---|---|
action | policy action taken (for example ALLOW or DENY) |
res | result of the audited operation(success/fail) |
func | IMA policy hook the rule applies to |
mask | IMA policy permission mask the rule matches |
Example Audit Record #
{
"fields": {
"action": "measure",
"func": "BPRM_CHECK",
"res": "1"
},
"raw": [
"node=JD-debian-12-workstation type=INTEGRITY_POLICY_RULE msg=audit(1781633139.102:2169045): action=measure func=BPRM_CHECK res=1"
],
"record_type": "INTEGRITY_POLICY_RULE"
}
References #
INTEGRITY_USERSPACE msgtype 1808
#Description
IMA appraisal of userspace-supplied data
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
cause | reason the integrity operation produced this result |
comm | command line program name |
name | file name in avcs |
dev | device identifier |
ino | inode number |
res | result of the audited operation(success/fail) |
errno | error code of the audited operation |
Example Audit Record #
{
"fields": {
"auid": "1000",
"cause": "missing-hash",
"comm": "dwtrigger",
"dev": "vda1",
"errno": "0",
"ino": "2887116",
"name": "/var/tmp/dwexec",
"op": "appraise_data",
"pid": "100540",
"res": "0",
"ses": "72",
"subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=UNKNOWN[1808] msg=audit(1781719000.505:245392): pid=100540 uid=0 auid=1000 ses=72 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 op=appraise_data cause=missing-hash comm=\"dwtrigger\" name=\"/var/tmp/dwexec\" dev=\"vda1\" ino=2887116 res=0 errno=0",
"UID=\"root\" AUID=\"debian\"",
"node=JD-debian-12-workstation type=SYSCALL msg=audit(1781719000.505:245392): arch=c000003e syscall=322 success=no exit=-13 a0=3 a1=612293e7800d a2=7ffee3d07a58 a3=7ffee3d07a50 items=1 ppid=100522 pid=100540 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=72 comm=\"dwtrigger\" exe=\"/var/tmp/dwtrigger\" subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key=\"integuser\"",
"ARCH=x86_64 SYSCALL=execveat AUID=\"debian\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
"node=JD-debian-12-workstation type=CWD msg=audit(1781719000.505:245392): cwd=\"/home/debian\"",
"node=JD-debian-12-workstation type=PATH msg=audit(1781719000.505:245392): item=0 name=\"\" inode=2887116 dev=fd:01 mode=0100755 ouid=9999 ogid=9999 rdev=00:00 obj=unconfined_u:object_r:user_tmp_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
"OUID=\"unknown(9999)\" OGID=\"unknown(9999)\"",
"node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781719000.505:245392): proctitle=2F7661722F746D702F647774726967676572002F7661722F746D702F647765786563"
],
"record_type": "INTEGRITY_USERSPACE"
}
References #
KERNEL msgtype 2000
#ANOM_LOGIN_FAILURES msgtype 2100
#Description
Failed login limit reached
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"acct": "catalog",
"addr": "?",
"auid": "4294967295",
"exe": "/usr/bin/python3.11",
"failures": "3",
"hostname": "?",
"op": "login",
"pid": "2324",
"res": "failed",
"ses": "4294967295",
"subj": "system_u:system_r:auditd_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=ANOM_LOGIN_FAILURES msg=audit(1781634271.619:539463): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_LOGIN_FAILURES op=login acct=\"catalog\" failures=3 res=failed exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "ANOM_LOGIN_FAILURES"
}
Example keys not documented in the fields table: acct, failures
ANOM_LOGIN_TIME msgtype 2101
#Description
Login attempted at bad time
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"acct": "catalog",
"addr": "?",
"auid": "4294967295",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"op": "login",
"pid": "2324",
"res": "failed",
"ses": "4294967295",
"subj": "system_u:system_r:auditd_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=ANOM_LOGIN_TIME msg=audit(1781634271.619:539470): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_LOGIN_TIME op=login acct=\"catalog\" res=failed exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "ANOM_LOGIN_TIME"
}
Example keys not documented in the fields table: acct
ANOM_LOGIN_SESSIONS msgtype 2102
#Description
Maximum concurrent sessions reached
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"acct": "catalog",
"addr": "?",
"auid": "4294967295",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"maxsessions": "1",
"op": "login",
"pid": "2324",
"res": "failed",
"ses": "4294967295",
"subj": "system_u:system_r:auditd_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=ANOM_LOGIN_SESSIONS msg=audit(1781634271.619:539477): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_LOGIN_SESSIONS op=login acct=\"catalog\" maxsessions=1 res=failed exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "ANOM_LOGIN_SESSIONS"
}
Example keys not documented in the fields table: acct, maxsessions
ANOM_LOGIN_ACCT msgtype 2103
#Description
Login attempted to watched account
Fields #
| Name | Description |
|---|---|
acct | a user's account name |
daddr | remote IP address |
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"acct": "catalog",
"addr": "?",
"auid": "4294967295",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"op": "login",
"pid": "2324",
"res": "failed",
"ses": "4294967295",
"subj": "system_u:system_r:auditd_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=ANOM_LOGIN_ACCT msg=audit(1781634271.619:539484): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_LOGIN_ACCT op=login acct=\"catalog\" res=failed exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "ANOM_LOGIN_ACCT"
}
ANOM_LOGIN_LOCATION msgtype 2104
#Description
Login from forbidden location
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"acct": "catalog",
"addr": "198.51.100.9",
"auid": "4294967295",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"op": "login",
"pid": "2324",
"res": "failed",
"ses": "4294967295",
"subj": "system_u:system_r:auditd_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=ANOM_LOGIN_LOCATION msg=audit(1781634271.619:539491): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_LOGIN_LOCATION op=login acct=\"catalog\" addr=198.51.100.9 res=failed exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "ANOM_LOGIN_LOCATION"
}
Example keys not documented in the fields table: acct
ANOM_MAX_DAC msgtype 2105
#Description
Max DAC (Discretionary Access Control) failures reached
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"acct": "catalog",
"addr": "?",
"auid": "4294967295",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"op": "dac-check",
"pid": "2324",
"res": "failed",
"ses": "4294967295",
"subj": "system_u:system_r:auditd_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=ANOM_MAX_DAC msg=audit(1781634271.619:539498): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_MAX_DAC op=dac-check acct=\"catalog\" res=failed exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "ANOM_MAX_DAC"
}
Example keys not documented in the fields table: acct
ANOM_MAX_MAC msgtype 2106
#Description
Max MAC (Mandatory Access Control) failures reached
