auditd

msgtypeTitleDescriptionSampleRule
1005USERmsgtype 1005Message from userspace (deprecated)YN
1006LOGINmsgtype 1006Define the login ID and informationYN
1100USER_AUTHmsgtype 1100User system access authenticationYY
1101USER_ACCTmsgtype 1101User system access authorizationYY
1102USER_MGMTmsgtype 1102User account attribute changeYN
1103CRED_ACQmsgtype 1103User credential acquiredYY
1104CRED_DISPmsgtype 1104User credential disposedYN
1105USER_STARTmsgtype 1105User session startYY
1106USER_ENDmsgtype 1106User session endYY
1107USER_AVCmsgtype 1107User space AVC (Access Vector Cache) messageYN
1108USER_CHAUTHTOKmsgtype 1108User account authentication token or attribute changedYN
1109USER_ERRmsgtype 1109User account state errorYN
1110CRED_REFRmsgtype 1110User credential refreshedYN
1111USYS_CONFIGmsgtype 1111User space system config changeYN
1112USER_LOGINmsgtype 1112User login attempt (success or failure)YY
1113USER_LOGOUTmsgtype 1113User has logged outYN
1114ADD_USERmsgtype 1114User account addedYY
1115DEL_USERmsgtype 1115User account deletedYN
1116ADD_GROUPmsgtype 1116Group account addedYN
1117DEL_GROUPmsgtype 1117Group account deletedYN
1118DAC_CHECKmsgtype 1118User space DAC check resultsNN
1119CHGRP_IDmsgtype 1119User space group ID changedYN
1120TESTmsgtype 1120Used for test success messagesNN
1121TRUSTED_APPmsgtype 1121Trusted app msg - freestyle textYN
1122USER_SELINUX_ERRmsgtype 1122SELinux user space errorNN
1123USER_CMDmsgtype 1123User shell command and argsYY
1124USER_TTYmsgtype 1124Non-ICANON TTY input meaningYY
1125CHUSER_IDmsgtype 1125Changed user ID supplemental dataNN
1126GRP_AUTHmsgtype 1126Authentication for group passwordYN
1127SYSTEM_BOOTmsgtype 1127System bootYN
1128SYSTEM_SHUTDOWNmsgtype 1128System shutdownYN
1129SYSTEM_RUNLEVELmsgtype 1129System runlevel changeYN
1130SERVICE_STARTmsgtype 1130Service (daemon) startYN
1131SERVICE_STOPmsgtype 1131Service (daemon) stopYY
1132GRP_MGMTmsgtype 1132Group account attribute was modifiedYN
1133GRP_CHAUTHTOKmsgtype 1133Group account password or PIN changedYN
1134MAC_CHECKmsgtype 1134User space MAC (Mandatory Access Control) decision resultsNN
1135ACCT_LOCKmsgtype 1135User's account locked by adminYN
1136ACCT_UNLOCKmsgtype 1136User's account unlocked by adminYN
1137USER_DEVICEmsgtype 1137User space hotplug device changesYN
1138SOFTWARE_UPDATEmsgtype 1138Software update eventYN
1200DAEMON_STARTmsgtype 1200Daemon startup recordYY
1201DAEMON_ENDmsgtype 1201Daemon normal stop recordYY
1202DAEMON_ABORTmsgtype 1202Daemon error stop recordYY
1203DAEMON_CONFIGmsgtype 1203Daemon config changeYN
1205DAEMON_ROTATEmsgtype 1205Auditd should rotate logsYN
1206DAEMON_RESUMEmsgtype 1206Auditd should resume loggingYN
1207DAEMON_ACCEPTmsgtype 1207Auditd accepted remote connectionYN
1208DAEMON_CLOSEmsgtype 1208Auditd closed remote connectionYN
1209DAEMON_ERRmsgtype 1209Auditd internal errorNN
1300SYSCALLmsgtype 1300System call event informationYY
1302PATHmsgtype 1302Filename path informationYY
1303IPCmsgtype 1303System call IPC (Inter-Process Communication) objectYN
1304SOCKETCALLmsgtype 1304System call socketcall argumentsYN
1305CONFIG_CHANGEmsgtype 1305Audit system configuration changeYN
1306SOCKADDRmsgtype 1306System call socket address argument informationYN
1307CWDmsgtype 1307Current working directoryYY
1309EXECVEmsgtype 1309Arguments supplied to the execve system callYY
1311IPC_SET_PERMmsgtype 1311IPC new permissions record typeYN
1312MQ_OPENmsgtype 1312POSIX MQ open record typeYN
1313MQ_SENDRECVmsgtype 1313POSIX MQ send/receive record typeYN
1314MQ_NOTIFYmsgtype 1314POSIX MQ notify record typeYN
1315MQ_GETSETATTRmsgtype 1315POSIX MQ get/set attribute record typeYN
1316KERNEL_OTHERmsgtype 1316For use by 3rd party modulesNN
1317FD_PAIRmsgtype 1317Information for pipe and socketpair system callsYN
1318OBJ_PIDmsgtype 1318Target process information for ptrace, kill, tkill, and tgkill syscallsYN
1319TTYmsgtype 1319Input on an administrative TTYYY
1320EOEmsgtype 1320End of multi-record eventYN
1321BPRM_FCAPSmsgtype 1321Information about file system capabilities increasing permissionsYY
1322CAPSETmsgtype 1322Record showing argument to sys_capset setting process-based capabilitiesYN
1323MMAPmsgtype 1323Mmap system call file descriptor and flagsYN
1324NETFILTER_PKTmsgtype 1324Packets traversing netfilter chainsYN
1325NETFILTER_CFGmsgtype 1325Netfilter chain modificationsYN
1326SECCOMPmsgtype 1326Secure Computing eventYN
1327PROCTITLEmsgtype 1327Process Title infoYY
1328FEATURE_CHANGEmsgtype 1328Audit feature changed valueYN
1330KERN_MODULEmsgtype 1330Kernel Module eventsYN
1331FANOTIFYmsgtype 1331Fanotify access decisionYN
1332TIME_INJOFFSETmsgtype 1332Timekeeping offset injectedYN
1333TIME_ADJNTPVALmsgtype 1333NTP value adjustmentYN
1334BPFmsgtype 1334BPF load/unloadYN
1335EVENT_LISTENERmsgtype 1335audit mcast sock join/partYN
1336URINGOPmsgtype 1336io_uring operationYN
1337OPENAT2msgtype 1337Record showing openat2 how argsYN
1338DM_CTRLmsgtype 1338Device Mapper target controlYN
1339DM_EVENTmsgtype 1339Device Mapper eventsYN
1400AVCmsgtype 1400SELinux AVC (Access Vector Cache) denial or grantYN
1401SELINUX_ERRmsgtype 1401Internal SELinux errorsYN
1402AVC_PATHmsgtype 1402dentry, vfsmount pair from AVCNN
1403MAC_POLICY_LOADmsgtype 1403SELinux Policy file loadYN
1404MAC_STATUSmsgtype 1404SELinux mode (enforcing, permissive, off) changedYN
1405MAC_CONFIG_CHANGEmsgtype 1405SELinux Boolean value modificationYN
1406MAC_UNLBL_ALLOWmsgtype 1406NetLabel: allow unlabeled trafficYN
1407MAC_CIPSOV4_ADDmsgtype 1407NetLabel: add CIPSOv4 (Commercial Internet Protocol Security Option) DOI (Domain of Interpretation) entryYN
1408MAC_CIPSOV4_DELmsgtype 1408NetLabel: del CIPSOv4 (Commercial Internet Protocol Security Option) DOI (Domain of Interpretation) entryYN
1409MAC_MAP_ADDmsgtype 1409NetLabel: add LSM (Linux Security Module) domain mappingYN
1410MAC_MAP_DELmsgtype 1410NetLabel: del LSM (Linux Security Module) domain mappingYN
1411MAC_IPSEC_ADDSAmsgtype 1411Not usedNN
1412MAC_IPSEC_DELSAmsgtype 1412Not usedNN
1413MAC_IPSEC_ADDSPDmsgtype 1413Not usedNN
1414MAC_IPSEC_DELSPDmsgtype 1414Not usedNN
1415MAC_IPSEC_EVENTmsgtype 1415Audit an IPsec eventYN
1416MAC_UNLBL_STCADDmsgtype 1416NetLabel: add a static labelYN
1417MAC_UNLBL_STCDELmsgtype 1417NetLabel: del a static labelYN
1418MAC_CALIPSO_ADDmsgtype 1418NetLabel: add CALIPSO DOI (Domain of Interpretation) entryYN
1419MAC_CALIPSO_DELmsgtype 1419NetLabel: delete CALIPSO DOI (Domain of Interpretation) entryYN
1420IPE_ACCESSmsgtype 1420Integrity Policy Enforcement (IPE) access decision (denial or grant)YN
1421IPE_CONFIG_CHANGEmsgtype 1421IPE active policy changeYN
1422IPE_POLICY_LOADmsgtype 1422IPE policy loadYN
1423LANDLOCK_ACCESSmsgtype 1423Landlock access denialYN
1424LANDLOCK_DOMAINmsgtype 1424Landlock domain allocation or deallocation statusYN
1425MAC_TASK_CONTEXTSmsgtype 1425Subject security contexts when multiple LSMs are activeNN
1426MAC_OBJ_CONTEXTSmsgtype 1426Object security contexts when multiple LSMs are activeNN
1500APPARMORmsgtype 1500AppArmor LSM audit eventNN
1501APPARMOR_AUDITmsgtype 1501AppArmor access decision logged in audit modeNN
1502APPARMOR_ALLOWEDmsgtype 1502AppArmor access allowed (complain or learning mode)NN
1503APPARMOR_DENIEDmsgtype 1503AppArmor access denied in enforce modeNN
1504APPARMOR_HINTmsgtype 1504AppArmor reserved audit type (unused in the current kernel)NN
1505APPARMOR_STATUSmsgtype 1505AppArmor policy load or status changeNN
1506APPARMOR_ERRORmsgtype 1506AppArmor internal errorNN
1507APPARMOR_KILLmsgtype 1507AppArmor access denied with task killNN
1700ANOM_PROMISCUOUSmsgtype 1700Device changed promiscuous modeYN
1701ANOM_ABENDmsgtype 1701Process ended abnormallyYN
1702ANOM_LINKmsgtype 1702Suspicious use of file linksYN
1703ANOM_CREATmsgtype 1703Suspicious file creationYN
1800INTEGRITY_DATAmsgtype 1800Data integrity verificationYN
1801INTEGRITY_METADATAmsgtype 1801Metadata integrity verificationYN
1802INTEGRITY_STATUSmsgtype 1802Integrity enable statusYN
1803INTEGRITY_HASHmsgtype 1803Integrity HASH typeNN
1804INTEGRITY_PCRmsgtype 1804PCR (Platform Configuration Register) invalidation messagesYN
1805INTEGRITY_RULEmsgtype 1805Integrity Policy actionYN
1806INTEGRITY_EVM_XATTRmsgtype 1806EVM XATTRS modificationsYN
1807INTEGRITY_POLICY_RULEmsgtype 1807Integrity Policy ruleYN
1808INTEGRITY_USERSPACEmsgtype 1808IMA appraisal of userspace-supplied dataYN
2000KERNELmsgtype 2000Kernel audit statusNN
2100ANOM_LOGIN_FAILURESmsgtype 2100Failed login limit reachedYN
2101ANOM_LOGIN_TIMEmsgtype 2101Login attempted at bad timeYN
2102ANOM_LOGIN_SESSIONSmsgtype 2102Maximum concurrent sessions reachedYN
2103ANOM_LOGIN_ACCTmsgtype 2103Login attempted to watched accountYN
2104ANOM_LOGIN_LOCATIONmsgtype 2104Login from forbidden locationYN
2105ANOM_MAX_DACmsgtype 2105Max DAC (Discretionary Access Control) failures reachedYN
2106ANOM_MAX_MACmsgtype 2106Max MAC (Mandatory Access Control) failures reachedYN
2107ANOM_AMTU_FAILmsgtype 2107AMTU (Abstract Machine Test Utility) failureYN
2108ANOM_RBAC_FAILmsgtype 2108RBAC (Role-Based Access Control) self test failureYN
2109ANOM_RBAC_INTEGRITY_FAILmsgtype 2109RBAC (Role-Based Access Control) file integrity test failureYN
2110ANOM_CRYPTO_FAILmsgtype 2110Crypto system test failureYN
2111ANOM_ACCESS_FSmsgtype 2111Access of file or directory ended abnormallyYN
2112ANOM_EXECmsgtype 2112Execution of file ended abnormallyYN
2113ANOM_MK_EXECmsgtype 2113Make an executableYN
2114ANOM_ADD_ACCTmsgtype 2114Adding a user account ended abnormallyYN
2115ANOM_DEL_ACCTmsgtype 2115Deleting a user account ended abnormallyYN
2116ANOM_MOD_ACCTmsgtype 2116Changing an account ended abnormallyYN
2117ANOM_ROOT_TRANSmsgtype 2117User became rootYN
2118ANOM_LOGIN_SERVICEmsgtype 2118Service acct attempted loginYN
2119ANOM_LOGIN_ROOTmsgtype 2119Root login attemptedYN
2120ANOM_ORIGIN_FAILURESmsgtype 2120Origin has too many failed login attemptsYN
2121ANOM_SESSIONmsgtype 2121The user session is badYN
2200RESP_ANOMALYmsgtype 2200Anomaly not reacted toYN
2201RESP_ALERTmsgtype 2201Alert notification action (email or log): the email/log reactions are unimplemented FIXME stubs in upstream audisp-ids 3.x (reactions.c:370-372); emittable by custom pluginsYN
2202RESP_KILL_PROCmsgtype 2202Kill programYN
2203RESP_TERM_ACCESSmsgtype 2203Terminate sessionYN
2204RESP_ACCT_REMOTEmsgtype 2204User account locked from remote accessYN
2205RESP_ACCT_LOCK_TIMEDmsgtype 2205User account locked for timeYN
2206RESP_ACCT_UNLOCK_TIMEDmsgtype 2206User account unlocked from timeYN
2207RESP_ACCT_LOCKmsgtype 2207User account was lockedYN
2208RESP_TERM_LOCKmsgtype 2208Terminal was lockedYN
2209RESP_SEBOOLmsgtype 2209Set an SELinux booleanYN
2210RESP_EXECmsgtype 2210Execute a scriptYN
2211RESP_SINGLEmsgtype 2211Go to single user modeYN
2212RESP_HALTmsgtype 2212Take the system downYN
2213RESP_ORIGIN_BLOCKmsgtype 2213Remote address blocked by firewall rule (iptables or nftables depending on system configuration)YN
2214RESP_ORIGIN_BLOCK_TIMEDmsgtype 2214Address blocked for timeYN
2215RESP_ORIGIN_UNBLOCK_TIMEDmsgtype 2215Address unblocked from timedYN
2300USER_ROLE_CHANGEmsgtype 2300User changed to a new SELinux roleYN
2301ROLE_ASSIGNmsgtype 2301Administrator assigned user to SELinux roleYN
2302ROLE_REMOVEmsgtype 2302Administrator removed user from SELinux roleYN
2303LABEL_OVERRIDEmsgtype 2303Administrator is overriding a SELinux labelYN
2304LABEL_LEVEL_CHANGEmsgtype 2304Object level SELinux label modifiedYN
2305USER_LABELED_EXPORTmsgtype 2305Object exported with SELinux labelYN
2306USER_UNLABELED_EXPORTmsgtype 2306Object exported without SELinux labelNN
2307DEV_ALLOCmsgtype 2307Device was allocatedNN
2308DEV_DEALLOCmsgtype 2308Device was deallocatedNN
2309FS_RELABELmsgtype 2309Filesystem relabeledYN
2310USER_MAC_POLICY_LOADmsgtype 2310Userspace daemon loaded SELinux policyYN
2311ROLE_MODIFYmsgtype 2311Administrator modified an SELinux roleNN
2312USER_MAC_CONFIG_CHANGEmsgtype 2312Change made to MAC (Mandatory Access Control) policyYN
2313USER_MAC_STATUSmsgtype 2313Userspace daemon enforcing changeYN
2400CRYPTO_TEST_USERmsgtype 2400Cryptographic test resultsYN
2401CRYPTO_PARAM_CHANGE_USERmsgtype 2401Cryptographic attribute changeYN
2402CRYPTO_LOGINmsgtype 2402Cryptographic officer loginYN
2403CRYPTO_LOGOUTmsgtype 2403Cryptographic officer logoutYN
2404CRYPTO_KEY_USERmsgtype 2404Create, delete, negotiate cryptographic key identifierYN
2405CRYPTO_FAILURE_USERmsgtype 2405Fail decrypt, encrypt or randomize operationYN
2406CRYPTO_REPLAY_USERmsgtype 2406Cryptographic replay attack detectedNN
2407CRYPTO_SESSIONmsgtype 2407Parameters set during TLS session establishmentYN
2408CRYPTO_IKE_SAmsgtype 2408Parameters related to IKE SAYN
2409CRYPTO_IPSEC_SAmsgtype 2409Parameters related to IPSEC SAYN
2500VIRT_CONTROLmsgtype 2500Start, Pause, Stop VMYN
2501VIRT_RESOURCEmsgtype 2501Resource assignmentYN
2502VIRT_MACHINE_IDmsgtype 2502Binding of label to VMYN
2503VIRT_INTEGRITY_CHECKmsgtype 2503Guest integrity resultsNN
2504VIRT_CREATEmsgtype 2504Creation of guest imageNN
2505VIRT_DESTROYmsgtype 2505Destruction of guest imageNN
2506VIRT_MIGRATE_INmsgtype 2506Inbound guest migration infoNN
2507VIRT_MIGRATE_OUTmsgtype 2507Outbound guest migration infoNN

USER msgtype 1005

#
Message type
1005
Fires
Emitted by default (no audit rule required)

Description

Message from userspace (deprecated)

Fields #

NameDescription
textfree-form message text supplied by the sender (auditctl -m / audit_log_user_message)
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "1000",
    "exe": "/usr/sbin/auditctl",
    "hostname": "?",
    "pid": "2909",
    "res": "success",
    "ses": "1",
    "subj": "unconfined_u:unconfined_r:auditctl_t:s0-s0:c0.c1023",
    "terminal": "?",
    "text": "CATALOG_RESP_DEMO",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=USER msg=audit(1781634271.615:539452): pid=2909 uid=0 auid=1000 ses=1 subj=unconfined_u:unconfined_r:auditctl_t:s0-s0:c0.c1023 msg='text=CATALOG_RESP_DEMO exe=\"/usr/sbin/auditctl\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"debian\""
  ],
  "record_type": "USER"
}

LOGIN msgtype 1006

#
Message type
1006
Fires
Emitted by default (no audit rule required)

Description

Define the login ID and information

Fields #

NameDescription
pidprocess ID
uiduser ID
subjlspp subject's context string
old-auidaudit login UID before this login record set it
auidlogin user ID
ttytty udevice the user is running programs on
old-sessession ID before this login record set it
seslogin session ID
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "auid": "1003",
    "old-auid": "4294967295",
    "old-ses": "4294967295",
    "pid": "51529",
    "res": "1",
    "ses": "17",
    "subj": "unconfined",
    "tty": "(none)",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=LOGIN msg=audit(1781632420.123:1880745): pid=51529 uid=0 subj=unconfined old-auid=4294967295 auid=1003 tty=(none) old-ses=4294967295 ses=17 res=1",
    "UID=\"root\" OLD-AUID=\"unset\" AUID=\"r2usr\""
  ],
  "record_type": "LOGIN"
}

References #

USER_AUTH msgtype 1100

#
Message type
1100
Fires
Emitted by default (no audit rule required)

Description

User system access authentication

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
grantorsPAM modules that granted (or would deny) the operation
accta user's account name
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "acct": "debian",
    "addr": "10.2.20.61",
    "auid": "4294967295",
    "exe": "/usr/sbin/sshd",
    "grantors": "pam_permit",
    "hostname": "10.2.20.61",
    "op": "PAM:authentication",
    "pid": "996",
    "res": "success",
    "ses": "4294967295",
    "subj": "system_u:system_r:sshd_t:s0",
    "terminal": "ssh",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=USER_AUTH msg=audit(1781634177.456:177708): pid=996 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0 msg='op=PAM:authentication grantors=pam_permit acct=\"debian\" exe=\"/usr/sbin/sshd\" hostname=10.2.20.61 addr=10.2.20.61 terminal=ssh res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "USER_AUTH"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
prefixeqsrc_1 rulesplunk
typeinuser_auth1 rulesplunk

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

USER_ACCT msgtype 1101

#
Message type
1101
Fires
Emitted by default (no audit rule required)

Description

User system access authorization

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
grantorsPAM modules that granted (or would deny) the operation
accta user's account name
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "acct": "root",
    "addr": "?",
    "auid": "4294967295",
    "exe": "/usr/bin/sudo",
    "grantors": "pam_permit",
    "hostname": "?",
    "op": "PAM:accounting",
    "pid": "2759",
    "res": "success",
    "ses": "4294967295",
    "subj": "system_u:system_r:initrc_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=USER_ACCT msg=audit(1781634264.630:525236): pid=2759 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:initrc_t:s0 msg='op=PAM:accounting grantors=pam_permit acct=\"root\" exe=\"/usr/bin/sudo\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "USER_ACCT"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
CommandLinecontains.sh1 rulesplunk
CommandLinecontainslist1 rulesplunk
exein/usr/bin/sudo1 rulesplunk
typeincred_acq1 rulesplunk
typeinuser_acct1 rulesplunk
typeinuser_cmd1 rulesplunk

USER_MGMT msgtype 1102

#
Message type
1102
Fires
Emitted by default (no audit rule required)

Description

User account attribute change

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)
opthe operation being performed that is audited

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "4294967295",
    "exe": "/usr/sbin/useradd",
    "hostname": "?",
    "id": "1000",
    "op": "add-home-dir",
    "pid": "1264",
    "res": "success",
    "ses": "4294967295",
    "subj": "system_u:system_r:unconfined_service_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "type=USER_MGMT msg=audit(1481076992.521:393): pid=1264 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:unconfined_service_t:s0 msg='op=add-home-dir id=1000 exe=\"/usr/sbin/useradd\" hostname=? addr=? terminal=? res=success'"
  ],
  "record_type": "USER_MGMT"
}

Example keys not documented in the fields table: id

CRED_ACQ msgtype 1103

#
Message type
1103
Fires
Emitted by default (no audit rule required)

Description

User credential acquired

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
grantorsPAM modules that granted (or would deny) the operation
accta user's account name
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "acct": "debian",
    "addr": "10.2.20.61",
    "auid": "4294967295",
    "exe": "/usr/sbin/sshd",
    "grantors": "pam_permit",
    "hostname": "10.2.20.61",
    "op": "PAM:setcred",
    "pid": "996",
    "res": "success",
    "ses": "4294967295",
    "subj": "system_u:system_r:sshd_t:s0",
    "terminal": "ssh",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=CRED_ACQ msg=audit(1781634177.503:178599): pid=996 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0 msg='op=PAM:setcred grantors=pam_permit acct=\"debian\" exe=\"/usr/sbin/sshd\" hostname=10.2.20.61 addr=10.2.20.61 terminal=ssh res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "CRED_ACQ"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
CommandLinecontains.sh1 rulesplunk
CommandLinecontainslist1 rulesplunk
exein/usr/bin/sudo1 rulesplunk
typeincred_acq1 rulesplunk
typeinuser_acct1 rulesplunk
typeinuser_cmd1 rulesplunk

CRED_DISP msgtype 1104

#
Message type
1104
Fires
Emitted by default (no audit rule required)

Description

User credential disposed

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
grantorsPAM modules that granted (or would deny) the operation
accta user's account name
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "acct": "root",
    "addr": "?",
    "auid": "1000",
    "exe": "/usr/bin/sudo",
    "grantors": "pam_permit",
    "hostname": "?",
    "op": "PAM:setcred",
    "pid": "4342",
    "res": "success",
    "ses": "1",
    "subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
    "terminal": "?",
    "uid": "1000"
  },
  "raw": [
    "node=JD-debian-12-workstation type=CRED_DISP msg=audit(1781634357.202:597381): pid=4342 uid=1000 auid=1000 ses=1 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=PAM:setcred grantors=pam_permit acct=\"root\" exe=\"/usr/bin/sudo\" hostname=? addr=? terminal=? res=success'",
    "UID=\"debian\" AUID=\"debian\""
  ],
  "record_type": "CRED_DISP"
}

USER_START msgtype 1105

#
Message type
1105
Fires
Emitted by default (no audit rule required)

Description

User session start

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
grantorsPAM modules that granted (or would deny) the operation
accta user's account name
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "acct": "root",
    "addr": "?",
    "auid": "1000",
    "exe": "/usr/bin/sudo",
    "grantors": "pam_limits,pam_permit,pam_unix",
    "hostname": "?",
    "op": "PAM:session_open",
    "pid": "4342",
    "res": "success",
    "ses": "1",
    "subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
    "terminal": "?",
    "uid": "1000"
  },
  "raw": [
    "node=JD-debian-12-workstation type=USER_START msg=audit(1781634338.070:594674): pid=4342 uid=1000 auid=1000 ses=1 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=PAM:session_open grantors=pam_limits,pam_permit,pam_unix acct=\"root\" exe=\"/usr/bin/sudo\" hostname=? addr=? terminal=? res=success'",
    "UID=\"debian\" AUID=\"debian\""
  ],
  "record_type": "USER_START"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
CommandLinecontains.sh1 rulesplunk
CommandLinecontainslist1 rulesplunk
exein/usr/bin/sudo1 rulesplunk
prefixeqsrc_1 rulesplunk
typeincred_acq1 rulesplunk
typeinuser_acct1 rulesplunk
typeinuser_cmd1 rulesplunk

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

  • Potential SSH with System User source: NIX System users, typically 1…999 are users that do not map to actual “human” users, but are used as security identities for system daemons, in order to implement privilege separation and run system daemons with minimal privileges. This…T1078, T1078.001

USER_END msgtype 1106

#
Message type
1106
Fires
Emitted by default (no audit rule required)

Description

User session end

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
grantorsPAM modules that granted (or would deny) the operation
accta user's account name
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "acct": "root",
    "addr": "?",
    "auid": "1000",
    "exe": "/usr/bin/sudo",
    "grantors": "pam_limits,pam_permit,pam_unix",
    "hostname": "?",
    "op": "PAM:session_close",
    "pid": "4342",
    "res": "success",
    "ses": "1",
    "subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
    "terminal": "?",
    "uid": "1000"
  },
  "raw": [
    "node=JD-debian-12-workstation type=USER_END msg=audit(1781634357.202:597371): pid=4342 uid=1000 auid=1000 ses=1 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=PAM:session_close grantors=pam_limits,pam_permit,pam_unix acct=\"root\" exe=\"/usr/bin/sudo\" hostname=? addr=? terminal=? res=success'",
    "UID=\"debian\" AUID=\"debian\""
  ],
  "record_type": "USER_END"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
CommandLinecontains.sh1 rulesplunk
CommandLinecontainslist1 rulesplunk
exein/usr/bin/sudo1 rulesplunk
typeincred_acq1 rulesplunk
typeinuser_acct1 rulesplunk
typeinuser_cmd1 rulesplunk

USER_AVC msgtype 1107

#
Message type
1107
Fires
Emitted by default (no audit rule required)

Description

User space AVC (Access Vector Cache) message

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
msgtypeuserspace AVC message type
interfaceD-Bus interface of the userspace AVC
memberD-Bus member (method or signal) of the userspace AVC
destD-Bus destination of the userspace AVC
spidsent process ID
tpidtarget process ID of the userspace AVC
scontextthe subject's context string
tcontextthe target's or object's context string
tclasstarget's object classification
permissiveSELinux is in permissive mode
exeexecutable name
sauidsent login user ID
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "4294967295",
    "dest": ":1.5",
    "exe": "/usr/bin/dbus-daemon",
    "hostname": "?",
    "msgtype": "method_return",
    "permissive": "1",
    "pid": "504",
    "sauid": "100",
    "scontext": "system_u:system_r:systemd_logind_t:s0",
    "ses": "4294967295",
    "spid": "514",
    "subj": "system_u:system_r:system_dbusd_t:s0",
    "tclass": "dbus",
    "tcontext": "system_u:system_r:virtd_t:s0",
    "terminal": "?",
    "tpid": "538",
    "uid": "100"
  },
  "raw": [
    "node=JD-debian-12-workstation type=USER_AVC msg=audit(1781634167.497:12119): pid=504 uid=100 auid=4294967295 ses=4294967295 subj=system_u:system_r:system_dbusd_t:s0 msg='avc:  denied  { send_msg } for msgtype=method_return dest=:1.5 spid=514 tpid=538 scontext=system_u:system_r:systemd_logind_t:s0 tcontext=system_u:system_r:virtd_t:s0 tclass=dbus permissive=1  exe=\"/usr/bin/dbus-daemon\" sauid=100 hostname=? addr=? terminal=?'",
    "UID=\"messagebus\" AUID=\"unset\" SAUID=\"messagebus\""
  ],
  "record_type": "USER_AVC"
}

USER_CHAUTHTOK msgtype 1108

#
Message type
1108
Fires
Emitted by default (no audit rule required)

Description

User account authentication token or attribute changed

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
accta user's account name
idthe numeric UID of the account (emitted when the name is unavailable; mutually exclusive with acct)
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "acct": "r2grp2",
    "addr": "?",
    "auid": "1000",
    "exe": "/usr/bin/gpasswd",
    "hostname": "?",
    "op": "password",
    "pid": "51492",
    "res": "success",
    "ses": "15",
    "subj": "unconfined",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=USER_CHAUTHTOK msg=audit(1781632419.739:1879192): pid=51492 uid=0 auid=1000 ses=15 subj=unconfined msg='op=password of group r2grp2 removed by root acct=\"r2grp2\" exe=\"/usr/bin/gpasswd\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"debian\""
  ],
  "record_type": "USER_CHAUTHTOK"
}

USER_ERR msgtype 1109

#
Message type
1109
Fires
Emitted by default (no audit rule required)

Description

User account state error

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
grantorsPAM modules that granted (or would deny) the operation
accta user's account name
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "acct": "?",
    "addr": "127.0.0.1",
    "auid": "4294967295",
    "exe": "/usr/sbin/sshd",
    "grantors": "?",
    "hostname": "127.0.0.1",
    "op": "PAM:bad_ident",
    "pid": "29600",
    "res": "failed",
    "ses": "4294967295",
    "subj": "unconfined",
    "terminal": "ssh",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=USER_ERR msg=audit(1781630273.728:1288286): pid=29600 uid=0 auid=4294967295 ses=4294967295 subj=unconfined msg='op=PAM:bad_ident grantors=? acct=\"?\" exe=\"/usr/sbin/sshd\" hostname=127.0.0.1 addr=127.0.0.1 terminal=ssh res=failed'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "USER_ERR"
}

CRED_REFR msgtype 1110

#
Message type
1110
Fires
Emitted by default (no audit rule required)

Description

User credential refreshed

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
grantorsPAM modules that granted (or would deny) the operation
accta user's account name
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "acct": "root",
    "addr": "?",
    "auid": "1000",
    "exe": "/usr/bin/sudo",
    "grantors": "pam_permit",
    "hostname": "?",
    "op": "PAM:setcred",
    "pid": "4342",
    "res": "success",
    "ses": "1",
    "subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
    "terminal": "?",
    "uid": "1000"
  },
  "raw": [
    "node=JD-debian-12-workstation type=CRED_REFR msg=audit(1781634338.070:594660): pid=4342 uid=1000 auid=1000 ses=1 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=PAM:setcred grantors=pam_permit acct=\"root\" exe=\"/usr/bin/sudo\" hostname=? addr=? terminal=? res=success'",
    "UID=\"debian\" AUID=\"debian\""
  ],
  "record_type": "CRED_REFR"
}

USYS_CONFIG msgtype 1111

#
Message type
1111
Fires
Emitted by default (no audit rule required)

Description

User space system config change

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "4294967295",
    "exe": "/usr/sbin/hwclock",
    "hostname": "?",
    "pid": "1232",
    "res": "success",
    "ses": "4294967295",
    "subj": "system_u:system_r:unconfined_service_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "type=USYS_CONFIG msg=audit(1481076993.000:402): pid=1232 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:unconfined_service_t:s0 msg='changing system time exe=\"/usr/sbin/hwclock\" hostname=? addr=? terminal=? res=success'"
  ],
  "record_type": "USYS_CONFIG"
}

USER_LOGIN msgtype 1112

#
Message type
1112
Fires
Emitted by default (no audit rule required)

Description

User login attempt (success or failure)

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
accta user's account name
idthe numeric UID of the account (emitted when the name is unavailable; mutually exclusive with acct)
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "acct": "debian",
    "addr": "10.2.20.61",
    "auid": "4294967295",
    "exe": "/usr/sbin/sshd",
    "hostname": "?",
    "op": "login",
    "pid": "996",
    "res": "failed",
    "ses": "4294967295",
    "subj": "system_u:system_r:sshd_t:s0",
    "terminal": "sshd",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=USER_LOGIN msg=audit(1781634177.416:176875): pid=996 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0 msg='op=login acct=\"debian\" exe=\"/usr/sbin/sshd\" hostname=? addr=10.2.20.61 terminal=sshd res=failed'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "USER_LOGIN"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
typeinuser_auth1 rulesplunk

USER_LOGOUT msgtype 1113

#
Message type
1113
Fires
Emitted by default (no audit rule required)

Description

User has logged out

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)
opthe operation being performed that is audited

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "1000",
    "exe": "/usr/sbin/sshd",
    "hostname": "?",
    "id": "1000",
    "op": "login",
    "pid": "1298",
    "res": "success",
    "ses": "1",
    "subj": "system_u:system_r:sshd_t:s0-s0:c0.c1023",
    "terminal": "/dev/pts/0",
    "uid": "0"
  },
  "raw": [
    "type=USER_LOGOUT msg=audit(1481077049.033:424): pid=1298 uid=0 auid=1000 ses=1 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=1000 exe=\"/usr/sbin/sshd\" hostname=? addr=? terminal=/dev/pts/0 res=success'"
  ],
  "record_type": "USER_LOGOUT"
}

Example keys not documented in the fields table: id

ADD_USER msgtype 1114

#
Message type
1114
Fires
Emitted by default (no audit rule required)

Description

User account added

Fields #

NameDescriptionRules
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
idthe numeric UID of the account (emitted when the name is unavailable; mutually exclusive with acct)
exeexecutable name1 detection rule
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "1000",
    "exe": "/usr/sbin/useradd",
    "hostname": "?",
    "id": "1004",
    "op": "adding",
    "pid": "2811",
    "res": "success",
    "ses": "1",
    "subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=ADD_USER msg=audit(1781634268.083:529550): pid=2811 uid=0 auid=1000 ses=1 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=adding user id=1004 exe=\"/usr/sbin/useradd\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"debian\" ID=\"r3usr\""
  ],
  "record_type": "ADD_USER"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
typeeqadd_user2 rulessigma, splunk
typeeqsyscall1 rulesigma

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

  • Linux Auditd Add User Account Type source: The following analytic detects the suspicious add user account type. This behavior is critical for a SOC to monitor because it may indicate attempts to gain unauthorized access or maintain control over a system. Such actions could be signs…T1136, T1136.001

DEL_USER msgtype 1115

#
Message type
1115
Fires
Emitted by default (no audit rule required)

Description

User account deleted

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
accta user's account name
idthe numeric UID of the account (emitted when the name is unavailable; mutually exclusive with acct)
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "1000",
    "exe": "/usr/sbin/userdel",
    "hostname": "?",
    "id": "1004",
    "op": "deleting",
    "pid": "2901",
    "res": "success",
    "ses": "1",
    "subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=DEL_USER msg=audit(1781634271.403:539248): pid=2901 uid=0 auid=1000 ses=1 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=deleting user entries id=1004 exe=\"/usr/sbin/userdel\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"debian\" ID=\"r3usr\""
  ],
  "record_type": "DEL_USER"
}