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"acct": "catalog",
"addr": "?",
"auid": "4294967295",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"op": "mac-check",
"pid": "2324",
"res": "failed",
"ses": "4294967295",
"subj": "system_u:system_r:auditd_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=ANOM_MAX_MAC msg=audit(1781634271.619:539505): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_MAX_MAC op=mac-check acct=\"catalog\" res=failed exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "ANOM_MAX_MAC"
}
Example keys not documented in the fields table: acct
ANOM_AMTU_FAIL msgtype 2107
#Description
AMTU (Abstract Machine Test Utility) failure
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "4294967295",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"op": "amtu",
"pid": "2324",
"res": "failed",
"ses": "4294967295",
"subj": "system_u:system_r:auditd_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=ANOM_AMTU_FAIL msg=audit(1781634271.619:539512): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_AMTU_FAIL op=amtu res=failed exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "ANOM_AMTU_FAIL"
}
ANOM_RBAC_FAIL msgtype 2108
#Description
RBAC (Role-Based Access Control) self test failure
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "4294967295",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"op": "rbac-check",
"pid": "2324",
"res": "failed",
"ses": "4294967295",
"subj": "system_u:system_r:auditd_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=ANOM_RBAC_FAIL msg=audit(1781634271.619:539519): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_RBAC_FAIL op=rbac-check res=failed exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "ANOM_RBAC_FAIL"
}
ANOM_RBAC_INTEGRITY_FAIL msgtype 2109
#Description
RBAC (Role-Based Access Control) file integrity test failure
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "4294967295",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"op": "rbac-integrity",
"pid": "2324",
"res": "failed",
"ses": "4294967295",
"subj": "system_u:system_r:auditd_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=ANOM_RBAC_INTEGRITY_FAIL msg=audit(1781634271.619:539526): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_RBAC_INTEGRITY_FAIL op=rbac-integrity res=failed exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "ANOM_RBAC_INTEGRITY_FAIL"
}
ANOM_CRYPTO_FAIL msgtype 2110
#Description
Crypto system test failure
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "4294967295",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"op": "crypto",
"pid": "2324",
"res": "failed",
"ses": "4294967295",
"subj": "system_u:system_r:auditd_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=ANOM_CRYPTO_FAIL msg=audit(1781634271.619:539533): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_CRYPTO_FAIL op=crypto res=failed exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "ANOM_CRYPTO_FAIL"
}
ANOM_ACCESS_FS msgtype 2111
#Description
Access of file or directory ended abnormally
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "4294967295",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"op": "fs-access",
"path": "/etc/shadow",
"pid": "2324",
"res": "failed",
"ses": "4294967295",
"subj": "system_u:system_r:auditd_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=ANOM_ACCESS_FS msg=audit(1781634271.619:539540): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_ACCESS_FS op=fs-access path=\"/etc/shadow\" res=failed exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "ANOM_ACCESS_FS"
}
Example keys not documented in the fields table: path
ANOM_EXEC msgtype 2112
#Description
Execution of file ended abnormally
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "4294967295",
"cmd": "/tmp/suspicious",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"op": "exec",
"pid": "2324",
"res": "failed",
"ses": "4294967295",
"subj": "system_u:system_r:auditd_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=ANOM_EXEC msg=audit(1781634271.619:539547): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_EXEC op=exec cmd=\"/tmp/suspicious\" res=failed exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "ANOM_EXEC"
}
Example keys not documented in the fields table: cmd
ANOM_MK_EXEC msgtype 2113
#Description
Make an executable
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "4294967295",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"op": "mk-exec",
"path": "/tmp/x",
"pid": "2324",
"res": "failed",
"ses": "4294967295",
"subj": "system_u:system_r:auditd_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=ANOM_MK_EXEC msg=audit(1781634271.619:539554): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_MK_EXEC op=mk-exec path=\"/tmp/x\" res=failed exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "ANOM_MK_EXEC"
}
Example keys not documented in the fields table: path
ANOM_ADD_ACCT msgtype 2114
#Description
Adding a user account ended abnormally
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"acct": "catalog",
"addr": "?",
"auid": "4294967295",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"op": "add-acct",
"pid": "2324",
"res": "success",
"ses": "4294967295",
"subj": "system_u:system_r:auditd_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=ANOM_ADD_ACCT msg=audit(1781634271.619:539561): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_ADD_ACCT op=add-acct acct=\"catalog\" res=success exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "ANOM_ADD_ACCT"
}
Example keys not documented in the fields table: acct
ANOM_DEL_ACCT msgtype 2115
#Description
Deleting a user account ended abnormally
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"acct": "catalog",
"addr": "?",
"auid": "4294967295",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"op": "del-acct",
"pid": "2324",
"res": "success",
"ses": "4294967295",
"subj": "system_u:system_r:auditd_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=ANOM_DEL_ACCT msg=audit(1781634271.619:539568): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_DEL_ACCT op=del-acct acct=\"catalog\" res=success exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "ANOM_DEL_ACCT"
}
Example keys not documented in the fields table: acct
ANOM_MOD_ACCT msgtype 2116
#Description
Changing an account ended abnormally
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"acct": "catalog",
"addr": "?",
"auid": "4294967295",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"op": "mod-acct",
"pid": "2324",
"res": "success",
"ses": "4294967295",
"subj": "system_u:system_r:auditd_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=ANOM_MOD_ACCT msg=audit(1781634271.619:539575): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_MOD_ACCT op=mod-acct acct=\"catalog\" res=success exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "ANOM_MOD_ACCT"
}
Example keys not documented in the fields table: acct
ANOM_ROOT_TRANS msgtype 2117
#Description