ADD_GROUP msgtype 1116

#
Message type
1116
Fires
Emitted by default (no audit rule required)

Description

Group account added

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
accta user's account name
idthe numeric GID of the group (emitted when the name is unavailable; mutually exclusive with acct)
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "acct": "r3usr",
    "addr": "?",
    "auid": "1000",
    "exe": "/usr/sbin/useradd",
    "hostname": "?",
    "op": "adding",
    "pid": "2811",
    "res": "success",
    "ses": "1",
    "subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=ADD_GROUP msg=audit(1781634268.083:529538): pid=2811 uid=0 auid=1000 ses=1 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=adding group acct=\"r3usr\" exe=\"/usr/sbin/useradd\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"debian\""
  ],
  "record_type": "ADD_GROUP"
}

DEL_GROUP msgtype 1117

#
Message type
1117
Fires
Emitted by default (no audit rule required)

Description

Group account deleted

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
accta user's account name
idthe numeric GID of the group (emitted when the name is unavailable; mutually exclusive with acct)
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "acct": "r3usr",
    "addr": "?",
    "auid": "1000",
    "exe": "/usr/sbin/userdel",
    "hostname": "?",
    "op": "deleting",
    "pid": "2901",
    "res": "success",
    "ses": "1",
    "subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=DEL_GROUP msg=audit(1781634271.403:539258): pid=2901 uid=0 auid=1000 ses=1 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=deleting group acct=\"r3usr\" exe=\"/usr/sbin/userdel\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"debian\""
  ],
  "record_type": "DEL_GROUP"
}

DAC_CHECK msgtype 1118

#
Message type
1118
Fires
Emitted by default (no audit rule required)

Description

User space DAC check results

CHGRP_ID msgtype 1119

#
Message type
1119
Fires
Emitted by default (no audit rule required)

Description

User space group ID changed

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "1000",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "pid": "28679",
    "res": "success",
    "ses": "1",
    "subj": "unconfined",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=CHGRP_ID msg=audit(1781630189.242:1259446): pid=28679 uid=0 auid=1000 ses=1 subj=unconfined msg='chgrp-test-verify exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"debian\""
  ],
  "record_type": "CHGRP_ID"
}

TEST msgtype 1120

#
Message type
1120
Fires
Emitted by default (no audit rule required)

Description

Used for test success messages

TRUSTED_APP msgtype 1121

#
Message type
1121
Fires
Emitted by default (no audit rule required)

Description

Trusted app msg - freestyle text

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)
opthe operation being performed that is audited

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "1000",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "op": "catalog-sample",
    "pid": "51615",
    "res": "success",
    "ses": "15",
    "subj": "unconfined",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=TRUSTED_APP msg=audit(1781632421.163:1883922): pid=51615 uid=0 auid=1000 ses=15 subj=unconfined msg='op=catalog-sample trusted-app exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'"
  ],
  "record_type": "TRUSTED_APP"
}

USER_SELINUX_ERR msgtype 1122

#
Message type
1122
Fires
Emitted by default (no audit rule required)

Description

SELinux user space error

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

USER_CMD msgtype 1123

#
Message type
1123
Fires
Emitted by default (no audit rule required)

Description

User shell command and args

Fields #

NameDescription
pidProcess ID
uidUser ID
auidAudit user ID (login UID)
sesSession ID
subjSELinux security context of the subject
cwdCurrent working directory when the command ran
cmdCommand that was executed
exeExecutable that ran the command (sudo)
terminalTerminal
resResult (success or failed)

Example Audit Record #

{
  "fields": {
    "auid": "4294967295",
    "cmd": "6A757079746572206C6162202D2D5365727665724170702E616C6C6F775F72656D6F74655F6163636573733D74727565202D2D5365727665724170702E6F70656E5F62726F777365723D66616C7365202D2D4964656E7469747950726F76696465722E746F6B656E3D6D7974686963202D2D5365727665724170702E626173655F75726C3D2F6A757079746572202D2D5365727665724170702E64656661756C745F75726C3D2F6A757079746572202D2D706F72743D38383838202D2D69703D302E302E302E30",
    "cwd": "/projects",
    "exe": "/usr/bin/sudo",
    "pid": "2759",
    "res": "success",
    "ses": "4294967295",
    "subj": "system_u:system_r:initrc_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=USER_CMD msg=audit(1781634264.630:525243): pid=2759 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:initrc_t:s0 msg='cwd=\"/projects\" cmd=6A757079746572206C6162202D2D5365727665724170702E616C6C6F775F72656D6F74655F6163636573733D74727565202D2D5365727665724170702E6F70656E5F62726F777365723D66616C7365202D2D4964656E7469747950726F76696465722E746F6B656E3D6D7974686963202D2D5365727665724170702E626173655F75726C3D2F6A757079746572202D2D5365727665724170702E64656661756C745F75726C3D2F6A757079746572202D2D706F72743D38383838202D2D69703D302E302E302E30 exe=\"/usr/bin/sudo\" terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "USER_CMD"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
typeinuser_cmd2 rulessplunk
typeincred_acq1 rulesplunk
typeinexecve1 rulesplunk
typeinproctitle1 rulesplunk
typeinuser_acct1 rulesplunk
CommandLinecontains.sh1 rulesplunk
CommandLinecontainslist1 rulesplunk
exein/usr/bin/sudo1 rulesplunk

USER_TTY msgtype 1124

#
Message type
1124
Fires
Emitted by default (no audit rule required)

Description

Non-ICANON TTY input meaning

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
dataTTY text

Example Audit Record #

{
  "fields": {
    "auid": "1000",
    "data": "7375202D20616E647265775F6B726F68",
    "pid": "28058",
    "ses": "762",
    "subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
    "uid": "0"
  },
  "raw": [
    "type=USER_TTY msg=audit(1491922681.082:1065050): pid=28058 uid=0 auid=1000 ses=762 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 data=7375202D20616E647265775F6B726F68"
  ],
  "record_type": "USER_TTY"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
nameeq/etc/pam.d/system-auth1 rulesigma
typeeqpath1 rulesigma

CHUSER_ID msgtype 1125

#
Message type
1125
Fires
Emitted by default (no audit rule required)

Description

Changed user ID supplemental data

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

GRP_AUTH msgtype 1126

#
Message type
1126
Fires
Emitted by default (no audit rule required)

Description

Authentication for group password

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "1000",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "pid": "28917",
    "res": "success",
    "ses": "1",
    "subj": "unconfined",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=GRP_AUTH msg=audit(1781630215.758:1267010): pid=28917 uid=0 auid=1000 ses=1 subj=unconfined msg='grp-auth-test exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"debian\""
  ],
  "record_type": "GRP_AUTH"
}

SYSTEM_BOOT msgtype 1127

#
Message type
1127
Fires
Emitted by default (no audit rule required)

Description

System boot

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
commcommand line program name
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "4294967295",
    "comm": "systemd-update-utmp",
    "exe": "/usr/lib/systemd/systemd-update-utmp",
    "hostname": "?",
    "pid": "500",
    "res": "success",
    "ses": "4294967295",
    "subj": "system_u:system_r:initrc_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=SYSTEM_BOOT msg=audit(1781634166.940:1739): pid=500 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:initrc_t:s0 msg=' comm=\"systemd-update-utmp\" exe=\"/usr/lib/systemd/systemd-update-utmp\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "SYSTEM_BOOT"
}

SYSTEM_SHUTDOWN msgtype 1128

#
Message type
1128
Fires
Emitted by default (no audit rule required)

Description

System shutdown

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
commcommand line program name
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "4294967295",
    "comm": "systemd-update-utmp",
    "exe": "/usr/lib/systemd/systemd-update-utmp",
    "hostname": "?",
    "pid": "1261",
    "res": "success",
    "ses": "4294967295",
    "subj": "unconfined",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=SYSTEM_SHUTDOWN msg=audit(1781627515.990:129066): pid=1261 uid=0 auid=4294967295 ses=4294967295 subj=unconfined msg=' comm=\"systemd-update-utmp\" exe=\"/usr/lib/systemd/systemd-update-utmp\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "SYSTEM_SHUTDOWN"
}

SYSTEM_RUNLEVEL msgtype 1129

#
Message type
1129
Fires
Emitted by default (no audit rule required)

Description

System runlevel change

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
old-levelprevious system runlevel
new-levelnew system runlevel
commcommand line program name
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "4294967295",
    "comm": "systemd-update-utmp",
    "exe": "/usr/lib/systemd/systemd-update-utmp",
    "hostname": "?",
    "new-level": "5",
    "old-level": "N",
    "pid": "3722",
    "res": "success",
    "ses": "4294967295",
    "subj": "system_u:system_r:initrc_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=SYSTEM_RUNLEVEL msg=audit(1781634283.021:560212): pid=3722 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:initrc_t:s0 msg='old-level=N new-level=5 comm=\"systemd-update-utmp\" exe=\"/usr/lib/systemd/systemd-update-utmp\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "SYSTEM_RUNLEVEL"
}

SERVICE_START msgtype 1130

#
Message type
1130
Fires
Emitted by default (no audit rule required)

Description

Service (daemon) start

Fields #

NameDescription
pidProcess ID of the service manager
uidUser ID
auidAudit user ID (login UID)
sesSession ID
unitName of the service unit started
commCommand name of the service manager
exeExecutable of the service manager
hostnameHostname
addrNetwork address
terminalTerminal
resResult (success or failed)
subjlspp subject's context string

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "4294967295",
    "comm": "systemd",
    "exe": "/usr/lib/systemd/systemd",
    "hostname": "?",
    "pid": "1",
    "res": "success",
    "ses": "4294967295",
    "subj": "system_u:system_r:init_t:s0",
    "terminal": "?",
    "uid": "0",
    "unit": "auditd"
  },
  "raw": [
    "node=JD-debian-12-workstation type=SERVICE_START msg=audit(1781634257.778:513027): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='unit=auditd comm=\"systemd\" exe=\"/usr/lib/systemd/systemd\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "SERVICE_START"
}

SERVICE_STOP msgtype 1131

#
Message type
1131
Fires
Emitted by default (no audit rule required)

Description

Service (daemon) stop

Fields #

NameDescriptionRules
pidProcess ID of the service manager
uidUser ID
auidAudit user ID (login UID)
sesSession ID
unitName of the service unit stopped8 detection rules
commCommand name of the service manager
exeExecutable of the service manager
hostnameHostname
addrNetwork address
terminalTerminal
resResult (success or failed)
subjlspp subject's context string

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "4294967295",
    "comm": "systemd",
    "exe": "/usr/lib/systemd/systemd",
    "hostname": "?",
    "pid": "1",
    "res": "success",
    "ses": "4294967295",
    "subj": "system_u:system_r:init_t:s0",
    "terminal": "?",
    "uid": "0",
    "unit": "systemd-update-utmp-runlevel"
  },
  "raw": [
    "node=JD-debian-12-workstation type=SERVICE_STOP msg=audit(1781634283.045:560313): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='unit=systemd-update-utmp-runlevel comm=\"systemd\" exe=\"/usr/lib/systemd/systemd\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "SERVICE_STOP"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
typeeqservice_stop7 rulessigma, splunk
dc_hostlt31 rulesplunk

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Splunk #

  • Linux Auditd Auditd Service Stop source: The following analytic detects the suspicious auditd service stop. This behavior is critical for a SOC to monitor because it may indicate attempts to gain unauthorized access or maintain control over a system. Such actions could be signs…T1489
  • Linux Auditd Disable Or Modify System Firewall source: The following analytic detects the suspicious disable or modify system firewall. This behavior is critical for a SOC to monitor because it may indicate attempts to gain unauthorized access or maintain control over a system. Such actions…T1686
  • Linux Auditd Osquery Service Stop source: The following analytic detects suspicious stopping of the osquery service, which may indicate an attempt to disable monitoring and evade detection. Osquery is a powerful tool used for querying system information and detecting…T1489

GRP_MGMT msgtype 1132

#
Message type
1132
Fires
Emitted by default (no audit rule required)

Description

Group account attribute was modified

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)
opthe operation being performed that is audited

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "4294967295",
    "exe": "/usr/sbin/groupadd",
    "hostname": "?",
    "id": "1000",
    "op": "add-shadow-group",
    "pid": "1235",
    "res": "success",
    "ses": "4294967295",
    "subj": "system_u:system_r:unconfined_service_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "type=GRP_MGMT msg=audit(1481076992.419:386): pid=1235 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:unconfined_service_t:s0 msg='op=add-shadow-group id=1000 exe=\"/usr/sbin/groupadd\" hostname=? addr=? terminal=? res=success'"
  ],
  "record_type": "GRP_MGMT"
}

Example keys not documented in the fields table: id

GRP_CHAUTHTOK msgtype 1133

#
Message type
1133
Fires
Emitted by default (no audit rule required)

Description

Group account password or PIN changed

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "1000",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "pid": "28917",
    "res": "success",
    "ses": "1",
    "subj": "unconfined",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=GRP_CHAUTHTOK msg=audit(1781630215.758:1267003): pid=28917 uid=0 auid=1000 ses=1 subj=unconfined msg='grp-chauthtok-test exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"debian\""
  ],
  "record_type": "GRP_CHAUTHTOK"
}

MAC_CHECK msgtype 1134

#
Message type
1134
Fires
Emitted by default (no audit rule required)

Description

User space MAC (Mandatory Access Control) decision results

ACCT_LOCK msgtype 1135

#
Message type
1135
Fires
Emitted by default (no audit rule required)

Description

User's account locked by admin

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "1000",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "pid": "29132",
    "res": "success",
    "ses": "1",
    "subj": "unconfined",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=ACCT_LOCK msg=audit(1781630235.907:1273935): pid=29132 uid=0 auid=1000 ses=1 subj=unconfined msg='acct-lock-test exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"debian\""
  ],
  "record_type": "ACCT_LOCK"
}

ACCT_UNLOCK msgtype 1136

#
Message type
1136
Fires
Emitted by default (no audit rule required)

Description

User's account unlocked by admin

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "1000",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "pid": "29132",
    "res": "success",
    "ses": "1",
    "subj": "unconfined",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=ACCT_UNLOCK msg=audit(1781630235.907:1273942): pid=29132 uid=0 auid=1000 ses=1 subj=unconfined msg='acct-unlock-test exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"debian\""
  ],
  "record_type": "ACCT_UNLOCK"
}

USER_DEVICE msgtype 1137

#
Message type
1137
Fires
Emitted by default (no audit rule required)

Description

User space hotplug device changes

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe device authorization action (inserted-device, removed-device, changed-authorization-state-for, discovered-device)
devicethe sysfs path of the USB device
device_rulehex-encoded usbguard rule describing the device (id, serial, name, hash, interface)
exethe daemon that emitted the record (usbguard-daemon)
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "4294967295",
    "device": "/devices/pci0000:00/0000:00:01.2/usb1/1-2/1-2.3",
    "device_rule": "626C6F636B20696420303632373A303030312073657269616C202238393132362D303030303A30303A30312E322D322E3322206E616D65202251454D5520555342204D6F75736522206861736820224A374576465164306F64682F636266675037566C364B714E6B66344953393449756E30734D64464655504D3D2220706172656E742D6861736820226144645272436B6B6C486E41737A485378755953704834456E7349442F6C745341477373564C68765478733D22207669612D706F72742022312D322E332220776974682D696E746572666163652030333A30313A303220776974682D636F6E6E6563742D747970652022756E6B6E6F776E22",
    "exe": "/usr/sbin/usbguard-daemon",
    "hostname": "?",
    "op": "inserted-device",
    "pid": "2297",
    "res": "success",
    "ses": "4294967295",
    "subj": "system_u:system_r:init_t:s0-s15:c0.c1023",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=localhost type=USER_DEVICE msg=audit(1782740627.120:433): pid=2297 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0-s15:c0.c1023 msg='op=\"inserted-device\" device=\"/devices/pci0000:00/0000:00:01.2/usb1/1-2/1-2.3\" device_rule=626C6F636B20696420303632373A303030312073657269616C202238393132362D303030303A30303A30312E322D322E3322206E616D65202251454D5520555342204D6F75736522206861736820224A374576465164306F64682F636266675037566C364B714E6B66344953393449756E30734D64464655504D3D2220706172656E742D6861736820226144645272436B6B6C486E41737A485378755953704834456E7349442F6C745341477373564C68765478733D22207669612D706F72742022312D322E332220776974682D696E746572666163652030333A30313A303220776974682D636F6E6E6563742D747970652022756E6B6E6F776E22 exe=\"/usr/sbin/usbguard-daemon\" hostname=? addr=? terminal=? res=success'"
  ],
  "record_type": "USER_DEVICE"
}

SOFTWARE_UPDATE msgtype 1138

#
Message type
1138
Fires
Emitted by default (no audit rule required)

Description

Software update event

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe package operation (install, update, remove)
swthe full package NEVRA (name-epoch:version-release.arch) being installed, updated, or removed
sw_typethe package-management backend that emitted the record (currently always rpm)
key_enforcewhether package-signature enforcement was active
gpg_resGPG signature verification result
root_dirroot directory the update applied to
commthe package-manager command that ran the transaction
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "1000",
    "comm": "rpm",
    "exe": "/usr/bin/rpm",
    "gpg_res": "0",
    "hostname": "?",
    "key_enforce": "0",
    "op": "install",
    "pid": "803140",
    "res": "success",
    "root_dir": "/",
    "ses": "241",
    "subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
    "sw": "dwh-probe-1.0-1.noarch",
    "sw_type": "rpm",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=linux-audit-host type=SOFTWARE_UPDATE msg=audit(1783637823.949:22539443): pid=803140 uid=0 auid=1000 ses=241 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=install sw=\"dwh-probe-1.0-1.noarch\" sw_type=rpm key_enforce=0 gpg_res=0 root_dir=\"/\" comm=\"rpm\" exe=\"/usr/bin/rpm\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"labuser\""
  ],
  "record_type": "SOFTWARE_UPDATE"
}

DAEMON_START msgtype 1200

#
Message type
1200
Fires
Emitted by default (no audit rule required)

Description

Daemon startup record

Fields #

NameDescription
opthe operation being performed that is audited
veraudit daemon's version number
formataudit log's format
kernelkernel's version number
auidlogin user ID
pidprocess ID
uiduser ID
seslogin session ID
subjlspp subject's context string
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "auid": "4294967295",
    "format": "enriched",
    "kernel": "6.1.0-44-amd64",
    "op": "start",
    "pid": "2322",
    "res": "success",
    "ses": "4294967295",
    "subj": "system_u:system_r:auditd_t:s0",
    "uid": "0",
    "ver": "3.0.9"
  },
  "raw": [
    "node=JD-debian-12-workstation type=DAEMON_START msg=audit(1781634257.573:708): op=start ver=3.0.9 format=enriched kernel=6.1.0-44-amd64 auid=4294967295 pid=2322 uid=0 ses=4294967295 subj=system_u:system_r:auditd_t:s0 res=success",
    "AUID=\"unset\" UID=\"root\""
  ],
  "record_type": "DAEMON_START"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

  • Linux Auditd Auditd Daemon Start source: The following analytic detects the (re)initialization of the Linux audit daemon (auditd) by identifying log entries of type DAEMON_START. This event indicates that the audit subsystem has resumed logging after being stopped or has started…T1685, T1685.004

DAEMON_END msgtype 1201

#
Message type
1201
Fires
Emitted by default (no audit rule required)

Description

Daemon normal stop record

Fields #

NameDescription
opthe operation being performed that is audited
auidlogin user ID
uiduser ID
seslogin session ID
pidprocess ID
subjlspp subject's context string
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "auid": "-1",
    "op": "terminate",
    "pid": "-1",
    "res": "success",
    "ses": "-1",
    "subj": "?",
    "uid": "-1"
  },
  "raw": [
    "node=JD-debian-12-workstation type=DAEMON_END msg=audit(1781634206.873:8602): op=terminate auid=-1 uid=-1 ses=-1 pid=-1 subj=? res=success",
    "AUID=\"unset\" UID=\"unset\""
  ],
  "record_type": "DAEMON_END"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

  • Linux Auditd Auditd Daemon Shutdown source: The following analytic detects the unexpected termination of the Linux Audit daemon (auditd) by monitoring for log entries of type DAEMON_END. This event signifies that the audit logging service has stopped, either due to a legitimate…T1685, T1685.004

DAEMON_ABORT msgtype 1202

#
Message type
1202
Fires
Emitted by default (no audit rule required)

Description

Daemon error stop record

Fields #

NameDescription
opthe operation being performed that is audited
auidlogin user ID
pidprocess ID
uiduser ID
seslogin session ID
subjlspp subject's context string
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "auid": "0",
    "op": "set-pid",
    "pid": "791",
    "res": "failed",
    "ses": "12",
    "subj": "unconfined",
    "uid": "0"
  },
  "raw": [
    "node=dw-disposable-vm type=DAEMON_ABORT msg=audit(1781731230.798:3442): op=set-pid auid=0 pid=791 uid=0 ses=12 subj=unconfined  res=failed",
    "AUID=\"root\" UID=\"root\""
  ],
  "record_type": "DAEMON_ABORT"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

  • Linux Auditd Auditd Daemon Abort source: The following analytic detects the abnormal termination of the Linux audit daemon (auditd) by identifying DAEMON_ABORT events in audit logs. These terminations suggest a serious failure of the auditing subsystem, potentially due to…T1685, T1685.004

DAEMON_CONFIG msgtype 1203

#
Message type
1203
Fires
Emitted by default (no audit rule required)

Description

Daemon config change

Fields #

NameDescription
opthe operation being performed that is audited
stateaudit daemon configuration resulting state
auidlogin user ID
uiduser ID
seslogin session ID
pidprocess ID
subjlspp subject's context string
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "auid": "1000",
    "op": "reconfigure",
    "pid": "51449",
    "res": "success",
    "state": "changed",
    "subj": "unconfined"
  },
  "raw": [
    "node=JD-debian-12-workstation type=DAEMON_CONFIG msg=audit(1781632421.227:3346): op=reconfigure state=changed auid=1000 pid=51449 subj=unconfined res=success",
    "AUID=\"debian\""
  ],
  "record_type": "DAEMON_CONFIG"
}

DAEMON_ROTATE msgtype 1205

#
Message type
1205
Fires
Emitted by default (no audit rule required)

Description

Auditd should rotate logs

Fields #

NameDescription
opthe operation being performed that is audited
auidlogin user ID
uiduser ID
seslogin session ID
pidprocess ID
subjlspp subject's context string
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "auid": "1000",
    "op": "rotate-logs",
    "pid": "51449",
    "res": "success",
    "ses": "15",
    "subj": "unconfined",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=DAEMON_ROTATE msg=audit(1781632422.224:77): op=rotate-logs auid=1000 uid=0 ses=15 pid=51449 subj=unconfined res=success",
    "AUID=\"debian\" UID=\"root\""
  ],
  "record_type": "DAEMON_ROTATE"
}

DAEMON_RESUME msgtype 1206

#
Message type
1206
Fires
Emitted by default (no audit rule required)

Description

Auditd should resume logging

Fields #

NameDescription
opthe operation being performed that is audited
auidlogin user ID
uiduser ID
seslogin session ID
pidprocess ID
subjlspp subject's context string
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "auid": "1000",
    "op": "resume-logging",
    "pid": "109949",
    "res": "success",
    "ses": "90",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=DAEMON_RESUME msg=audit(1781719930.237:7502): op=resume-logging auid=1000 uid=0 ses=90 pid=109949 res=success",
    "AUID=\"debian\" UID=\"root\""
  ],
  "record_type": "DAEMON_RESUME"
}

DAEMON_ACCEPT msgtype 1207

#
Message type
1207
Fires
Emitted by default (no audit rule required)

Description

Auditd accepted remote connection

Fields #

NameDescription
opthe operation being performed that is audited
addrthe remote address that the user is connecting from
portremote port of the audit connection
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "::ffff:127.0.0.1",
    "port": "37074",
    "res": "success"
  },
  "raw": [
    "node=JD-debian-12-workstation type=DAEMON_ACCEPT msg=audit(1781635296.535:3244): addr=::ffff:127.0.0.1 port=37074 res=success"
  ],
  "record_type": "DAEMON_ACCEPT"
}

DAEMON_CLOSE msgtype 1208

#
Message type
1208
Fires
Emitted by default (no audit rule required)

Description

Auditd closed remote connection

Fields #

NameDescription
addrthe remote address that the user is connecting from
portremote port of the audit connection
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "::ffff:127.0.0.1",
    "port": "57858",
    "res": "success"
  },
  "raw": [
    "node=JD-debian-12-workstation type=DAEMON_CLOSE msg=audit(1781641212.864:8400): addr=::ffff:127.0.0.1 port=57858 res=success"
  ],
  "record_type": "DAEMON_CLOSE"
}

DAEMON_ERR msgtype 1209

#
Message type
1209
Fires
Emitted by default (no audit rule required)

Description

Auditd internal error

Fields #

NameDescription
opthe operation being performed that is audited
resresult of the audited operation(success/fail)

SYSCALL msgtype 1300

#
Message type
1300
Fires
Requires a loaded audit rule

Description

System call event information

How it fires #

This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:

-a always,exit -F arch=b64 -S execve -k exec

Fields #

NameDescriptionRules
archCPU architecture (e.g. c000003e for x86_64)
syscallSystem call number2 detection rules
successWhether the syscall succeeded (yes or no)2 detection rules
exitExit value or errno of the syscall
a0First argument to the syscall (hex)10 detection rules
a1Second argument to the syscall (hex)
a2Third argument to the syscall (hex)
a3Fourth argument to the syscall (hex)
itemsNumber of PATH records attached to this event
ppidParent process ID
pidProcess ID
auidAudit user ID (login UID)
uidUser ID3 detection rules
gidGroup ID
euidEffective user ID1 detection rule
suidSaved set-user-ID
fsuidFile system user ID
egidEffective group ID
sgidSaved set-group-ID
fsgidFile system group ID
ttyTerminal associated with the process
sesSession ID
commCommand name of the process28 detection rules
exeExecutable path of the process71 detection rules
subjlspp subject's context string
keyAudit rule key that triggered this record8 detection rules

Example Audit Record #

{
  "fields": {
    "a0": "2442de3bf7e8",
    "a1": "2442dd0f4cb0",
    "a2": "2442dd889e60",
    "a3": "0",
    "arch": "c000003e",
    "auid": "4294967295",
    "comm": "iptables",
    "egid": "0",
    "euid": "0",
    "exe": "/usr/sbin/xtables-nft-multi",
    "exit": "0",
    "fsgid": "0",
    "fsuid": "0",
    "gid": "0",
    "items": "2",
    "key": "T1059_exec",
    "pid": "2407",
    "ppid": "671",
    "ses": "4294967295",
    "sgid": "0",
    "subj": "system_u:system_r:iptables_t:s0",
    "success": "yes",
    "suid": "0",
    "syscall": "59",
    "tty": "(none)",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=SYSCALL msg=audit(1781634257.762:512605): arch=c000003e syscall=59 success=yes exit=0 a0=2442de3bf7e8 a1=2442dd0f4cb0 a2=2442dd889e60 a3=0 items=2 ppid=671 pid=2407 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=\"iptables\" exe=\"/usr/sbin/xtables-nft-multi\" subj=system_u:system_r:iptables_t:s0 key=\"T1059_exec\"",
    "ARCH=x86_64 SYSCALL=execve AUID=\"unset\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
    "node=JD-debian-12-workstation type=EXECVE msg=audit(1781634257.762:512605): argc=13 a0=\"/usr/sbin/iptables\" a1=\"--wait\" a2=\"-t\" a3=\"raw\" a4=\"-C\" a5=\"PREROUTING\" a6=\"-d\" a7=\"172.18.0.6\" a8=\"!\" a9=\"-i\" a10=\"br-440f323861ca\" a11=\"-j\" a12=\"DROP\"",
    "node=JD-debian-12-workstation type=CWD msg=audit(1781634257.762:512605): cwd=\"/\"",
    "node=JD-debian-12-workstation type=PATH msg=audit(1781634257.762:512605): item=0 name=\"/usr/sbin/iptables\" inode=5537074 dev=fe:01 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:iptables_exec_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
    "OUID=\"root\" OGID=\"root\"",
    "node=JD-debian-12-workstation type=PATH msg=audit(1781634257.762:512605): item=1 name=\"/lib64/ld-linux-x86-64.so.2\" inode=5505708 dev=fe:01 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:ld_so_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
    "OUID=\"root\" OGID=\"root\"",
    "node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781634257.762:512605): proctitle=2F7573722F7362696E2F69707461626C6573002D2D77616974002D7400726177002D4300505245524F5554494E47002D64003137322E31382E302E360021002D690062722D343430663332333836316361002D6A0044524F50"
  ],
  "record_type": "SYSCALL"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
typeeqsyscall26 rulessigma, splunk
typeeqexecve2 rulessigma
typeeqadd_user1 rulesigma
commeqinsmod2 rulessigma, splunk
commeqsplit2 rulessigma, splunk
exein/usr/bin/sudo1 rulesplunk
uidne01 rulesplunk
usereqroot1 rulesplunk

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Splunk #

  • Linux Auditd At Application Execution source: The following analytic detects the execution of the "At" application in Linux, which can be used by attackers to create persistence entries on a compromised host. This detection leverages data from Endpoint Detection and Response (EDR)…T1053, T1053.002
  • Linux Auditd Copy Fail Privilege Escalation source: Detects the exploitation pattern associated with Copy Fail. Copy Fail (CVE-2026-31431) is a logic bug in the Linux kernel's authentication cryptographic template. It lets an unprivileged local user trigger a deterministic, controlled…T1068
  • Linux Auditd Data Transfer Size Limits Via Split Syscall source: The following analytic detects suspicious data transfer activities that involve the use of the split syscall, potentially indicating an attempt to evade detection by breaking large files into smaller parts. Attackers may use this…T1030

References #

PATH msgtype 1302

#
Message type
1302
Fires
Requires a loaded audit rule

Description

Filename path information

How it fires #

This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:

-w /etc/passwd -p wa -k identity

Fields #

NameDescriptionRules
itemItem number in the PATH record sequence
nameFile or directory path73 detection rules
inodeInode number of the file
devDevice identifier
modeFile permission mode (octal)
ouidOwner user ID of the file
ogidOwner group ID of the file
rdevDevice identifier for special files
objlspp object context string
nametypeType of path operation (NORMAL, CREATE, DELETE, etc.)6 detection rules
cap_fpfile permitted capability map
cap_fifile inherited capability map
cap_fefile assigned effective capability map
cap_fverfile system capabilities version number
cap_frootidroot user ID namespace owner of the file capability set

Example Audit Record #

{
  "fields": {
    "cap_fe": "0",
    "cap_fi": "0",
    "cap_fp": "0",
    "cap_frootid": "0",
    "cap_fver": "0",
    "dev": "fe:01",
    "inode": "5537074",
    "item": "0",
    "mode": "0100755",
    "name": "/usr/sbin/iptables",
    "nametype": "NORMAL",
    "obj": "system_u:object_r:iptables_exec_t:s0",
    "ogid": "0",
    "ouid": "0",
    "rdev": "00:00"
  },
  "raw": [
    "node=JD-debian-12-workstation type=SYSCALL msg=audit(1781634257.762:512605): arch=c000003e syscall=59 success=yes exit=0 a0=2442de3bf7e8 a1=2442dd0f4cb0 a2=2442dd889e60 a3=0 items=2 ppid=671 pid=2407 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=\"iptables\" exe=\"/usr/sbin/xtables-nft-multi\" subj=system_u:system_r:iptables_t:s0 key=\"T1059_exec\"",
    "ARCH=x86_64 SYSCALL=execve AUID=\"unset\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
    "node=JD-debian-12-workstation type=EXECVE msg=audit(1781634257.762:512605): argc=13 a0=\"/usr/sbin/iptables\" a1=\"--wait\" a2=\"-t\" a3=\"raw\" a4=\"-C\" a5=\"PREROUTING\" a6=\"-d\" a7=\"172.18.0.6\" a8=\"!\" a9=\"-i\" a10=\"br-440f323861ca\" a11=\"-j\" a12=\"DROP\"",
    "node=JD-debian-12-workstation type=CWD msg=audit(1781634257.762:512605): cwd=\"/\"",
    "node=JD-debian-12-workstation type=PATH msg=audit(1781634257.762:512605): item=0 name=\"/usr/sbin/iptables\" inode=5537074 dev=fe:01 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:iptables_exec_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
    "OUID=\"root\" OGID=\"root\"",
    "node=JD-debian-12-workstation type=PATH msg=audit(1781634257.762:512605): item=1 name=\"/lib64/ld-linux-x86-64.so.2\" inode=5505708 dev=fe:01 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:ld_so_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
    "OUID=\"root\" OGID=\"root\"",
    "node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781634257.762:512605): proctitle=2F7573722F7362696E2F69707461626C6573002D2D77616974002D7400726177002D4300505245524F5554494E47002D64003137322E31382E302E360021002D690062722D343430663332333836316361002D6A0044524F50"
  ],
  "record_type": "PATH"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
typeeqpath19 rulessigma, splunk
typeeqcwd7 rulessplunk
typeeqexecve2 rulessigma
match_countgt07 rulessplunk
nameeq/etc/issue2 rulessigma
nameeq/etc/pam.d/system-auth2 rulessigma
nametypeeqcreate2 rulessigma, splunk
a0eqhostname1 rulesigma
a0equname1 rulesigma

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

References #

IPC msgtype 1303

#
Message type
1303
Fires
Requires a loaded audit rule

Description

System call IPC (Inter-Process Communication) object

How it fires #

This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:

-a always,exit -F arch=b64 -S shmget,semget,msgget -k ipc

Fields #

NameDescription
ouidOwner user ID of the IPC object
ogidOwner group ID of the IPC object
modePermission mode of the IPC object
objSELinux context of the IPC object

Example Audit Record #

{
  "fields": {
    "mode": "0600",
    "ogid": "0",
    "ouid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=SYSCALL msg=audit(1781632713.732:2113093): arch=c000003e syscall=66 success=yes exit=0 a0=0 a1=0 a2=10 a3=7fff00000001 items=0 ppid=56702 pid=56740 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=15 comm=\"cryptsetup\" exe=\"/usr/sbin/cryptsetup\" subj=unconfined key=\"cat_ipc\"",
    "ARCH=x86_64 SYSCALL=semctl AUID=\"debian\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
    "node=JD-debian-12-workstation type=IPC msg=audit(1781632713.732:2113093): ouid=0 ogid=0 mode=0600",
    "OUID=\"root\" OGID=\"root\"",
    "node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781632713.732:2113093): proctitle=63727970747365747570006C756B734F70656E002F746D702F7232622F6C756B736261636B00636174616C6F676C756B73002D"
  ],
  "record_type": "IPC"
}

References #

SOCKETCALL msgtype 1304

#
Message type
1304
Fires
Requires a loaded audit rule

Description

System call socketcall arguments

How it fires #

This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:

-a always,exit -F arch=b32 -S socketcall -k net

Fields #

NameDescription
nargsNumber of arguments to the socket call
a0First argument (hex)
a1Second argument (hex)
a2Third argument (hex)
a3argument to the syscall (hex)
a4argument to the syscall (hex)
a5argument to the syscall (hex)