User became root
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"acct": "catalog",
"addr": "?",
"auid": "4294967295",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"op": "root-trans",
"pid": "2324",
"res": "success",
"ses": "4294967295",
"subj": "system_u:system_r:auditd_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=ANOM_ROOT_TRANS msg=audit(1781634271.619:539582): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_ROOT_TRANS op=root-trans acct=\"catalog\" res=success exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "ANOM_ROOT_TRANS"
}
Example keys not documented in the fields table: acct
ANOM_LOGIN_SERVICE msgtype 2118
#Description
Service acct attempted login
Fields #
| Name | Description |
|---|---|
acct | a user's account name |
daddr | remote IP address |
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "4294967295",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"op": "login",
"pid": "2324",
"res": "failed",
"ses": "4294967295",
"subj": "system_u:system_r:auditd_t:s0",
"svc": "sshd",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=ANOM_LOGIN_SERVICE msg=audit(1781634271.619:539589): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_LOGIN_SERVICE op=login svc=sshd res=failed exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "ANOM_LOGIN_SERVICE"
}
Example keys not documented in the fields table: svc
ANOM_LOGIN_ROOT msgtype 2119
#Description
Root login attempted
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"acct": "root",
"addr": "?",
"auid": "4294967295",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"op": "login",
"pid": "2324",
"res": "failed",
"ses": "4294967295",
"subj": "system_u:system_r:auditd_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=ANOM_LOGIN_ROOT msg=audit(1781634271.619:539596): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_LOGIN_ROOT op=login acct=\"root\" res=failed exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "ANOM_LOGIN_ROOT"
}
Example keys not documented in the fields table: acct
ANOM_ORIGIN_FAILURES msgtype 2120
#Description
Origin has too many failed login attempts
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "198.51.100.9",
"auid": "4294967295",
"exe": "/usr/bin/python3.11",
"failures": "5",
"hostname": "?",
"op": "origin",
"pid": "2324",
"res": "failed",
"ses": "4294967295",
"subj": "system_u:system_r:auditd_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=ANOM_ORIGIN_FAILURES msg=audit(1781634271.619:539603): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_ORIGIN_FAILURES op=origin addr=198.51.100.9 failures=5 res=failed exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "ANOM_ORIGIN_FAILURES"
}
Example keys not documented in the fields table: failures
ANOM_SESSION msgtype 2121
#Description
The user session is bad
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"acct": "catalog",
"addr": "?",
"auid": "4294967295",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"op": "session",
"pid": "2324",
"res": "failed",
"ses": "4294967295",
"subj": "system_u:system_r:auditd_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=ANOM_SESSION msg=audit(1781634271.619:539610): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_SESSION op=session acct=\"catalog\" res=failed exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "ANOM_SESSION"
}
Example keys not documented in the fields table: acct
RESP_ANOMALY msgtype 2200
#Description
Anomaly not reacted to
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "4294967295",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"op": "anomaly-detected",
"pid": "2324",
"res": "success",
"ses": "4294967295",
"subj": "system_u:system_r:auditd_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=RESP_ANOMALY msg=audit(1781634272.652:540389): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='RESP_ANOMALY op=anomaly-detected res=success exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "RESP_ANOMALY"
}
RESP_ALERT msgtype 2201
#Description
Alert notification action (email or log): the email/log reactions are unimplemented FIXME stubs in upstream audisp-ids 3.x (reactions.c:370-372); emittable by custom plugins
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "4294967295",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"op": "alert",
"pid": "2324",
"res": "success",
"ses": "4294967295",
"subj": "system_u:system_r:auditd_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=RESP_ALERT msg=audit(1781634272.676:540608): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='RESP_ALERT op=alert res=success exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "RESP_ALERT"
}
RESP_KILL_PROC msgtype 2202
#Description
Kill program
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "4294967295",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"op": "kill-process",
"pid": "2324",
"res": "success",
"ses": "4294967295",
"subj": "system_u:system_r:auditd_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=RESP_KILL_PROC msg=audit(1781634272.652:540397): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='RESP_KILL_PROC op=kill-process pid=12345 res=success exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "RESP_KILL_PROC"
}
RESP_TERM_ACCESS msgtype 2203
#Description
Terminate session
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "4294967295",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"op": "terminate-session",
"pid": "2324",
"res": "success",
"ses": "4294967295",
"subj": "system_u:system_r:auditd_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=RESP_TERM_ACCESS msg=audit(1781634272.716:540658): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='RESP_TERM_ACCESS op=terminate-session res=success exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "RESP_TERM_ACCESS"
}
RESP_ACCT_REMOTE msgtype 2204
#Description
User account locked from remote access
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"acct": "catalog",
"addr": "?",
"auid": "4294967295",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"op": "lock-acct-remote",
"pid": "2324",
"res": "success",
"ses": "4294967295",
"subj": "system_u:system_r:auditd_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=RESP_ACCT_REMOTE msg=audit(1781634271.623:539645): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='RESP_ACCT_REMOTE op=lock-acct-remote acct=\"catalog\" res=success exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "RESP_ACCT_REMOTE"
}
Example keys not documented in the fields table: acct
RESP_ACCT_LOCK_TIMED msgtype 2205
#Description
User account locked for time
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"acct": "catalog",
"addr": "?",
"auid": "4294967295",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"op": "lock-acct-timed",
"pid": "2324",
"res": "success",
"ses": "4294967295",
"subj": "system_u:system_r:auditd_t:s0",
"terminal": "?",