Example Audit Record #

{
  "fields": {
    "a0": "3",
    "a1": "ffde5b9c",
    "a2": "10",
    "nargs": "3"
  },
  "raw": [
    "node=JD-debian-12-workstation type=SYSCALL msg=audit(1781731984.980:1214350): arch=40000003 syscall=102 success=no exit=-111 a0=3 a1=ffde5b60 a2=0 a3=eafe1ff4 items=0 ppid=37557 pid=37579 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=48 comm=\"sock32\" exe=\"/tmp/recap/sock32\" subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key=\"sockcap\"",
    "ARCH=i386 SYSCALL=socketcall(connect) AUID=\"debian\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
    "node=JD-debian-12-workstation type=SOCKETCALL msg=audit(1781731984.980:1214350): nargs=3 a0=3 a1=ffde5b9c a2=10",
    "node=JD-debian-12-workstation type=SOCKADDR msg=audit(1781731984.980:1214350): saddr=020000097F0000010000000000000000",
    "SADDR={ saddr_fam=inet laddr=127.0.0.1 lport=9 }",
    "node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781731984.980:1214350): proctitle=\"/tmp/recap/sock32\""
  ],
  "record_type": "SOCKETCALL"
}

References #

CONFIG_CHANGE msgtype 1305

#
Message type
1305
Fires
Emitted by default (no audit rule required)

Description

Audit system configuration change

Fields #

NameDescription
auidAudit user ID (login UID) that made the change
sesSession ID
subjlspp subject's context string
opOperation performed (e.g. add_rule, remove_rule)
keyAudit rule key associated with the change
listAudit rule list affected
resResult of the operation (1 for success, 0 for failure)

Example Audit Record #

{
  "fields": {
    "auid": "4294967295",
    "key": "T1562_audit_log_tamper",
    "list": "4",
    "op": "remove_rule",
    "res": "1",
    "ses": "4294967295",
    "subj": "system_u:system_r:auditctl_t:s0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=CONFIG_CHANGE msg=audit(1781634257.694:511157): auid=4294967295 ses=4294967295 subj=system_u:system_r:auditctl_t:s0 op=remove_rule key=\"T1562_audit_log_tamper\" list=4 res=1",
    "AUID=\"unset\"",
    "node=JD-debian-12-workstation type=SYSCALL msg=audit(1781634257.694:511157): arch=c000003e syscall=44 success=yes exit=1092 a0=3 a1=7fff5edbde00 a2=444 a3=0 items=0 ppid=2328 pid=2390 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=\"auditctl\" exe=\"/usr/sbin/auditctl\" subj=system_u:system_r:auditctl_t:s0 key=\"T1071_data_transfer\"",
    "ARCH=x86_64 SYSCALL=sendto AUID=\"unset\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
    "node=JD-debian-12-workstation type=SOCKADDR msg=audit(1781634257.694:511157): saddr=100000000000000000000000",
    "SADDR={ saddr_fam=netlink nlnk-fam=16 nlnk-pid=0 }",
    "node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781634257.694:511157): proctitle=2F7362696E2F617564697463746C002D52002F6574632F61756469742F61756469742E72756C6573"
  ],
  "record_type": "CONFIG_CHANGE"
}

References #

SOCKADDR msgtype 1306

#
Message type
1306
Fires
Requires a loaded audit rule

Description

System call socket address argument information

How it fires #

This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:

-a always,exit -F arch=b64 -S connect,accept,bind -k net

Fields #

NameDescription
saddrSocket address structure (hex-encoded)

Example Audit Record #

{
  "fields": {
    "saddr": "100000000000000000000000"
  },
  "raw": [
    "node=JD-debian-12-workstation type=SYSCALL msg=audit(1781634257.690:510675): arch=c000003e syscall=45 success=yes exit=1092 a0=3 a1=7fff5edc2590 a2=231c a3=40 items=0 ppid=2328 pid=2390 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=\"auditctl\" exe=\"/usr/sbin/auditctl\" subj=system_u:system_r:auditctl_t:s0 key=\"T1071_data_transfer\"",
    "ARCH=x86_64 SYSCALL=recvfrom AUID=\"unset\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
    "node=JD-debian-12-workstation type=SOCKADDR msg=audit(1781634257.690:510675): saddr=100000000000000000000000",
    "SADDR={ saddr_fam=netlink nlnk-fam=16 nlnk-pid=0 }",
    "node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781634257.690:510675): proctitle=2F7362696E2F617564697463746C002D52002F6574632F61756469742F61756469742E72756C6573"
  ],
  "record_type": "SOCKADDR"
}

References #

CWD msgtype 1307

#
Message type
1307
Fires
Requires a loaded audit rule

Description

Current working directory

How it fires #

This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:

-a always,exit -F arch=b64 -S execve -k exec

Fields #

NameDescription
cwdCurrent working directory

Example Audit Record #

{
  "fields": {
    "cwd": "/"
  },
  "raw": [
    "node=JD-debian-12-workstation type=SYSCALL msg=audit(1781634257.762:512605): arch=c000003e syscall=59 success=yes exit=0 a0=2442de3bf7e8 a1=2442dd0f4cb0 a2=2442dd889e60 a3=0 items=2 ppid=671 pid=2407 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=\"iptables\" exe=\"/usr/sbin/xtables-nft-multi\" subj=system_u:system_r:iptables_t:s0 key=\"T1059_exec\"",
    "ARCH=x86_64 SYSCALL=execve AUID=\"unset\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
    "node=JD-debian-12-workstation type=EXECVE msg=audit(1781634257.762:512605): argc=13 a0=\"/usr/sbin/iptables\" a1=\"--wait\" a2=\"-t\" a3=\"raw\" a4=\"-C\" a5=\"PREROUTING\" a6=\"-d\" a7=\"172.18.0.6\" a8=\"!\" a9=\"-i\" a10=\"br-440f323861ca\" a11=\"-j\" a12=\"DROP\"",
    "node=JD-debian-12-workstation type=CWD msg=audit(1781634257.762:512605): cwd=\"/\"",
    "node=JD-debian-12-workstation type=PATH msg=audit(1781634257.762:512605): item=0 name=\"/usr/sbin/iptables\" inode=5537074 dev=fe:01 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:iptables_exec_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
    "OUID=\"root\" OGID=\"root\"",
    "node=JD-debian-12-workstation type=PATH msg=audit(1781634257.762:512605): item=1 name=\"/lib64/ld-linux-x86-64.so.2\" inode=5505708 dev=fe:01 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:ld_so_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
    "OUID=\"root\" OGID=\"root\"",
    "node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781634257.762:512605): proctitle=2F7573722F7362696E2F69707461626C6573002D2D77616974002D7400726177002D4300505245524F5554494E47002D64003137322E31382E302E360021002D690062722D343430663332333836316361002D6A0044524F50"
  ],
  "record_type": "CWD"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
match_countgt07 rulessplunk
typeeqcwd7 rulessplunk
typeeqpath7 rulessplunk
nametypeeqcreate1 rulesplunk

References #

EXECVE msgtype 1309

#
Message type
1309
Fires
Requires a loaded audit rule

Description

Arguments supplied to the execve system call

How it fires #

This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:

-a always,exit -F arch=b64 -S execve -k exec

Fields #

NameDescriptionRules
argcNumber of command-line arguments
a0First command-line argument (the program path)56 detection rules
a1Second command-line argument51 detection rules
a2Third command-line argument17 detection rules
a3Fourth command-line argument11 detection rules

Example Audit Record #

{
  "fields": {
    "a0": "/usr/sbin/iptables",
    "a1": "--wait",
    "a10": "br-440f323861ca",
    "a11": "-j",
    "a12": "DROP",
    "a2": "-t",
    "a3": "raw",
    "a4": "-C",
    "a5": "PREROUTING",
    "a6": "-d",
    "a7": "172.18.0.6",
    "a8": "!",
    "a9": "-i",
    "argc": "13"
  },
  "raw": [
    "node=JD-debian-12-workstation type=SYSCALL msg=audit(1781634257.762:512605): arch=c000003e syscall=59 success=yes exit=0 a0=2442de3bf7e8 a1=2442dd0f4cb0 a2=2442dd889e60 a3=0 items=2 ppid=671 pid=2407 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=\"iptables\" exe=\"/usr/sbin/xtables-nft-multi\" subj=system_u:system_r:iptables_t:s0 key=\"T1059_exec\"",
    "ARCH=x86_64 SYSCALL=execve AUID=\"unset\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
    "node=JD-debian-12-workstation type=EXECVE msg=audit(1781634257.762:512605): argc=13 a0=\"/usr/sbin/iptables\" a1=\"--wait\" a2=\"-t\" a3=\"raw\" a4=\"-C\" a5=\"PREROUTING\" a6=\"-d\" a7=\"172.18.0.6\" a8=\"!\" a9=\"-i\" a10=\"br-440f323861ca\" a11=\"-j\" a12=\"DROP\"",
    "node=JD-debian-12-workstation type=CWD msg=audit(1781634257.762:512605): cwd=\"/\"",
    "node=JD-debian-12-workstation type=PATH msg=audit(1781634257.762:512605): item=0 name=\"/usr/sbin/iptables\" inode=5537074 dev=fe:01 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:iptables_exec_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
    "OUID=\"root\" OGID=\"root\"",
    "node=JD-debian-12-workstation type=PATH msg=audit(1781634257.762:512605): item=1 name=\"/lib64/ld-linux-x86-64.so.2\" inode=5505708 dev=fe:01 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:ld_so_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
    "OUID=\"root\" OGID=\"root\"",
    "node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781634257.762:512605): proctitle=2F7573722F7362696E2F69707461626C6573002D2D77616974002D7400726177002D4300505245524F5554494E47002D64003137322E31382E302E360021002D690062722D343430663332333836316361002D6A0044524F50"
  ],
  "record_type": "EXECVE"
}

Example keys not documented in the fields table: a10, a11, a12, a4, a5, a6, a7, a8, a9

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
typeeqexecve37 rulessigma, splunk
typeeqproctitle6 rulessplunk
typeeqsyscall3 rulessigma, splunk
execve_commandin*find*7 rulessplunk
execve_commandin*grep*7 rulessplunk
a1ends_with.jpg3 rulessigma
a1ends_with.png3 rulessigma
a1eq-sel2 rulessigma
a1eq-selection2 rulessigma
a1eq/bin/sh2 rulessigma
a0eqcp2 rulessigma
a0eqhostname2 rulessigma
a0eqsteghide2 rulessigma
a0equname2 rulessigma
a0eqxclip2 rulessigma

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

  • Binary Padding - Linux source high: Adversaries may use binary padding to add junk data and change the on-disk representation of malware. This rule detect using dd and truncate to add a junk data to file.T1027, T1027.001
  • Bpfdoor TCP Ports Redirect source medium: All TCP traffic on particular port from attacker is routed to different port. ex. '/sbin/iptables -t nat -D PREROUTING -p tcp -s 192.168.1.1 --dport 22 -j REDIRECT --to-ports 42392' The traffic looks like encrypted SSH communications going to TCP port 22, but in reality is being directed to the shell port once it hits the iptables rule for the attacker host only.T1686
  • Linux Capabilities Discovery source low: Detects attempts to discover the files with setuid/setgid capability on them. That would allow adversary to escalate their privileges.T1083, T1548

Splunk #

  • Linux Auditd Base64 Decode Files source: The following analytic detects suspicious Base64 decode operations that may indicate malicious activity, such as data exfiltration or execution of encoded commands. Base64 is commonly used to encode data for safe transmission, but…T1140
  • Linux Auditd Clipboard Data Copy source: The following analytic detects the use of the Linux 'xclip' command to copy data from the clipboard. It leverages Linux Auditd telemetry, focusing on process names and command-line arguments related to clipboard operations. This activity…T1115
  • Linux Auditd Data Transfer Size Limits Via Split source: The following analytic detects suspicious data transfer activities that involve the use of the split syscall, potentially indicating an attempt to evade detection by breaking large files into smaller parts. Attackers may use this…T1030

References #

IPC_SET_PERM msgtype 1311

#
Message type
1311
Fires
Requires a loaded audit rule

Description

IPC new permissions record type

How it fires #

This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:

-a always,exit -F arch=b64 -S shmctl,semctl,msgctl -k ipc

Fields #

NameDescription
qbytesipc objects quantity of bytes
ouidfile owner user ID
ogidfile owner group ID
modeLandlock domain enforcement mode (enforcing)

Example Audit Record #

{
  "fields": {
    "mode": "0600",
    "ogid": "0",
    "ouid": "0",
    "qbytes": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=SYSCALL msg=audit(1781632420.555:1883815): arch=c000003e syscall=31 success=yes exit=0 a0=2 a1=1 a2=7f3361005c30 a3=10 items=0 ppid=51449 pid=51615 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=15 comm=\"python3\" exe=\"/usr/bin/python3.11\" subj=unconfined key=\"cat_ipc\"",
    "ARCH=x86_64 SYSCALL=shmctl AUID=\"debian\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
    "node=JD-debian-12-workstation type=IPC msg=audit(1781632420.555:1883815): ouid=0 ogid=0 mode=0600",
    "OUID=\"root\" OGID=\"root\"",
    "node=JD-debian-12-workstation type=IPC_SET_PERM msg=audit(1781632420.555:1883815): qbytes=0 ouid=0 ogid=0 mode=0600",
    "OUID=\"root\" OGID=\"root\"",
    "node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781632420.555:1883815): proctitle=707974686F6E33002F746D702F726F756E64322E7079"
  ],
  "record_type": "IPC_SET_PERM"
}

References #

MQ_OPEN msgtype 1312

#
Message type
1312
Fires
Requires a loaded audit rule

Description

POSIX MQ open record type

How it fires #

This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:

-a always,exit -F arch=b64 -S mq_open -k posixmq

Fields #

NameDescription
oflagopen syscall flags
modeLandlock domain enforcement mode (enforcing)
mq_flagsPOSIX message queue flags
mq_maxmsgmaximum number of messages on the POSIX message queue
mq_msgsizemaximum message size on the POSIX message queue
mq_curmsgscurrent number of messages on the POSIX message queue

Example Audit Record #

{
  "fields": {
    "mode": "0600",
    "mq_curmsgs": "0",
    "mq_flags": "0x0",
    "mq_maxmsg": "10",
    "mq_msgsize": "64",
    "oflag": "0x42"
  },
  "raw": [
    "node=JD-debian-12-workstation type=SYSCALL msg=audit(1781632420.559:1883818): arch=c000003e syscall=240 success=yes exit=3 a0=7f3360b29a61 a1=42 a2=180 a3=7f3360b2cb30 items=2 ppid=51449 pid=51615 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=15 comm=\"python3\" exe=\"/usr/bin/python3.11\" subj=unconfined key=\"cat_mq\"",
    "ARCH=x86_64 SYSCALL=mq_open AUID=\"debian\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
    "node=JD-debian-12-workstation type=MQ_OPEN msg=audit(1781632420.559:1883818): oflag=0x42 mode=0600 mq_flags=0x0 mq_maxmsg=10 mq_msgsize=64 mq_curmsgs=0",
    "node=JD-debian-12-workstation type=CWD msg=audit(1781632420.559:1883818): cwd=\"/home/debian\"",
    "node=JD-debian-12-workstation type=PATH msg=audit(1781632420.559:1883818): item=0 name=\"catalog_q2\" inode=264781 dev=00:13 mode=0100600 ouid=0 ogid=0 rdev=00:00 nametype=CREATE cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
    "OUID=\"root\" OGID=\"root\"",
    "node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781632420.559:1883818): proctitle=707974686F6E33002F746D702F726F756E64322E7079"
  ],
  "record_type": "MQ_OPEN"
}

References #

MQ_SENDRECV msgtype 1313

#
Message type
1313
Fires
Requires a loaded audit rule

Description

POSIX MQ send/receive record type

How it fires #

This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:

-a always,exit -F arch=b64 -S mq_timedsend,mq_timedreceive -k posixmq

Fields #

NameDescription
mqdesPOSIX message queue descriptor
msg_lenmessage length for the message-queue send or receive
msg_priomessage priority for the message-queue send or receive
abs_timeout_secabsolute timeout seconds for the message queue operation
abs_timeout_nsecabsolute timeout nanoseconds for the message queue operation

Example Audit Record #

{
  "fields": {
    "abs_timeout_nsec": "0",
    "abs_timeout_sec": "1781632422",
    "mqdes": "3",
    "msg_len": "18",
    "msg_prio": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=SYSCALL msg=audit(1781632420.559:1883819): arch=c000003e syscall=242 success=yes exit=0 a0=3 a1=7f3360b1b190 a2=12 a3=0 items=1 ppid=51449 pid=51615 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=15 comm=\"python3\" exe=\"/usr/bin/python3.11\" subj=unconfined key=\"cat_mq\"",
    "ARCH=x86_64 SYSCALL=mq_timedsend AUID=\"debian\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
    "node=JD-debian-12-workstation type=MQ_SENDRECV msg=audit(1781632420.559:1883819): mqdes=3 msg_len=18 msg_prio=0 abs_timeout_sec=1781632422 abs_timeout_nsec=0",
    "node=JD-debian-12-workstation type=CWD msg=audit(1781632420.559:1883819): cwd=\"/home/debian\"",
    "node=JD-debian-12-workstation type=PATH msg=audit(1781632420.559:1883819): item=0 name=(null) inode=264781 dev=00:13 mode=0100600 ouid=0 ogid=0 rdev=00:00 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
    "OUID=\"root\" OGID=\"root\"",
    "node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781632420.559:1883819): proctitle=707974686F6E33002F746D702F726F756E64322E7079"
  ],
  "record_type": "MQ_SENDRECV"
}

References #

MQ_NOTIFY msgtype 1314

#
Message type
1314
Fires
Requires a loaded audit rule

Description

POSIX MQ notify record type

How it fires #

This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:

-a always,exit -F arch=b64 -S mq_notify -k posixmq

Fields #

NameDescription
mqdesPOSIX message queue descriptor
sigev_signosignal number

Example Audit Record #

{
  "fields": {
    "mqdes": "3",
    "sigev_signo": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=SYSCALL msg=audit(1781632420.559:1883821): arch=c000003e syscall=244 success=yes exit=0 a0=3 a1=0 a2=7f3360b1b3f0 a3=0 items=0 ppid=51449 pid=51615 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=15 comm=\"python3\" exe=\"/usr/bin/python3.11\" subj=unconfined key=\"cat_mq\"",
    "ARCH=x86_64 SYSCALL=mq_notify AUID=\"debian\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
    "node=JD-debian-12-workstation type=MQ_NOTIFY msg=audit(1781632420.559:1883821): mqdes=3 sigev_signo=0",
    "node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781632420.559:1883821): proctitle=707974686F6E33002F746D702F726F756E64322E7079"
  ],
  "record_type": "MQ_NOTIFY"
}

References #

MQ_GETSETATTR msgtype 1315

#
Message type
1315
Fires
Requires a loaded audit rule

Description

POSIX MQ get/set attribute record type

How it fires #

This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:

-a always,exit -F arch=b64 -S mq_getsetattr -k posixmq

Fields #

NameDescription
mqdesPOSIX message queue descriptor
mq_flagsPOSIX message queue flags
mq_maxmsgmaximum number of messages on the POSIX message queue
mq_msgsizemaximum message size on the POSIX message queue
mq_curmsgscurrent number of messages on the POSIX message queue

Example Audit Record #

{
  "fields": {
    "mq_curmsgs": "0",
    "mq_flags": "0x0",
    "mq_maxmsg": "10",
    "mq_msgsize": "64",
    "mqdes": "3"
  },
  "raw": [
    "node=JD-debian-12-workstation type=SYSCALL msg=audit(1781632420.559:1883823): arch=c000003e syscall=245 success=yes exit=0 a0=3 a1=7f3360b56cb0 a2=0 a3=0 items=0 ppid=51449 pid=51615 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=15 comm=\"python3\" exe=\"/usr/bin/python3.11\" subj=unconfined key=\"cat_mq\"",
    "ARCH=x86_64 SYSCALL=mq_getsetattr AUID=\"debian\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
    "node=JD-debian-12-workstation type=MQ_GETSETATTR msg=audit(1781632420.559:1883823): mqdes=3 mq_flags=0x0 mq_maxmsg=10 mq_msgsize=64 mq_curmsgs=0 ",
    "node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781632420.559:1883823): proctitle=707974686F6E33002F746D702F726F756E64322E7079"
  ],
  "record_type": "MQ_GETSETATTR"
}

References #

KERNEL_OTHER msgtype 1316

#
Message type
1316
Fires
Emitted by default (no audit rule required)

Description

For use by 3rd party modules

FD_PAIR msgtype 1317

#
Message type
1317
Fires
Requires a loaded audit rule

Description

Information for pipe and socketpair system calls

How it fires #

This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:

-a always,exit -F arch=b64 -S pipe,pipe2,socketpair -k fdpair

Fields #

NameDescription
fd0first file descriptor of the created pair
fd1second file descriptor of the created pair

Example Audit Record #

{
  "fields": {
    "fd0": "7",
    "fd1": "9"
  },
  "raw": [
    "node=JD-debian-12-workstation type=SYSCALL msg=audit(1781634258.158:513530): arch=c000003e syscall=53 success=yes exit=0 a0=1 a1=80001 a2=0 a3=c00012f078 items=0 ppid=1121 pid=2466 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=\"runc\" exe=\"/usr/bin/runc\" subj=system_u:system_r:initrc_t:s0 key=\"cat_fdpair\"",
    "ARCH=x86_64 SYSCALL=socketpair AUID=\"unset\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
    "node=JD-debian-12-workstation type=FD_PAIR msg=audit(1781634258.158:513530): fd0=7 fd1=9",
    "node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781634258.158:513530): proctitle=72756E63002D2D726F6F74002F7661722F72756E2F646F636B65722F72756E74696D652D72756E632F6D6F6279002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6D6F62792F36616133383239633966356566636632623230353437336565"
  ],
  "record_type": "FD_PAIR"
}

References #

OBJ_PID msgtype 1318

#
Message type
1318
Fires
Requires a loaded audit rule

Description

Target process information for ptrace, kill, tkill, and tgkill syscalls

How it fires #

This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:

-a always,exit -F arch=b64 -S ptrace -k ptrace

Fields #

NameDescription
opidobject's process ID
oauidobject's login user ID
ouidfile owner user ID
osesobject's session ID
objlspp object context string
ocommobject's command line name

Example Audit Record #

{
  "fields": {
    "oauid": "-1",
    "obj": "system_u:system_r:initrc_t:s0",
    "ocomm": "dockerd",
    "opid": "671",
    "oses": "-1",
    "ouid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=SYSCALL msg=audit(1781634257.750:512329): arch=c000003e syscall=234 success=yes exit=0 a0=29f a1=8b9 a2=17 a3=7ffed2507080 items=0 ppid=1 pid=671 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=\"dockerd\" exe=\"/usr/bin/dockerd\" subj=system_u:system_r:initrc_t:s0 key=\"T1489_process_kill\"",
    "ARCH=x86_64 SYSCALL=tgkill AUID=\"unset\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
    "node=JD-debian-12-workstation type=OBJ_PID msg=audit(1781634257.750:512329): opid=671 oauid=-1 ouid=0 oses=-1 obj=system_u:system_r:initrc_t:s0 ocomm=\"dockerd\"",
    "OAUID=\"unset\" OUID=\"root\"",
    "node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781634257.750:512329): proctitle=2F7573722F62696E2F646F636B657264002D480066643A2F2F002D2D636F6E7461696E6572643D2F72756E2F636F6E7461696E6572642F636F6E7461696E6572642E736F636B"
  ],
  "record_type": "OBJ_PID"
}

References #

TTY msgtype 1319

#
Message type
1319
Fires
Emitted by default (no audit rule required)

Description

Input on an administrative TTY

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
majordevice major number
minordevice minor number
commcommand line program name
dataTTY text

Example Audit Record #

{
  "fields": {
    "auid": "1000",
    "comm": "bash",
    "data": "69640A657869740A",
    "major": "136",
    "minor": "0",
    "pid": "32503",
    "ses": "1",
    "uid": "1003"
  },
  "raw": [
    "node=JD-debian-12-workstation type=TTY msg=audit(1781630540.940:1378859): tty pid=32503 uid=1003 auid=1000 ses=1 major=136 minor=0 comm=\"bash\" data=69640A657869740A",
    "UID=\"testlogout123\" AUID=\"debian\""
  ],
  "record_type": "TTY"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
nameeq/etc/pam.d/system-auth1 rulesigma
typeeqpath1 rulesigma

References #

EOE msgtype 1320

#
Message type
1320
Fires
Emitted by default (no audit rule required)

Description

End of multi-record event

Example Audit Record #

{
  "fields": {},
  "raw": [
    "node=JD-debian-12-workstation type=EOE msg=audit(1781641908.324:2323996): "
  ],
  "record_type": "EOE"
}

References #

BPRM_FCAPS msgtype 1321

#
Message type
1321
Fires
Requires a loaded audit rule

Description

Information about file system capabilities increasing permissions

How it fires #

This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:

-a always,exit -F arch=b64 -S execve -k filecaps

Fields #

NameDescription
fverfile system capabilities version number
fpfile assigned permitted capability map
fifile assigned inherited capability map
fefile assigned effective capability map
old_ppold process permitted capability map
old_piold process inherited capability map
old_peold process effective capability map
old_paold process ambient capability map
ppprocess permitted capability map
piprocess inherited capability map
peprocess effective capability map
paprocess ambient capability map
frootidroot user ID namespace owner of the file capability set

Example Audit Record #

{
  "fields": {
    "fe": "0",
    "fi": "0",
    "fp": "0",
    "frootid": "0",
    "fver": "0",
    "old_pa": "0",
    "old_pe": "000001f7fdffffff",
    "old_pi": "0",
    "old_pp": "000001f7fdffffff",
    "pa": "0",
    "pe": "000001f7fdffffff",
    "pi": "0",
    "pp": "000001f7fdffffff"
  },
  "raw": [
    "node=JD-debian-12-workstation type=SYSCALL msg=audit(1781634257.766:512777): arch=c000003e syscall=59 success=yes exit=0 a0=5611885bc330 a1=56118918c5a0 a2=5611891898d0 a3=0 items=3 ppid=2408 pid=2410 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=\"ifupdown-hotplu\" exe=\"/usr/bin/dash\" subj=system_u:system_r:udev_t:s0 key=\"T1059_exec\"",
    "ARCH=x86_64 SYSCALL=execve AUID=\"unset\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
    "node=JD-debian-12-workstation type=BPRM_FCAPS msg=audit(1781634257.766:512777): fver=0 fp=0 fi=0 fe=0 old_pp=000001f7fdffffff old_pi=0 old_pe=000001f7fdffffff old_pa=0 pp=000001f7fdffffff pi=0 pe=000001f7fdffffff pa=0 frootid=0",
    "node=JD-debian-12-workstation type=EXECVE msg=audit(1781634257.766:512777): argc=3 a0=\"/bin/sh\" a1=\"-e\" a2=\"/lib/udev/ifupdown-hotplug\"",
    "node=JD-debian-12-workstation type=CWD msg=audit(1781634257.766:512777): cwd=\"/\"",
    "node=JD-debian-12-workstation type=PATH msg=audit(1781634257.766:512777): item=0 name=\"/lib/udev/ifupdown-hotplug\" inode=5512454 dev=fe:01 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:bin_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
    "OUID=\"root\" OGID=\"root\"",
    "node=JD-debian-12-workstation type=PATH msg=audit(1781634257.766:512777): item=1 name=\"/bin/sh\" inode=5506763 dev=fe:01 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:shell_exec_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
    "OUID=\"root\" OGID=\"root\"",
    "node=JD-debian-12-workstation type=PATH msg=audit(1781634257.766:512777): item=2 name=\"/lib64/ld-linux-x86-64.so.2\" inode=5505708 dev=fe:01 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:ld_so_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
    "OUID=\"root\" OGID=\"root\"",
    "node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781634257.766:512777): proctitle=\"(spawn)\""
  ],
  "record_type": "BPRM_FCAPS"
}

References #

CAPSET msgtype 1322

#
Message type
1322
Fires
Requires a loaded audit rule

Description

Record showing argument to sys_capset setting process-based capabilities

How it fires #

This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:

-a always,exit -F arch=b64 -S capset -k caps

Fields #

NameDescription
pidprocess ID
cap_piprocess inherited capability map
cap_ppprocess permitted capability map
cap_peprocess effective capability map
cap_paprocess ambient capability map

Example Audit Record #

{
  "fields": {
    "cap_pa": "0",
    "cap_pe": "00000000a80425fb",
    "cap_pi": "00000000a80425fb",
    "cap_pp": "00000000a80425fb",
    "pid": "2474"
  },
  "raw": [
    "node=JD-debian-12-workstation type=SYSCALL msg=audit(1781634258.214:513610): arch=c000003e syscall=126 success=yes exit=0 a0=c000098570 a1=c000098578 a2=0 a3=0 items=0 ppid=2466 pid=2474 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=\"runc:[2:INIT]\" exe=\"/runc\" subj=system_u:system_r:initrc_t:s0 key=\"T1548_capabilities\"",
    "ARCH=x86_64 SYSCALL=capset AUID=\"unset\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
    "node=JD-debian-12-workstation type=CAPSET msg=audit(1781634258.214:513610): pid=2474 cap_pi=00000000a80425fb cap_pp=00000000a80425fb cap_pe=00000000a80425fb cap_pa=0",
    "node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781634258.214:513610): proctitle=72756E6300696E6974"
  ],
  "record_type": "CAPSET"
}

References #

MMAP msgtype 1323

#
Message type
1323
Fires
Requires a loaded audit rule

Description

Mmap system call file descriptor and flags

How it fires #

This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:

-a always,exit -F arch=b64 -S mmap -k mmap

Fields #

NameDescription
fdfile descriptor number
flagsmmap syscall flags

Example Audit Record #

{
  "fields": {
    "fd": "3",
    "flags": "0x812"
  },
  "raw": [
    "node=JD-debian-12-workstation type=SYSCALL msg=audit(1781634257.762:512610): arch=c000003e syscall=9 success=yes exit=140067170054144 a0=7f63edea7000 a1=8000 a2=5 a3=812 items=0 ppid=671 pid=2407 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=\"iptables\" exe=\"/usr/sbin/xtables-nft-multi\" subj=system_u:system_r:iptables_t:s0 key=\"T1055_mmap_exec\"",
    "ARCH=x86_64 SYSCALL=mmap AUID=\"unset\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
    "node=JD-debian-12-workstation type=MMAP msg=audit(1781634257.762:512610): fd=3 flags=0x812",
    "node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781634257.762:512610): proctitle=2F7573722F7362696E2F69707461626C6573002D2D77616974002D7400726177002D4300505245524F5554494E47002D64003137322E31382E302E360021002D690062722D343430663332333836316361002D6A0044524F50"
  ],
  "record_type": "MMAP"
}

References #

NETFILTER_PKT msgtype 1324

#
Message type
1324
Fires
Emitted by default (no audit rule required)

Description

Packets traversing netfilter chains

Fields #

NameDescription
marknetfilter packet mark
saddrstruct socket address structure
daddrremote IP address
protonetwork protocol
sportlocal port number
dportremote port number

Example Audit Record #

{
  "fields": {
    "daddr": "127.0.0.1",
    "mark": "0x0",
    "proto": "1",
    "saddr": "127.0.0.1"
  },
  "raw": [
    "node=JD-debian-12-workstation type=NETFILTER_PKT msg=audit(1781632714.004:2114926): mark=0x0 saddr=127.0.0.1 daddr=127.0.0.1 proto=1"
  ],
  "record_type": "NETFILTER_PKT"
}

NETFILTER_CFG msgtype 1325

#
Message type
1325
Fires
Emitted by default (no audit rule required)

Description

Netfilter chain modifications

Fields #

NameDescription
tableNetfilter table name
familyAddress family (e.g. 2 for IPv4, 10 for IPv6)
entriesNumber of entries in the table
opthe operation being performed that is audited
pidprocess ID
subjlspp subject's context string
commcommand line program name

Example Audit Record #

{
  "fields": {
    "comm": "iptables",
    "entries": "1",
    "family": "2",
    "op": "nft_register_rule",
    "pid": "2409",
    "subj": "system_u:system_r:iptables_t:s0",
    "table": "raw:106"
  },
  "raw": [
    "node=JD-debian-12-workstation type=NETFILTER_CFG msg=audit(1781634257.766:512779): table=raw:106 family=2 entries=1 op=nft_register_rule pid=2409 subj=system_u:system_r:iptables_t:s0 comm=\"iptables\"",
    "node=JD-debian-12-workstation type=SYSCALL msg=audit(1781634257.766:512779): arch=c000003e syscall=46 success=yes exit=396 a0=3 a1=7fff72384f90 a2=0 a3=7fff72384f7c items=0 ppid=671 pid=2409 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=\"iptables\" exe=\"/usr/sbin/xtables-nft-multi\" subj=system_u:system_r:iptables_t:s0 key=\"T1071_msg_transfer\"",
    "ARCH=x86_64 SYSCALL=sendmsg AUID=\"unset\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
    "node=JD-debian-12-workstation type=SOCKADDR msg=audit(1781634257.766:512779): saddr=100000000000000000000000",
    "SADDR={ saddr_fam=netlink nlnk-fam=16 nlnk-pid=0 }",
    "node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781634257.766:512779): proctitle=2F7573722F7362696E2F69707461626C6573002D2D77616974002D7400726177002D4100505245524F5554494E47002D64003137322E31382E302E360021002D690062722D343430663332333836316361002D6A0044524F50"
  ],
  "record_type": "NETFILTER_CFG"
}

References #

SECCOMP msgtype 1326

#
Message type
1326
Fires
Emitted by default (no audit rule required)

Description

Secure Computing event

Fields #

NameDescription
auidlogin user ID
uiduser ID
gidgroup ID
seslogin session ID
subjlspp subject's context string
pidprocess ID
commcommand line program name
exeexecutable name
sigsignal number
archthe elf architecture flags
syscallsyscall number in effect when the event occurred
compatis_compat_task result
ipnetwork address of a printer
codeseccomp action code

Example Audit Record #

{
  "fields": {
    "arch": "c000003e",
    "auid": "4294967295",
    "code": "0x7ffc0000",
    "comm": "true",
    "compat": "0",
    "exe": "/usr/bin/true",
    "gid": "0",
    "ip": "0x7f13da9bb917",
    "pid": "5052",
    "ses": "4294967295",
    "sig": "0",
    "subj": "unconfined",
    "syscall": "3",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=SECCOMP msg=audit(1781627806.180:583840): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=5052 comm=\"true\" exe=\"/usr/bin/true\" sig=0 arch=c000003e syscall=3 compat=0 ip=0x7f13da9bb917 code=0x7ffc0000",
    "AUID=\"unset\" UID=\"root\" GID=\"root\" ARCH=x86_64 SYSCALL=close"
  ],
  "record_type": "SECCOMP"
}

References #

PROCTITLE msgtype 1327

#
Message type
1327
Fires
Requires a loaded audit rule

Description

Process Title info

How it fires #

This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:

-a always,exit -F arch=b64 -S execve -k exec

Fields #

NameDescriptionRules
proctitleProcess title (hex-encoded command line)59 detection rules