"timeout": "600",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=RESP_ACCT_LOCK_TIMED msg=audit(1781634271.623:539652): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='RESP_ACCT_LOCK_TIMED op=lock-acct-timed acct=\"catalog\" timeout=600 res=success exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "RESP_ACCT_LOCK_TIMED"
}
Example keys not documented in the fields table: acct, timeout
RESP_ACCT_UNLOCK_TIMED msgtype 2206
#Description
User account unlocked from time
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"acct": "catalog",
"addr": "?",
"auid": "4294967295",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"op": "unlock-acct-timed",
"pid": "2324",
"res": "success",
"ses": "4294967295",
"subj": "system_u:system_r:auditd_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=RESP_ACCT_UNLOCK_TIMED msg=audit(1781634271.623:539659): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='RESP_ACCT_UNLOCK_TIMED op=unlock-acct-timed acct=\"catalog\" res=success exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "RESP_ACCT_UNLOCK_TIMED"
}
Example keys not documented in the fields table: acct
RESP_ACCT_LOCK msgtype 2207
#Description
User account was locked
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"acct": "catalog",
"addr": "?",
"auid": "4294967295",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"op": "lock-acct",
"pid": "2324",
"res": "success",
"ses": "4294967295",
"subj": "system_u:system_r:auditd_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=RESP_ACCT_LOCK msg=audit(1781634271.623:539667): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='RESP_ACCT_LOCK op=lock-acct acct=\"catalog\" res=success exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "RESP_ACCT_LOCK"
}
Example keys not documented in the fields table: acct
RESP_TERM_LOCK msgtype 2208
#Description
Terminal was locked
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "4294967295",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"op": "lock-session",
"pid": "2324",
"res": "success",
"ses": "4294967295",
"subj": "system_u:system_r:auditd_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=RESP_TERM_LOCK msg=audit(1781634271.623:539674): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='RESP_TERM_LOCK op=lock-session res=success exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "RESP_TERM_LOCK"
}
RESP_SEBOOL msgtype 2209
#Description
Set an SELinux boolean
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "4294967295",
"bool": "httpd_enable_homedirs",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"op": "set-sebool",
"pid": "2324",
"res": "success",
"ses": "4294967295",
"subj": "system_u:system_r:auditd_t:s0",
"terminal": "?",
"uid": "0",
"val": "0"
},
"raw": [
"node=JD-debian-12-workstation type=RESP_SEBOOL msg=audit(1781634271.623:539681): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='RESP_SEBOOL op=set-sebool bool=httpd_enable_homedirs val=0 res=success exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "RESP_SEBOOL"
}
Example keys not documented in the fields table: bool, val
RESP_EXEC msgtype 2210
#Description
Execute a script
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "4294967295",
"cmd": "/usr/local/sbin/respond",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"op": "exec-response",
"pid": "2324",
"res": "success",
"ses": "4294967295",
"subj": "system_u:system_r:auditd_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=RESP_EXEC msg=audit(1781634271.623:539688): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='RESP_EXEC op=exec-response cmd=\"/usr/local/sbin/respond\" res=success exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "RESP_EXEC"
}
Example keys not documented in the fields table: cmd
RESP_SINGLE msgtype 2211
#Description
Go to single user mode
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "4294967295",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"op": "single-user-mode",
"pid": "2324",
"res": "success",
"ses": "4294967295",
"subj": "system_u:system_r:auditd_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=RESP_SINGLE msg=audit(1781634271.623:539695): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='RESP_SINGLE op=single-user-mode res=success exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "RESP_SINGLE"
}
RESP_HALT msgtype 2212
#Description
Take the system down
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "4294967295",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"op": "halt",
"pid": "2324",
"res": "success",
"ses": "4294967295",
"subj": "system_u:system_r:auditd_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=RESP_HALT msg=audit(1781634271.623:539702): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='RESP_HALT op=halt res=success exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "RESP_HALT"
}
RESP_ORIGIN_BLOCK msgtype 2213
#Description
Remote address blocked by firewall rule (iptables or nftables depending on system configuration)
Fields #
| Name | Description |
|---|---|
daddr | remote IP address |
reason | reason for the operation |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
Example Audit Record #
{
"fields": {
"addr": "198.51.100.9",
"auid": "4294967295",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"op": "block-origin",
"pid": "2324",
"res": "success",
"ses": "4294967295",
"subj": "system_u:system_r:auditd_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=RESP_ORIGIN_BLOCK msg=audit(1781634272.676:540615): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='RESP_ORIGIN_BLOCK op=block-origin addr=198.51.100.9 res=success exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "RESP_ORIGIN_BLOCK"
}
RESP_ORIGIN_BLOCK_TIMED msgtype 2214
#Description
Address blocked for time
Fields #
| Name | Description |
|---|---|
daddr | remote IP address |
reason | reason for the operation |
time_out | block timeout in minutes for the timed response |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
Example Audit Record #
{
"fields": {
"addr": "198.51.100.9",
"auid": "4294967295",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"op": "block-origin-timed",
"pid": "2324",
"res": "success",
"ses": "4294967295",
"subj": "system_u:system_r:auditd_t:s0",
"terminal": "?",
"timeout": "600",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=RESP_ORIGIN_BLOCK_TIMED msg=audit(1781634271.627:539743): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='RESP_ORIGIN_BLOCK_TIMED op=block-origin-timed addr=198.51.100.9 timeout=600 res=success exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "RESP_ORIGIN_BLOCK_TIMED"
}
Example keys not documented in the fields table: timeout
RESP_ORIGIN_UNBLOCK_TIMED msgtype 2215
#Description
Address unblocked from timed
Fields #
| Name | Description |
|---|---|
daddr | remote IP address |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
Example Audit Record #
{
"fields": {
"addr": "198.51.100.9",
"auid": "4294967295",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"op": "unblock-origin-timed",