Example Audit Record #

{
  "fields": {
    "proctitle": "2F7573722F7362696E2F69707461626C6573002D2D77616974002D7400726177002D4300505245524F5554494E47002D64003137322E31382E302E360021002D690062722D343430663332333836316361002D6A0044524F50"
  },
  "raw": [
    "node=JD-debian-12-workstation type=SYSCALL msg=audit(1781634257.762:512605): arch=c000003e syscall=59 success=yes exit=0 a0=2442de3bf7e8 a1=2442dd0f4cb0 a2=2442dd889e60 a3=0 items=2 ppid=671 pid=2407 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=\"iptables\" exe=\"/usr/sbin/xtables-nft-multi\" subj=system_u:system_r:iptables_t:s0 key=\"T1059_exec\"",
    "ARCH=x86_64 SYSCALL=execve AUID=\"unset\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
    "node=JD-debian-12-workstation type=EXECVE msg=audit(1781634257.762:512605): argc=13 a0=\"/usr/sbin/iptables\" a1=\"--wait\" a2=\"-t\" a3=\"raw\" a4=\"-C\" a5=\"PREROUTING\" a6=\"-d\" a7=\"172.18.0.6\" a8=\"!\" a9=\"-i\" a10=\"br-440f323861ca\" a11=\"-j\" a12=\"DROP\"",
    "node=JD-debian-12-workstation type=CWD msg=audit(1781634257.762:512605): cwd=\"/\"",
    "node=JD-debian-12-workstation type=PATH msg=audit(1781634257.762:512605): item=0 name=\"/usr/sbin/iptables\" inode=5537074 dev=fe:01 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:iptables_exec_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
    "OUID=\"root\" OGID=\"root\"",
    "node=JD-debian-12-workstation type=PATH msg=audit(1781634257.762:512605): item=1 name=\"/lib64/ld-linux-x86-64.so.2\" inode=5505708 dev=fe:01 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:ld_so_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
    "OUID=\"root\" OGID=\"root\"",
    "node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781634257.762:512605): proctitle=2F7573722F7362696E2F69707461626C6573002D2D77616974002D7400726177002D4300505245524F5554494E47002D64003137322E31382E302E360021002D690062722D343430663332333836316361002D6A0044524F50"
  ],
  "record_type": "PROCTITLE"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
typeeqexecve6 rulessplunk
typeeqproctitle6 rulessplunk
typeinexecve2 rulessplunk
typeinproctitle2 rulessplunk
typeinuser_cmd1 rulesplunk
proctitlein*service *2 rulessplunk
proctitlein*systemctl *2 rulessplunk
CommandLineis_not_null1 rulesplunk
c_processlt31 rulesplunk
dc_hosteq11 rulesplunk

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

  • Linux Auditd Add User Account source: The following analytic detects the creation of new user accounts on Linux systems using commands like "useradd" or "adduser." It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line…T1136, T1136.001
  • Linux Auditd AI CLI Permission Override Activated source: This detection identifies when an AI command-line tool is launched in an unsafe mode that bypasses normal safety checks and user approvals. For instance, running claude --dangerously-skip-permissions skips all safety restrictions, allowing…T1480
  • Linux Auditd Change File Owner To Root source: The following analytic detects the use of the 'chown' command to change a file owner to 'root' on a Linux system. It leverages Linux Auditd telemetry, specifically monitoring command-line executions and process details. This activity is…T1222, T1222.002

References #

FEATURE_CHANGE msgtype 1328

#
Message type
1328
Fires
Emitted by default (no audit rule required)

Description

Audit feature changed value

Fields #

NameDescription
ppidparent process ID
pidprocess ID
auidlogin user ID
uiduser ID
gidgroup ID
euideffective user ID
suidsent user ID
fsuidfile system user ID
egideffective group ID
sgidset group ID
fsgidfile system group ID
ttytty udevice the user is running programs on
seslogin session ID
commcommand line program name
exeexecutable name
subjlspp subject's context string
featurekernel feature being changed
oldprevious value
newnew value
old_lockfeature lock state before the change
new_lockfeature lock state after the change
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "auid": "1000",
    "comm": "auditctl",
    "egid": "0",
    "euid": "0",
    "exe": "/usr/sbin/auditctl",
    "feature": "loginuid_immutable",
    "fsgid": "0",
    "fsuid": "0",
    "gid": "0",
    "new": "1",
    "new_lock": "1",
    "old": "0",
    "old_lock": "0",
    "pid": "33977",
    "ppid": "33976",
    "res": "1",
    "ses": "1",
    "sgid": "0",
    "subj": "unconfined",
    "suid": "0",
    "tty": "(none)",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=FEATURE_CHANGE msg=audit(1781630669.800:1417007):  ppid=33976 pid=33977 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=\"auditctl\" exe=\"/usr/sbin/auditctl\" subj=unconfined feature=loginuid_immutable old=0 new=1 old_lock=0 new_lock=1 res=1",
    "AUID=\"debian\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\""
  ],
  "record_type": "FEATURE_CHANGE"
}

References #

KERN_MODULE msgtype 1330

#
Message type
1330
Fires
Requires a loaded audit rule

Description

Kernel Module events

How it fires #

This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:

-a always,exit -F arch=b64 -S init_module,finit_module,delete_module -k modules

Fields #

NameDescription
namefile name in avcs

Example Audit Record #

{
  "fields": {
    "name": "nft_compat"
  },
  "raw": [
    "node=JD-debian-12-workstation type=SYSCALL msg=audit(1781634171.392:79211): arch=c000003e syscall=313 success=yes exit=0 a0=0 a1=5566b4fed4a0 a2=0 a3=0 items=0 ppid=35 pid=701 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=\"modprobe\" exe=\"/usr/bin/kmod\" subj=system_u:system_r:kmod_t:s0 key=\"T1547_kernel_modules\"",
    "ARCH=x86_64 SYSCALL=finit_module AUID=\"unset\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
    "node=JD-debian-12-workstation type=KERN_MODULE msg=audit(1781634171.392:79211): name=\"nft_compat\"",
    "node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781634171.392:79211): proctitle=2F7362696E2F6D6F6470726F6265002D71002D2D006E666E65746C696E6B2D7375627379732D3131"
  ],
  "record_type": "KERN_MODULE"
}

References #

FANOTIFY msgtype 1331

#
Message type
1331
Fires
Emitted by default (no audit rule required)

Description

Fanotify access decision

Fields #

NameDescription
respfanotify permission response (allow or deny)
fan_typefanotify response info type
fan_infofanotify audit rule number
subj_trustfanotify subject trust value (0 no, 1 yes, 2 unknown)
obj_trustfanotify object trust value (0 no, 1 yes, 2 unknown)

Example Audit Record #

{
  "fields": {
    "fan_info": "2A",
    "fan_type": "1",
    "obj_trust": "0",
    "resp": "1",
    "subj_trust": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=FANOTIFY msg=audit(1781717953.135:245162): resp=1 fan_type=1 fan_info=2A subj_trust=0 obj_trust=0",
    "node=JD-debian-12-workstation type=SYSCALL msg=audit(1781717953.135:245162): arch=c000003e syscall=257 success=yes exit=4 a0=ffffff9c a1=710119527dd0 a2=80000 a3=0 items=1 ppid=90046 pid=90047 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=59 comm=\"python3\" exe=\"/usr/bin/python3.11\" subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key=\"fanotify\"",
    "ARCH=x86_64 SYSCALL=openat AUID=\"debian\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
    "node=JD-debian-12-workstation type=CWD msg=audit(1781717953.135:245162): cwd=\"/home/debian\"",
    "node=JD-debian-12-workstation type=PATH msg=audit(1781717953.135:245162): item=0 name=\"/tmp/fant\" inode=1835017 dev=fd:01 mode=0100644 ouid=0 ogid=0 rdev=00:00 obj=unconfined_u:object_r:user_tmp_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
    "OUID=\"root\" OGID=\"root\"",
    "node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781717953.135:245162): proctitle=707974686F6E33002D"
  ],
  "record_type": "FANOTIFY"
}

References #

TIME_INJOFFSET msgtype 1332

#
Message type
1332
Fires
Requires a loaded audit rule

Description

Timekeeping offset injected

How it fires #

This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:

-a always,exit -F arch=b64 -S clock_settime,settimeofday -k time-change

Fields #

NameDescription
secseconds component of the time change
nsecnanoseconds component of the time change

Example Audit Record #

{
  "fields": {
    "nsec": "398226411",
    "sec": "-1"
  },
  "raw": [
    "node=JD-debian-12-workstation type=SYSCALL msg=audit(1781627806.598:582950): arch=c000003e syscall=164 success=yes exit=0 a0=7f5df5e12380 a1=0 a2=3befff30 a3=7f5df5db4bc0 items=0 ppid=4981 pid=4982 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=\"python3\" exe=\"/usr/bin/python3.11\" subj=unconfined key=\"T1070_time_change\"",
    "ARCH=x86_64 SYSCALL=settimeofday AUID=\"debian\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
    "node=JD-debian-12-workstation type=TIME_INJOFFSET msg=audit(1781627806.598:582950): sec=-1 nsec=398226411",
    "node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781627806.598:582950): proctitle=7375646F002F7573722F62696E2F707974686F6E33002D"
  ],
  "record_type": "TIME_INJOFFSET"
}

References #

TIME_ADJNTPVAL msgtype 1333

#
Message type
1333
Fires
Requires a loaded audit rule

Description

NTP value adjustment

How it fires #

This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:

-a always,exit -F arch=b64 -S adjtimex,clock_adjtime -k time-change

Fields #

NameDescription
opthe operation being performed that is audited
oldprevious value
newnew value

Example Audit Record #

{
  "fields": {
    "new": "138842102107734",
    "old": "-721856555751",
    "op": "offset"
  },
  "raw": [
    "node=JD-debian-12-workstation type=SYSCALL msg=audit(1781634263.290:518491): arch=c000003e syscall=305 success=yes exit=0 a0=0 a1=7ffc08480930 a2=0 a3=7ffc0858d080 items=0 ppid=1 pid=453 auid=4294967295 uid=996 gid=996 euid=996 suid=996 fsuid=996 egid=996 sgid=996 fsgid=996 tty=(none) ses=4294967295 comm=\"systemd-timesyn\" exe=\"/usr/lib/systemd/systemd-timesyncd\" subj=system_u:system_r:ntpd_t:s0 key=\"cat_time\"",
    "ARCH=x86_64 SYSCALL=clock_adjtime AUID=\"unset\" UID=\"systemd-timesync\" GID=\"systemd-timesync\" EUID=\"systemd-timesync\" SUID=\"systemd-timesync\" FSUID=\"systemd-timesync\" EGID=\"systemd-timesync\" SGID=\"systemd-timesync\" FSGID=\"systemd-timesync\"",
    "node=JD-debian-12-workstation type=TIME_ADJNTPVAL msg=audit(1781634263.290:518491): op=offset old=-721856555751 new=138842102107734",
    "node=JD-debian-12-workstation type=TIME_ADJNTPVAL msg=audit(1781634263.290:518491): op=freq old=-87703970381824 new=47884019957760",
    "node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781634263.290:518491): proctitle=\"/lib/systemd/systemd-timesyncd\""
  ],
  "record_type": "TIME_ADJNTPVAL"
}

References #

BPF msgtype 1334

#
Message type
1334
Fires
Emitted by default (no audit rule required)

Description

BPF load/unload

Fields #

NameDescription
prog-idBPF program ID
opthe operation being performed that is audited

Example Audit Record #

{
  "fields": {
    "op": "LOAD",
    "prog-id": "81"
  },
  "raw": [
    "node=JD-debian-12-workstation type=BPF msg=audit(1781634257.694:511163): prog-id=81 op=LOAD",
    "node=JD-debian-12-workstation type=SYSCALL msg=audit(1781634257.694:511163): arch=c000003e syscall=321 success=yes exit=85 a0=5 a1=7ffc318bf920 a2=90 a3=4 items=0 ppid=0 pid=1 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=\"systemd\" exe=\"/usr/lib/systemd/systemd\" subj=system_u:system_r:init_t:s0 key=\"cat_bpf\"",
    "ARCH=x86_64 SYSCALL=bpf AUID=\"unset\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
    "node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781634257.694:511163): proctitle=\"/sbin/init\""
  ],
  "record_type": "BPF"
}

References #

EVENT_LISTENER msgtype 1335

#
Message type
1335
Fires
Emitted by default (no audit rule required)

Description

audit mcast sock join/part

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
ttytty udevice the user is running programs on
seslogin session ID
subjlspp subject's context string
commcommand line program name
exeexecutable name
nl-mcgrpaudit netlink multicast group joined or left
opthe operation being performed that is audited
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "auid": "4294967295",
    "comm": "systemd",
    "exe": "/usr/lib/systemd/systemd",
    "nl-mcgrp": "1",
    "op": "connect",
    "pid": "1",
    "res": "1",
    "ses": "4294967295",
    "subj": "system_u:system_r:init_t:s0",
    "tty": "(none)",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=EVENT_LISTENER msg=audit(1781634165.636:9): pid=1 uid=0 auid=4294967295 tty=(none) ses=4294967295 subj=system_u:system_r:init_t:s0 comm=\"systemd\" exe=\"/usr/lib/systemd/systemd\" nl-mcgrp=1 op=connect res=1",
    "UID=\"root\" AUID=\"unset\"",
    "node=JD-debian-12-workstation type=SYSCALL msg=audit(1781634165.636:9): arch=c000003e syscall=49 success=yes exit=0 a0=20 a1=55b6f362dc40 a2=c a3=7ffc318bfd84 items=0 ppid=0 pid=1 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=\"systemd\" exe=\"/usr/lib/systemd/systemd\" subj=system_u:system_r:init_t:s0 key=(null)",
    "ARCH=x86_64 SYSCALL=bind AUID=\"unset\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
    "node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781634165.636:9): proctitle=\"/sbin/init\""
  ],
  "record_type": "EVENT_LISTENER"
}

References #

URINGOP msgtype 1336

#
Message type
1336
Fires
Requires a loaded audit rule

Description

io_uring operation

How it fires #

This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:

-a always,exit -F arch=b64 -S io_uring_enter -k uring

Fields #

NameDescription
uring_opio_uring operation code
successwhether the syscall was successful or not
exitsyscall exit code
itemsthe number of path records in the event
ppidparent process ID
pidprocess ID
uiduser ID
gidgroup ID
euideffective user ID
suidsent user ID
fsuidfile system user ID
egideffective group ID
sgidset group ID
fsgidfile system group ID
subjlspp subject's context string
keykey assigned from triggered audit rule

Example Audit Record #

{
  "fields": {
    "egid": "0",
    "euid": "0",
    "exit": "0",
    "fsgid": "0",
    "fsuid": "0",
    "gid": "0",
    "items": "1",
    "key": "uringcap",
    "pid": "38669",
    "ppid": "38651",
    "sgid": "0",
    "subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
    "success": "yes",
    "suid": "0",
    "uid": "0",
    "uring_op": "18"
  },
  "raw": [
    "node=JD-debian-12-workstation type=URINGOP msg=audit(1781732081.383:1214470): uring_op=18 success=yes exit=0 items=1 ppid=38651 pid=38669 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key=\"uringcap\"",
    "UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
    "node=JD-debian-12-workstation type=SYSCALL msg=audit(1781732081.383:1214470): arch=c000003e syscall=426 success=yes exit=1 a0=3 a1=1 a2=1 a3=1 items=1 ppid=38651 pid=38669 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=54 comm=\"uring\" exe=\"/tmp/recap/uring\" subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key=\"uringcap\"",
    "ARCH=x86_64 SYSCALL=io_uring_enter AUID=\"debian\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
    "node=JD-debian-12-workstation type=CWD msg=audit(1781732081.383:1214470): cwd=\"/home/debian\"",
    "node=JD-debian-12-workstation type=PATH msg=audit(1781732081.383:1214470): item=0 name=\"/etc/hostname\" inode=11010243 dev=fd:01 mode=0100644 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:net_conf_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
    "OUID=\"root\" OGID=\"root\"",
    "node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781732081.383:1214470): proctitle=\"/tmp/recap/uring\""
  ],
  "record_type": "URINGOP"
}

References #

OPENAT2 msgtype 1337

#
Message type
1337
Fires
Requires a loaded audit rule

Description

Record showing openat2 how args

How it fires #

This record only appears when a matching auditctl / audit.rules syscall rule is loaded. Example rule:

-a always,exit -F arch=b64 -S openat2 -k open

Fields #

NameDescription
oflagopen syscall flags
modeLandlock domain enforcement mode (enforcing)
resolveopenat2 RESOLVE_* flags

Example Audit Record #

{
  "fields": {
    "mode": "00",
    "oflag": "012000000",
    "resolve": "0x14"
  },
  "raw": [
    "node=JD-debian-12-workstation type=SYSCALL msg=audit(1781634257.690:510676): arch=c000003e syscall=437 success=yes exit=12 a0=ffffffffffffff9c a1=c00015de3a a2=c000140d88 a3=18 items=1 ppid=2351 pid=2392 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=\"runc:[2:INIT]\" exe=\"/runc\" subj=system_u:system_r:initrc_t:s0 key=\"cat_openat2\"",
    "ARCH=x86_64 SYSCALL=openat2 AUID=\"unset\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
    "node=JD-debian-12-workstation type=OPENAT2 msg=audit(1781634257.690:510676): oflag=012000000 mode=00 resolve=0x14",
    "node=JD-debian-12-workstation type=CWD msg=audit(1781634257.690:510676): cwd=\"/var/lib/docker/rootfs/overlayfs/5532208236a5c5797a9da401566d1b5a1b0fc8324846bcf558a1b2d96fff977e\"",
    "node=JD-debian-12-workstation type=PATH msg=audit(1781634257.690:510676): item=0 name=\".\" inode=4755763 dev=00:35 mode=040755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:var_lib_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
    "OUID=\"root\" OGID=\"root\"",
    "node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781634257.690:510676): proctitle=72756E6300696E6974"
  ],
  "record_type": "OPENAT2"
}