"pid": "2324",
"res": "success",
"ses": "4294967295",
"subj": "system_u:system_r:auditd_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=RESP_ORIGIN_UNBLOCK_TIMED msg=audit(1781634271.627:539750): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='RESP_ORIGIN_UNBLOCK_TIMED op=unblock-origin-timed addr=198.51.100.9 res=success exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "RESP_ORIGIN_UNBLOCK_TIMED"
}
USER_ROLE_CHANGE msgtype 2300
#Description
User changed to a new SELinux role
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
default-context | SELinux context offered as the default at login |
selected-context | SELinux context the user selected at login |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "10.2.20.61",
"auid": "1000",
"default-context": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
"exe": "/usr/sbin/sshd",
"hostname": "10.2.20.61",
"pid": "996",
"res": "success",
"selected-context": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
"ses": "1",
"subj": "system_u:system_r:sshd_t:s0",
"terminal": "ssh",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=USER_ROLE_CHANGE msg=audit(1781634177.960:186480): pid=996 uid=0 auid=1000 ses=1 subj=system_u:system_r:sshd_t:s0 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe=\"/usr/sbin/sshd\" hostname=10.2.20.61 addr=10.2.20.61 terminal=ssh res=success'",
"UID=\"root\" AUID=\"debian\""
],
"record_type": "USER_ROLE_CHANGE"
}
ROLE_ASSIGN msgtype 2301
#Description
Administrator assigned user to SELinux role
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
acct | a user's account name |
old-seuser | SELinux user before the role change |
old-role | SELinux role before the role change |
old-range | SELinux MLS range before the role change |
new-seuser | SELinux user after the role change |
new-role | SELinux role after the role change |
new-range | SELinux MLS range after the role change |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"acct": "r3usr",
"addr": "?",
"auid": "1000",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"new-range": "s0",
"new-role": "user_r",
"new-seuser": "user_u",
"old-range": "?",
"old-role": "?",
"old-seuser": "?",
"op": "login-sename,role,range",
"pid": "2819",
"res": "success",
"ses": "1",
"subj": "unconfined_u:unconfined_r:semanage_t:s0-s0:c0.c1023",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=ROLE_ASSIGN msg=audit(1781634269.359:532608): pid=2819 uid=0 auid=1000 ses=1 subj=unconfined_u:unconfined_r:semanage_t:s0-s0:c0.c1023 msg='op=login-sename,role,range acct=\"r3usr\" old-seuser=? old-role=? old-range=? new-seuser=user_u new-role=user_r new-range=s0 exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"debian\""
],
"record_type": "ROLE_ASSIGN"
}
ROLE_REMOVE msgtype 2302
#Description
Administrator removed user from SELinux role
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
acct | a user's account name |
old-seuser | SELinux user before the role change |
old-role | SELinux role before the role change |
old-range | SELinux MLS range before the role change |
new-seuser | SELinux user after the role change |
new-role | SELinux role after the role change |
new-range | SELinux MLS range after the role change |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"acct": "r3usr",
"addr": "?",
"auid": "1000",
"exe": "/usr/bin/python3.11",
"hostname": "?",
"new-range": "?",
"new-role": "?",
"new-seuser": "?",
"old-range": "s0",
"old-role": "user_r",
"old-seuser": "user_u",
"op": "login",
"pid": "2884",
"res": "success",
"ses": "1",
"subj": "unconfined_u:unconfined_r:semanage_t:s0-s0:c0.c1023",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=ROLE_REMOVE msg=audit(1781634270.619:537790): pid=2884 uid=0 auid=1000 ses=1 subj=unconfined_u:unconfined_r:semanage_t:s0-s0:c0.c1023 msg='op=login acct=\"r3usr\" old-seuser=user_u old-role=user_r old-range=s0 new-seuser=? new-role=? new-range=? exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"debian\""
],
"record_type": "ROLE_REMOVE"
}
LABEL_OVERRIDE msgtype 2303
#Description
Administrator is overriding a SELinux label
Fields #
| Name | Description |
|---|---|
pid | process ID (cupsd) |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | the subject's context string (the cupsd domain) |
job | the print job ID |
job-sheets | the banner (job-sheets) the user supplied (start,end) |
banners | the banner pages cupsd applied to the job (start,end) |
exe | executable name (cupsd) |
hostname | the hostname the request came from |
addr | the remote address the request came from |
terminal | terminal name |
res | result of the audited operation (success/failed) |
Example Audit Record #
{
"fields": {
"addr": "::1",
"auid": "4294967295",
"banners": "unclassified,unclassified",
"exe": "/usr/sbin/cupsd",
"hostname": "localhost.localdomain",
"job": "18",
"job-sheets": "unclassified,unclassified",
"pid": "5469",
"res": "failed",
"ses": "4294967295",
"subj": "system_u:system_r:cupsd_t:s15:c0.c1023",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=localhost type=LABEL_OVERRIDE msg=audit(1782745213.098:2375): pid=5469 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:cupsd_t:s15:c0.c1023 msg='job=18 user supplied job-sheets=unclassified,unclassified ignored banners=unclassified,unclassified exe=\"/usr/sbin/cupsd\" hostname=localhost.localdomain addr=::1 terminal=? res=failed'"
],
"record_type": "LABEL_OVERRIDE"
}
LABEL_LEVEL_CHANGE msgtype 2304
#Description
Object level SELinux label modified
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | the subject's context string (the cupsd domain) |
printer | the destination print queue |
uri | the device URI the queue prints to |
banners | the banner pages attached to the job (start,end) |
range | the MLS sensitivity range applied to the job |
exe | executable name (cupsd) |
hostname | the hostname the request came from |
addr | the remote address the request came from |
terminal | terminal name |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "::1",
"auid": "4294967295",
"banners": "none,none",
"exe": "/usr/sbin/cupsd",
"hostname": "localhost.localdomain",
"pid": "5124",
"printer": "dwfile",
"range": "unknown",
"res": "success",
"ses": "4294967295",
"subj": "system_u:system_r:cupsd_t:s15:c0.c1023",
"terminal": "?",
"uid": "0",
"uri": "file:/tmp/dwprint.out"
},
"raw": [
"node=localhost type=LABEL_LEVEL_CHANGE msg=audit(1782740116.657:1729): pid=5124 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:cupsd_t:s15:c0.c1023 msg='printer=dwfile uri=file:/tmp/dwprint.out banners=none,none range=unknown exe=\"/usr/sbin/cupsd\" hostname=localhost.localdomain addr=::1 terminal=? res=success'"
],
"record_type": "LABEL_LEVEL_CHANGE"
}
USER_LABELED_EXPORT msgtype 2305
#Description
Object exported with SELinux label
Fields #
| Name | Description |
|---|---|
pid | process ID (cupsd) |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | the subject's context string (the cupsd domain) |
job | the print job ID |
acct | the account that owns the job |
printer | the destination print queue |
title | the job title (source document name) |
obj | the SELinux context of the exported job |
label | the resolved classification label applied to the export |
exe | executable name (cupsd) |
hostname | the hostname the request came from |
addr | the remote address the request came from |
terminal | terminal name |
res | result of the audited operation (success/failed) |
Example Audit Record #
{
"fields": {
"acct": "root",
"addr": "::1",
"auid": "4294967295",
"exe": "/usr/sbin/cupsd",
"hostname": "localhost.localdomain",
"job": "18",
"label": "unclassified",
"obj": "sysadm_u:sysadm_r:lpr_t:s0-s15:c0.c1023",
"pid": "5469",
"printer": "dwk",
"res": "success",
"ses": "4294967295",
"subj": "system_u:system_r:cupsd_t:s15:c0.c1023",
"terminal": "?",
"title": "j.txt",
"uid": "0"
},
"raw": [
"node=localhost type=USER_LABELED_EXPORT msg=audit(1782745213.114:2377): pid=5469 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:cupsd_t:s15:c0.c1023 msg='job=18 auid=0 acct=root printer=dwk title=j.txt obj=sysadm_u:sysadm_r:lpr_t:s0-s15:c0.c1023 label=unclassified exe=\"/usr/sbin/cupsd\" hostname=localhost.localdomain addr=::1 terminal=? res=success'"
],
"record_type": "USER_LABELED_EXPORT"
}
USER_UNLABELED_EXPORT msgtype 2306
#Description
Object exported without SELinux label
DEV_ALLOC msgtype 2307
#Description
Device was allocated
DEV_DEALLOC msgtype 2308
#Description
Device was deallocated
FS_RELABEL msgtype 2309
#Description
Filesystem relabeled
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "1000",
"exe": "/usr/sbin/setfiles",
"hostname": "?",
"op": "mass relabel",
"pid": "54891",
"res": "success",
"ses": "4",
"subj": "unconfined_u:unconfined_r:setfiles_t:s0-s0:c0.c1023",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=FS_RELABEL msg=audit(1781641141.755:2056951): pid=54891 uid=0 auid=1000 ses=4 subj=unconfined_u:unconfined_r:setfiles_t:s0-s0:c0.c1023 msg='op=mass relabel exe=\"/usr/sbin/setfiles\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"debian\""
],
"record_type": "FS_RELABEL"
}
USER_MAC_POLICY_LOAD msgtype 2310
#Description
Userspace daemon loaded SELinux policy
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
lsm | security module that produced the record (selinux, apparmor, ...) |
seqno | sequence number |
res | result of the audited operation(success/fail) |
exe | executable name |
sauid | sent login user ID |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "4294967295",
"exe": "/usr/bin/dbus-daemon",
"hostname": "?",
"lsm": "selinux",
"op": "load_policy",
"pid": "504",
"res": "1",
"sauid": "100",
"seqno": "6",
"ses": "4294967295",
"subj": "system_u:system_r:system_dbusd_t:s0",
"terminal": "?",
"uid": "100"
},
"raw": [
"node=JD-debian-12-workstation type=USER_MAC_POLICY_LOAD msg=audit(1781634271.163:538052): pid=504 uid=100 auid=4294967295 ses=4294967295 subj=system_u:system_r:system_dbusd_t:s0 msg='avc: op=load_policy lsm=selinux seqno=6 res=1 exe=\"/usr/bin/dbus-daemon\" sauid=100 hostname=? addr=? terminal=?'",
"UID=\"messagebus\" AUID=\"unset\" SAUID=\"messagebus\""
],
"record_type": "USER_MAC_POLICY_LOAD"
}
ROLE_MODIFY msgtype 2311
#Description
Administrator modified an SELinux role
USER_MAC_CONFIG_CHANGE msgtype 2312
#Description
Change made to MAC (Mandatory Access Control) policy
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
resrc | resource the record applies to (disk, mem, net for VIRT; object type for MAC config changes) |
op | the operation being performed that is audited |
tglob | file-context glob pattern |
ftype | file type the context rule applies to |
tcontext | the target's or object's context string |
comm | command line program name |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "1000",
"comm": "semanage",
"exe": "/usr/bin/python3.11",
"ftype": "any",
"hostname": "?",
"op": "delete",
"pid": "57695",
"res": "success",
"resrc": "fcontext",
"ses": "4",
"subj": "unconfined_u:unconfined_r:semanage_t:s0-s0:c0.c1023",
"terminal": "?",
"tglob": "/catalogtest(/.*)?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=USER_MAC_CONFIG_CHANGE msg=audit(1781641148.319:2066513): pid=57695 uid=0 auid=1000 ses=4 subj=unconfined_u:unconfined_r:semanage_t:s0-s0:c0.c1023 msg='resrc=fcontext op=delete tglob=\"/catalogtest(/.*)?\" ftype=any comm=\"semanage\" exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"debian\""
],
"record_type": "USER_MAC_CONFIG_CHANGE"
}
USER_MAC_STATUS msgtype 2313
#Description
Userspace daemon enforcing change
Fields #
| Name | Description |
|---|---|
pid | process ID (dbus-broker) |
uid | user ID (the message bus user, typically dbus/81) |
auid | login user ID (unset for the bus daemon) |
ses | login session ID |
subj | the subject's context string (the dbus-broker domain) |
op | the operation that changed MAC status (setenforce) |
lsm | the Linux Security Module reporting the change (selinux) |
enforcing | the new enforcing state (1 enforcing, 0 permissive) |
res | result of the audited operation (1 success) |
exe | executable name (dbus-broker) |
sauid | the sender audit user ID |
hostname | the hostname the request came from |
addr | the remote address the request came from |
terminal | terminal name |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "4294967295",
"enforcing": "0",
"exe": "/usr/bin/dbus-broker",
"hostname": "?",
"lsm": "selinux",
"op": "setenforce",
"pid": "769",
"res": "1",
"sauid": "81",
"ses": "4294967295",
"subj": "system_u:system_r:system_dbusd_t:s0-s0:c0.c1023",
"terminal": "?",
"uid": "81"
},
"raw": [
"type=USER_MAC_STATUS msg=audit(1782743524.377:437): pid=769 uid=81 auid=4294967295 ses=4294967295 subj=system_u:system_r:system_dbusd_t:s0-s0:c0.c1023 msg='avc: op=setenforce lsm=selinux enforcing=0 res=1 exe=\"/usr/bin/dbus-broker\" sauid=81 hostname=? addr=? terminal=?'"
],
"record_type": "USER_MAC_STATUS"
}
CRYPTO_TEST_USER msgtype 2400
#Description
Cryptographic test results
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "1000",
"exe": "/usr/bin/certutil",
"hostname": "?",
"pid": "147033",
"res": "failed",
"ses": "156",
"subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=CRYPTO_TEST_USER msg=audit(1781742805.668:3014500): pid=147033 uid=0 auid=1000 ses=156 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='NSS libsoftokn3.so: C_Initialize()=0x00000030 power-up self-tests failed exe=\"/usr/bin/certutil\" hostname=? addr=? terminal=? res=failed'",
"UID=\"root\" AUID=\"debian\""
],
"record_type": "CRYPTO_TEST_USER"
}
CRYPTO_PARAM_CHANGE_USER msgtype 2401
#Description
Cryptographic attribute change
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "1000",
"exe": "/tmp/nss_fail",
"hostname": "?",
"pid": "146120",
"res": "success",
"ses": "150",
"subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=CRYPTO_PARAM_CHANGE_USER msg=audit(1781742719.774:2986384): pid=146120 uid=0 auid=1000 ses=150 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='NSS libsoftokn3.so: C_SetPIN(hSession=0x80000004)=0x00000000 exe=\"/tmp/nss_fail\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"debian\""
],
"record_type": "CRYPTO_PARAM_CHANGE_USER"
}
CRYPTO_LOGIN msgtype 2402
#Description
Cryptographic officer login
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "1000",
"exe": "/tmp/nss_fips",
"hostname": "?",
"pid": "143186",
"res": "success",
"ses": "141",
"subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=CRYPTO_LOGIN msg=audit(1781742444.164:2919469): pid=143186 uid=0 auid=1000 ses=141 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='NSS libsoftokn3.so: C_Login(hSession=0x80000004, userType=0)=0x00000000 exe=\"/tmp/nss_fips\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"debian\""
],
"record_type": "CRYPTO_LOGIN"
}
CRYPTO_LOGOUT msgtype 2403
#Description
Cryptographic officer logout
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "1000",
"exe": "/tmp/nss_fail",
"hostname": "?",
"pid": "146120",
"res": "failed",
"ses": "150",
"subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=CRYPTO_LOGOUT msg=audit(1781742719.774:2986394): pid=146120 uid=0 auid=1000 ses=150 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='NSS libsoftokn3.so: C_Logout(hSession=0x80000001)=0x00000101 exe=\"/tmp/nss_fail\" hostname=? addr=? terminal=? res=failed'",
"UID=\"root\" AUID=\"debian\""
],
"record_type": "CRYPTO_LOGOUT"
}
CRYPTO_KEY_USER msgtype 2404
#Description
Create, delete, negotiate cryptographic key identifier
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
kind | server or client in crypto operation |
fp | crypto key fingerprint |
direction | IPsec SA direction |
spid | sent process ID |
suid | user ID that initiated the crypto operation |
rport | remote port number |
laddr | local network address |
lport | local network port |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "127.0.0.1",
"auid": "1000",
"direction": "both",
"exe": "/usr/local/libexec/sshd-session",
"fp": "?",
"hostname": "?",
"kind": "session",
"laddr": "127.0.0.1",
"lport": "2222",
"op": "destroy",
"pid": "138898",
"res": "success",
"rport": "58318",
"ses": "120",
"spid": "138899",
"subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
"suid": "101",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=CRYPTO_KEY_USER msg=audit(1781721196.292:246634): pid=138898 uid=0 auid=1000 ses=120 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=138899 suid=101 rport=58318 laddr=127.0.0.1 lport=2222 exe=\"/usr/local/libexec/sshd-session\" hostname=? addr=127.0.0.1 terminal=? res=success'",
"UID=\"root\" AUID=\"debian\" SUID=\"sshd\""
],
"record_type": "CRYPTO_KEY_USER"
}
CRYPTO_FAILURE_USER msgtype 2405
#Description
Fail decrypt, encrypt or randomize operation
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "1000",
"exe": "/tmp/nss_fail2",
"hostname": "?",
"pid": "146639",
"res": "failed",
"ses": "153",
"subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=CRYPTO_FAILURE_USER msg=audit(1781742765.075:3001374): pid=146639 uid=0 auid=1000 ses=153 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='NSS libsoftokn3.so: C_EncryptInit(hSession=0x80000005, pMechanism=7ffcd29cca50 {mechanism=0x00000111, ...}, hKey=0x00000002)=0x00000063 exe=\"/tmp/nss_fail2\" hostname=? addr=? terminal=? res=failed'",
"UID=\"root\" AUID=\"debian\""
],
"record_type": "CRYPTO_FAILURE_USER"
}
CRYPTO_REPLAY_USER msgtype 2406
#Description
Cryptographic replay attack detected
CRYPTO_SESSION msgtype 2407
#Description
Parameters set during TLS session establishment
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
direction | IPsec SA direction |
cipher | name of crypto cipher selected |
ksize | key size for crypto operation |
mac | crypto MAC algorithm selected |
pfs | key-exchange group negotiated for perfect forward secrecy |
spid | sent process ID |
suid | user ID that initiated the crypto operation |
rport | remote port number |
laddr | local network address |
lport | local network port |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "127.0.0.1",
"auid": "1000",
"cipher": "chacha20-poly1305@openssh.com",
"direction": "from-server",
"exe": "/usr/local/libexec/sshd-session",
"hostname": "?",
"ksize": "512",
"laddr": "127.0.0.1",
"lport": "2222",
"mac": "<implicit>",
"op": "start",
"pfs": "sntrup761x25519-sha512",
"pid": "138898",
"res": "success",
"rport": "58318",
"ses": "120",
"spid": "138899",
"subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
"suid": "101",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=CRYPTO_SESSION msg=audit(1781721196.086:246626): pid=138898 uid=0 auid=1000 ses=120 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=chacha20-poly1305@openssh.com ksize=512 mac=<implicit> pfs=sntrup761x25519-sha512 spid=138899 suid=101 rport=58318 laddr=127.0.0.1 lport=2222 exe=\"/usr/local/libexec/sshd-session\" hostname=? addr=127.0.0.1 terminal=? res=success'",
"UID=\"root\" AUID=\"debian\" SUID=\"sshd\""
],
"record_type": "CRYPTO_SESSION"
}
CRYPTO_IKE_SA msgtype 2408
#Description
Parameters related to IKE SA
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
direction | IPsec SA direction |
conn-name | IPsec connection name |
connstate | pluto's internal state-object serial number for this negotiation (increments per state; not an enumerated connection status) |
ike-version | IKE protocol version |
auth | authentication method negotiated for the IKE SA |
cipher | name of crypto cipher selected |
ksize | key size for crypto operation |
integ | integrity algorithm negotiated for the IKE SA |
prf | pseudo-random function negotiated for the IKE SA |
pfs | key-exchange group negotiated for perfect forward secrecy |
raddr | remote address of the connection |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "192.0.2.1",
"auid": "4294967295",
"auth": "PRESHARED_KEY",
"cipher": "none",
"conn-name": "r5",
"connstate": "1",
"direction": "initiator",
"exe": "/usr/libexec/ipsec/pluto",
"hostname": "?",
"ike-version": "2.0",
"integ": "none",
"ksize": "0",
"op": "start",
"pfs": "MODP2048",
"pid": "61499",
"prf": "none",
"raddr": "192.0.2.250",
"res": "failed",
"ses": "4294967295",
"subj": "system_u:system_r:ipsec_t:s0",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=CRYPTO_IKE_SA msg=audit(1781641429.666:2206992): pid=61499 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:ipsec_t:s0 msg='op=start direction=initiator conn-name=\"r5\" connstate=1 ike-version=2.0 auth=PRESHARED_KEY cipher=none ksize=0 integ=none prf=none pfs=MODP2048 raddr=192.0.2.250 exe=\"/usr/libexec/ipsec/pluto\" hostname=? addr=192.0.2.1 terminal=? res=failed'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "CRYPTO_IKE_SA"
}
CRYPTO_IPSEC_SA msgtype 2409
#Description
Parameters related to IPSEC SA
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
op | the operation being performed that is audited |
conn-name | IPsec connection name |
connstate | pluto's internal state-object serial number for this negotiation (increments per state; not an enumerated connection status) |
satype | IPsec SA type (ipsec-esp, ipsec-ah, or ipsec-policy) |
samode | IPsec SA mode (transport or tunnel) |
cipher | name of crypto cipher selected |
ksize | key size for crypto operation |
integ | integrity algorithm negotiated for the IPsec SA |
in-spi | inbound IPsec Security Parameter Index |
out-spi | outbound IPsec Security Parameter Index |
in-ipcomp | inbound IP compression CPI |
out-ipcomp | outbound IP compression CPI |
raddr | remote address of the connection |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "192.0.2.1",
"auid": "1000",
"cipher": "AES_GCM_C",
"conn-name": "r5",
"connstate": "2,",
"exe": "/usr/libexec/ipsec/pluto",
"hostname": "?",
"in-ipcomp": "0(0x00000000)",
"in-spi": "2296459588(0x2296459588)",
"integ": "NONE",
"ksize": "256",
"op": "start",
"out-ipcomp": "0(0x00000000)",
"out-spi": "2215416355(0x2215416355)",
"pid": "88553",
"raddr": "192.0.2.2",
"res": "success",
"samode": "tunnel",
"satype": "ipsec-esp",
"ses": "7",
"subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
"terminal": "?",
"uid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=CRYPTO_IPSEC_SA msg=audit(1781643889.065:2839748): pid=88553 uid=0 auid=1000 ses=7 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=start conn-name=\"r5\" connstate=2, satype=ipsec-esp samode=tunnel cipher=AES_GCM_C ksize=256 integ=NONE in-spi=2296459588(0x2296459588) out-spi=2215416355(0x2215416355) in-ipcomp=0(0x00000000) out-ipcomp=0(0x00000000) raddr=192.0.2.2 exe=\"/usr/libexec/ipsec/pluto\" hostname=? addr=192.0.2.1 terminal=? res=success'",
"UID=\"root\" AUID=\"debian\""
],
"record_type": "CRYPTO_IPSEC_SA"
}
VIRT_CONTROL msgtype 2500
#Description
Start, Pause, Stop VM
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
virt | virtualization driver (qemu, lxc, ...) |
op | the operation being performed that is audited |
reason | reason for the operation |
vm | name of the virtual machine |
uuid | UUID of the virtual machine |
vm-pid | process ID of the virtual machine (0 if not yet started) |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "4294967295",
"exe": "/usr/sbin/libvirtd",
"hostname": "?",
"op": "start",
"pid": "58538",
"reason": "booted",
"res": "failed",
"ses": "4294967295",
"subj": "system_u:system_r:virtd_t:s0",
"terminal": "?",
"uid": "0",
"uuid": "fb5e54c6-0345-4b27-b694-688d88eb48d0",
"virt": "qemu",
"vm": "r5vm",
"vm-pid": "0"
},
"raw": [
"node=JD-debian-12-workstation type=VIRT_CONTROL msg=audit(1781641224.555:2099420): pid=58538 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:virtd_t:s0 msg='virt=qemu op=start reason=booted vm=\"r5vm\" uuid=fb5e54c6-0345-4b27-b694-688d88eb48d0 vm-pid=0 exe=\"/usr/sbin/libvirtd\" hostname=? addr=? terminal=? res=failed'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "VIRT_CONTROL"
}
VIRT_RESOURCE msgtype 2501
#Description
Resource assignment
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
virt | virtualization driver (qemu, lxc, ...) |
resrc | resource the record applies to (disk, mem, net for VIRT; object type for MAC config changes) |
reason | reason for the operation |
vm | name of the virtual machine |
uuid | UUID of the virtual machine |
old-disk | previous resource value; the field is named old-<resrc> (old-disk, old-mem, ...) |
new-disk | new resource value; the field is named new-<resrc> (new-disk, new-mem, ...) |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "4294967295",
"exe": "/usr/sbin/libvirtd",
"hostname": "?",
"new-disk": "/tmp/r5disk.qcow2",
"old-disk": "?",
"pid": "58538",
"reason": "start",
"res": "success",
"resrc": "disk",
"ses": "4294967295",
"subj": "system_u:system_r:virtd_t:s0",
"terminal": "?",
"uid": "0",
"uuid": "fb5e54c6-0345-4b27-b694-688d88eb48d0",
"virt": "qemu",
"vm": "r5vm"
},
"raw": [
"node=JD-debian-12-workstation type=VIRT_RESOURCE msg=audit(1781641224.551:2099397): pid=58538 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:virtd_t:s0 msg='virt=qemu resrc=disk reason=start vm=\"r5vm\" uuid=fb5e54c6-0345-4b27-b694-688d88eb48d0 old-disk=\"?\" new-disk=\"/tmp/r5disk.qcow2\" exe=\"/usr/sbin/libvirtd\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "VIRT_RESOURCE"
}
VIRT_MACHINE_ID msgtype 2502
#Description
Binding of label to VM
Fields #
| Name | Description |
|---|---|
pid | process ID |
uid | user ID |
auid | login user ID |
ses | login session ID |
subj | lspp subject's context string |
virt | virtualization driver (qemu, lxc, ...) |
vm | name of the virtual machine |
uuid | UUID of the virtual machine |
vm-ctx | SELinux process context assigned to the VM |
img-ctx | SELinux file context assigned to the VM image |
model | security model used for VM labeling (selinux, apparmor, dac) |
exe | executable name |
hostname | the hostname that the user is connecting from |
addr | the remote address that the user is connecting from |
terminal | terminal name the user is running programs on |
res | result of the audited operation(success/fail) |
Example Audit Record #
{
"fields": {
"addr": "?",
"auid": "4294967295",
"exe": "/usr/sbin/libvirtd",
"hostname": "?",
"img-ctx": "system_u:object_r:svirt_image_t:s0:c62,c990",
"model": "selinux",
"pid": "58538",
"res": "success",
"ses": "4294967295",
"subj": "system_u:system_r:virtd_t:s0",
"terminal": "?",
"uid": "0",
"uuid": "fb5e54c6-0345-4b27-b694-688d88eb48d0",
"virt": "qemu",
"vm": "r5vm",
"vm-ctx": "system_u:system_r:svirt_t:s0:c62,c990"
},
"raw": [
"node=JD-debian-12-workstation type=VIRT_MACHINE_ID msg=audit(1781641224.479:2099037): pid=58538 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:virtd_t:s0 msg='virt=qemu vm=\"r5vm\" uuid=fb5e54c6-0345-4b27-b694-688d88eb48d0 vm-ctx=system_u:system_r:svirt_t:s0:c62,c990 img-ctx=system_u:object_r:svirt_image_t:s0:c62,c990 model=selinux exe=\"/usr/sbin/libvirtd\" hostname=? addr=? terminal=? res=success'",
"UID=\"root\" AUID=\"unset\""
],
"record_type": "VIRT_MACHINE_ID"
}
VIRT_INTEGRITY_CHECK msgtype 2503
#Description
Guest integrity results
VIRT_CREATE msgtype 2504
#Description
Creation of guest image
VIRT_DESTROY msgtype 2505
#Description
Destruction of guest image
VIRT_MIGRATE_IN msgtype 2506
#Description
Inbound guest migration info
VIRT_MIGRATE_OUT msgtype 2507
#Description
Outbound guest migration info
References
- Linux audit message dictionary (name, number, origin, class, description)
- Linux audit field dictionary (per-field FORMAT, MEANING, per-record EXCEPTION)
- libaudit userspace record-type constants (1100-1199 USER_*/SERVICE_*/CRED_*, 1205-1209 DAEMON_ROTATE..DAEMON_ERR, 1500-1599 AppArmor, 2100-2999 anomaly/response/role/crypto/virt)
- kernel UAPI AUDIT_* numeric constants (1200-1204 daemon, 1300-1399 syscall, 1400-1419 MAC/LSM; 1420-1426 IPE/Landlock/MAC-contexts defined upstream but not yet named by libaudit)
- libaudit record-type name table