References #

DM_CTRL msgtype 1338

#
Message type
1338
Fires
Emitted by default (no audit rule required)

Description

Device Mapper target control

Fields #

NameDescription
moduledevice-mapper target or kernel module name
opthe operation being performed that is audited
ppidparent process ID
pidprocess ID
auidlogin user ID
uiduser ID
gidgroup ID
euideffective user ID
suidsent user ID
fsuidfile system user ID
egideffective group ID
sgidset group ID
fsgidfile system group ID
ttytty udevice the user is running programs on
seslogin session ID
commcommand line program name
exeexecutable name
subjlspp subject's context string
devdevice identifier
error_msgdevice-mapper target error text on failure, or the literal string success when the operation succeeded
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "auid": "1000",
    "comm": "cryptsetup",
    "dev": "253:0",
    "egid": "0",
    "error_msg": "success",
    "euid": "0",
    "exe": "/usr/sbin/cryptsetup",
    "fsgid": "0",
    "fsuid": "0",
    "gid": "0",
    "module": "crypt",
    "op": "dtr",
    "pid": "56754",
    "ppid": "56702",
    "res": "1",
    "ses": "15",
    "sgid": "0",
    "subj": "unconfined",
    "suid": "0",
    "tty": "(none)",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=UNKNOWN[1338] msg=audit(1781632713.768:2113664): module=crypt op=dtr ppid=56702 pid=56754 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=15 comm=\"cryptsetup\" exe=\"/usr/sbin/cryptsetup\" subj=unconfined dev=253:0 error_msg='success' res=1",
    "AUID=\"debian\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\""
  ],
  "record_type": "DM_CTRL"
}

References #

DM_EVENT msgtype 1339

#
Message type
1339
Fires
Emitted by default (no audit rule required)

Description

Device Mapper events

Fields #

NameDescription
moduledevice-mapper target or kernel module name
opthe operation being performed that is audited
devdevice identifier
sectordevice-mapper device sector
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "dev": "7:0",
    "module": "verity",
    "op": "verify-data",
    "res": "0",
    "sector": "100"
  },
  "raw": [
    "node=JD-debian-12-workstation type=UNKNOWN[1339] msg=audit(1781674379.650:245044): module=verity op=verify-data dev=7:0 sector=100 res=0"
  ],
  "record_type": "DM_EVENT"
}

References #

AVC msgtype 1400

#
Message type
1400
Fires
Emitted by default (no audit rule required)

Description

SELinux AVC (Access Vector Cache) denial or grant

Fields #

NameDescription
pidProcess ID of the subject
commCommand name of the subject
pathTarget path, when the full path is resolved
nameTarget object name, when the full path is not resolved
devDevice of the target object
inoInode number of the target object
scontextSELinux security context of the subject
tcontextSELinux security context of the target object
tclassObject class of the target (file, dir, sock_file, ...)
permissiveSELinux mode at decision time (1 permissive, 0 enforcing)
ioctlcmdThe request argument to the ioctl syscall

Example Audit Record #

{
  "fields": {
    "comm": "avcprobe",
    "dev": "vda1",
    "ino": "2",
    "name": "/",
    "permissive": "1",
    "pid": "107789",
    "scontext": "unconfined_u:unconfined_r:dwbad_t:s0-s0:c0.c1023",
    "tclass": "dir",
    "tcontext": "system_u:object_r:root_t:s0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=AVC msg=audit(1781738979.016:2269224): avc:  denied  { search } for  pid=107789 comm=\"avcprobe\" name=\"/\" dev=\"vda1\" ino=2 scontext=unconfined_u:unconfined_r:dwbad_t:s0-s0:c0.c1023 tcontext=system_u:object_r:root_t:s0 tclass=dir permissive=1",
    "node=JD-debian-12-workstation type=AVC msg=audit(1781738979.016:2269224): avc:  denied  { search } for  pid=107789 comm=\"avcprobe\" name=\"etc\" dev=\"vda1\" ino=11010049 scontext=unconfined_u:unconfined_r:dwbad_t:s0-s0:c0.c1023 tcontext=system_u:object_r:etc_t:s0 tclass=dir permissive=1",
    "node=JD-debian-12-workstation type=AVC msg=audit(1781738979.016:2269224): avc:  denied  { read } for  pid=107789 comm=\"avcprobe\" name=\"passwd\" dev=\"vda1\" ino=11011862 scontext=unconfined_u:unconfined_r:dwbad_t:s0-s0:c0.c1023 tcontext=system_u:object_r:etc_t:s0 tclass=file permissive=1",
    "node=JD-debian-12-workstation type=AVC msg=audit(1781738979.016:2269224): avc:  denied  { open } for  pid=107789 comm=\"avcprobe\" path=\"/etc/passwd\" dev=\"vda1\" ino=11011862 scontext=unconfined_u:unconfined_r:dwbad_t:s0-s0:c0.c1023 tcontext=system_u:object_r:etc_t:s0 tclass=file permissive=1",
    "node=JD-debian-12-workstation type=SYSCALL msg=audit(1781738979.016:2269224): arch=c000003e syscall=257 success=yes exit=3 a0=ffffff9c a1=479004 a2=0 a3=22347680 items=1 ppid=107769 pid=107789 auid=1000 uid=1000 gid=1000 euid=1000 suid=1000 fsuid=1000 egid=1000 sgid=1000 fsgid=1000 tty=(none) ses=91 comm=\"avcprobe\" exe=\"/tmp/dwcap/avcprobe\" subj=unconfined_u:unconfined_r:dwbad_t:s0-s0:c0.c1023 key=\"dwavc\"",
    "ARCH=x86_64 SYSCALL=openat AUID=\"debian\" UID=\"debian\" GID=\"debian\" EUID=\"debian\" SUID=\"debian\" FSUID=\"debian\" EGID=\"debian\" SGID=\"debian\" FSGID=\"debian\"",
    "node=JD-debian-12-workstation type=CWD msg=audit(1781738979.016:2269224): cwd=\"/home/debian\"",
    "node=JD-debian-12-workstation type=PATH msg=audit(1781738979.016:2269224): item=0 name=\"/etc/passwd\" inode=11011862 dev=fd:01 mode=0100644 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:etc_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
    "OUID=\"root\" OGID=\"root\"",
    "node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781738979.016:2269224): proctitle=\"/tmp/dwcap/avcprobe\""
  ],
  "record_type": "AVC"
}

References #

SELINUX_ERR msgtype 1401

#
Message type
1401
Fires
Emitted by default (no audit rule required)

Description

Internal SELinux errors

Fields #

NameDescription
opthe operation being performed that is audited
reasonreason for the operation
scontextthe subject's context string
tcontextthe target's or object's context string
tclasstarget's object classification
permsSELinux permissions involved in the error
seresultSELinux access decision result
oldcontextSELinux context before the error
newcontextSELinux context after the error
taskcontextSELinux context of the acting task
invalid_contextthe SELinux context that failed validation

Example Audit Record #

{
  "fields": {
    "invalid_context": "unconfined_u:unconfined_r:dwbad_t:s0-s0:c0.c1023",
    "op": "security_compute_sid",
    "scontext": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
    "tclass": "process",
    "tcontext": "unconfined_u:object_r:dwexec_t:s0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=SELINUX_ERR msg=audit(1781732167.209:1214562): op=security_compute_sid invalid_context=\"unconfined_u:unconfined_r:dwbad_t:s0-s0:c0.c1023\" scontext=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:dwexec_t:s0 tclass=process",
    "node=JD-debian-12-workstation type=SYSCALL msg=audit(1781732167.209:1214562): arch=c000003e syscall=59 success=yes exit=0 a0=5bec7c15fa40 a1=5bec7c163d40 a2=5bec7c161240 a3=45fdd64043621a67 items=1 ppid=39588 pid=39651 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=58 comm=\"dwtrig\" exe=\"/tmp/dwtrig\" subj=unconfined_u:unconfined_r:dwbad_t:s0-s0:c0.c1023 key=\"selerr2\"",
    "ARCH=x86_64 SYSCALL=execve AUID=\"debian\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
    "node=JD-debian-12-workstation type=EXECVE msg=audit(1781732167.209:1214562): argc=1 a0=\"/tmp/dwtrig\"",
    "node=JD-debian-12-workstation type=CWD msg=audit(1781732167.209:1214562): cwd=\"/tmp/recap\"",
    "node=JD-debian-12-workstation type=PATH msg=audit(1781732167.209:1214562): item=0 name=\"/tmp/dwtrig\" inode=1835021 dev=fd:01 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=unconfined_u:object_r:dwexec_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
    "OUID=\"root\" OGID=\"root\"",
    "node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781732167.209:1214562): proctitle=\"/tmp/dwtrig\""
  ],
  "record_type": "SELINUX_ERR"
}

References #

AVC_PATH msgtype 1402

#
Message type
1402
Fires
Emitted by default (no audit rule required)

Description

dentry, vfsmount pair from AVC

MAC_POLICY_LOAD msgtype 1403

#
Message type
1403
Fires
Emitted by default (no audit rule required)

Description

SELinux Policy file load

Fields #

NameDescription
auidlogin user ID
seslogin session ID
lsmsecurity module that produced the record (selinux, apparmor, ...)
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "auid": "1000",
    "lsm": "selinux",
    "res": "1",
    "ses": "1"
  },
  "raw": [
    "node=JD-debian-12-workstation type=MAC_POLICY_LOAD msg=audit(1781634271.083:538063): auid=1000 ses=1 lsm=selinux res=1",
    "AUID=\"debian\""
  ],
  "record_type": "MAC_POLICY_LOAD"
}

References #

MAC_STATUS msgtype 1404

#
Message type
1404
Fires
Emitted by default (no audit rule required)

Description

SELinux mode (enforcing, permissive, off) changed

Fields #

NameDescription
enforcingwhether enforcing mode is active (1) or permissive (0)
old_enforcingMAC enforcing state before this change
auidlogin user ID
seslogin session ID
enabledMAC enabled state (1 enabled, 0 disabled)
old-enabledMAC enabled state before this change
lsmsecurity module that produced the record (selinux, apparmor, ...)
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "auid": "1000",
    "enabled": "1",
    "enforcing": "0",
    "lsm": "selinux",
    "old-enabled": "1",
    "old_enforcing": "1",
    "res": "1",
    "ses": "1"
  },
  "raw": [
    "node=JD-debian-12-workstation type=MAC_STATUS msg=audit(1781635211.620:942490): enforcing=0 old_enforcing=1 auid=1000 ses=1 enabled=1 old-enabled=1 lsm=selinux res=1",
    "AUID=\"debian\""
  ],
  "record_type": "MAC_STATUS"
}

MAC_CONFIG_CHANGE msgtype 1405

#
Message type
1405
Fires
Emitted by default (no audit rule required)

Description

SELinux Boolean value modification

Fields #

NameDescription
boolname of SELinux boolean
valvalue associated with the operation
old_valconfiguration value before the change
auidlogin user ID
seslogin session ID

Example Audit Record #

{
  "fields": {
    "auid": "1000",
    "bool": "aide_mmap_files",
    "old_val": "1",
    "ses": "1",
    "val": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=MAC_CONFIG_CHANGE msg=audit(1781634267.951:529349): bool=aide_mmap_files val=0 old_val=1 auid=1000 ses=1",
    "AUID=\"debian\""
  ],
  "record_type": "MAC_CONFIG_CHANGE"
}

References #

MAC_UNLBL_ALLOW msgtype 1406

#
Message type
1406
Fires
Emitted by default (no audit rule required)

Description

NetLabel: allow unlabeled traffic

Fields #

NameDescription
auidlogin user ID
seslogin session ID
subjlspp subject's context string
unlbl_acceptNetLabel unlabeled-traffic accept flag
oldprevious value

Example Audit Record #

{
  "fields": {
    "auid": "0",
    "old": "0",
    "ses": "0",
    "subj": "kernel",
    "unlbl_accept": "1"
  },
  "raw": [
    "node=JD-debian-12-workstation type=MAC_UNLBL_ALLOW msg=audit(1781634163.940:3): netlabel: auid=0 ses=0 subj=kernel unlbl_accept=1 old=0",
    "AUID=\"root\""
  ],
  "record_type": "MAC_UNLBL_ALLOW"
}

References #

MAC_CIPSOV4_ADD msgtype 1407

#
Message type
1407
Fires
Emitted by default (no audit rule required)

Description

NetLabel: add CIPSOv4 (Commercial Internet Protocol Security Option) DOI (Domain of Interpretation) entry

Fields #

NameDescription
auidlogin user ID
seslogin session ID
subjlspp subject's context string
cipso_doiCIPSO domain of interpretation
cipso_typeCIPSO mapping type
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "auid": "1000",
    "cipso_doi": "100",
    "cipso_type": "pass",
    "res": "1",
    "ses": "15",
    "subj": "unconfined"
  },
  "raw": [
    "node=JD-debian-12-workstation type=MAC_CIPSOV4_ADD msg=audit(1781632713.492:2112345): netlabel: auid=1000 ses=15 subj=unconfined cipso_doi=100 cipso_type=pass res=1",
    "AUID=\"debian\"",
    "node=JD-debian-12-workstation type=SYSCALL msg=audit(1781632713.492:2112345): arch=c000003e syscall=46 success=yes exit=48 a0=3 a1=7ffe48408fb0 a2=0 a3=7f749dc3a050 items=0 ppid=56702 pid=56718 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=15 comm=\"netlabelctl\" exe=\"/usr/sbin/netlabelctl\" subj=unconfined key=\"T1071_msg_transfer\"",
    "ARCH=x86_64 SYSCALL=sendmsg AUID=\"debian\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
    "node=JD-debian-12-workstation type=SOCKADDR msg=audit(1781632713.492:2112345): saddr=100000000000000000000000",
    "SADDR={ saddr_fam=netlink nlnk-fam=16 nlnk-pid=0 }",
    "node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781632713.492:2112345): proctitle=6E65746C6162656C63746C00636970736F763400616464007061737300646F693A31303000746167733A31006C6576656C733A303D30"
  ],
  "record_type": "MAC_CIPSOV4_ADD"
}

References #

MAC_CIPSOV4_DEL msgtype 1408

#
Message type
1408
Fires
Emitted by default (no audit rule required)

Description

NetLabel: del CIPSOv4 (Commercial Internet Protocol Security Option) DOI (Domain of Interpretation) entry

Fields #

NameDescription
auidlogin user ID
seslogin session ID
subjlspp subject's context string
cipso_doiCIPSO domain of interpretation
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "auid": "1000",
    "cipso_doi": "100",
    "res": "1",
    "ses": "15",
    "subj": "unconfined"
  },
  "raw": [
    "node=JD-debian-12-workstation type=MAC_CIPSOV4_DEL msg=audit(1781632713.512:2112730): netlabel: auid=1000 ses=15 subj=unconfined cipso_doi=100 res=1",
    "AUID=\"debian\"",
    "node=JD-debian-12-workstation type=SYSCALL msg=audit(1781632713.512:2112730): arch=c000003e syscall=46 success=yes exit=28 a0=3 a1=7ffdb3875560 a2=0 a3=7f164ef2f050 items=0 ppid=56702 pid=56730 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=15 comm=\"netlabelctl\" exe=\"/usr/sbin/netlabelctl\" subj=unconfined key=\"T1071_msg_transfer\"",
    "ARCH=x86_64 SYSCALL=sendmsg AUID=\"debian\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
    "node=JD-debian-12-workstation type=SOCKADDR msg=audit(1781632713.512:2112730): saddr=100000000000000000000000",
    "SADDR={ saddr_fam=netlink nlnk-fam=16 nlnk-pid=0 }",
    "node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781632713.512:2112730): proctitle=6E65746C6162656C63746C00636970736F76340064656C00646F693A313030"
  ],
  "record_type": "MAC_CIPSOV4_DEL"
}

References #

MAC_MAP_ADD msgtype 1409

#
Message type
1409
Fires
Emitted by default (no audit rule required)

Description

NetLabel: add LSM (Linux Security Module) domain mapping

Fields #

NameDescription
auidlogin user ID
seslogin session ID
subjlspp subject's context string
nlbl_domainNetLabel domain mapping name
nlbl_protocolNetLabel protocol for the domain mapping
cipso_doiCIPSO domain of interpretation
calipso_doiCALIPSO domain of interpretation
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "auid": "0",
    "nlbl_domain": "(default)",
    "nlbl_protocol": "unlbl",
    "res": "1",
    "ses": "0",
    "subj": "kernel"
  },
  "raw": [
    "node=JD-debian-12-workstation type=MAC_MAP_ADD msg=audit(1781634163.940:2): netlabel: auid=0 ses=0 subj=kernel nlbl_domain=(default) nlbl_protocol=unlbl res=1",
    "AUID=\"root\""
  ],
  "record_type": "MAC_MAP_ADD"
}

References #

MAC_MAP_DEL msgtype 1410

#
Message type
1410
Fires
Emitted by default (no audit rule required)

Description

NetLabel: del LSM (Linux Security Module) domain mapping

Fields #

NameDescription
auidlogin user ID
seslogin session ID
subjlspp subject's context string
nlbl_domainNetLabel domain mapping name
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "auid": "1000",
    "nlbl_domain": "catalog.test",
    "res": "1",
    "ses": "15",
    "subj": "unconfined"
  },
  "raw": [
    "node=JD-debian-12-workstation type=MAC_MAP_DEL msg=audit(1781632713.508:2112660): netlabel: auid=1000 ses=15 subj=unconfined nlbl_domain=catalog.test res=1",
    "AUID=\"debian\"",
    "node=JD-debian-12-workstation type=SYSCALL msg=audit(1781632713.508:2112660): arch=c000003e syscall=46 success=yes exit=40 a0=3 a1=7ffe062e4fc0 a2=0 a3=7fde3f195050 items=0 ppid=56702 pid=56728 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=15 comm=\"netlabelctl\" exe=\"/usr/sbin/netlabelctl\" subj=unconfined key=\"T1071_msg_transfer\"",
    "ARCH=x86_64 SYSCALL=sendmsg AUID=\"debian\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
    "node=JD-debian-12-workstation type=SOCKADDR msg=audit(1781632713.508:2112660): saddr=100000000000000000000000",
    "SADDR={ saddr_fam=netlink nlnk-fam=16 nlnk-pid=0 }",
    "node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781632713.508:2112660): proctitle=6E65746C6162656C63746C006D61700064656C00646F6D61696E3A636174616C6F672E74657374"
  ],
  "record_type": "MAC_MAP_DEL"
}

References #

MAC_IPSEC_ADDSA msgtype 1411

#
Message type
1411
Fires
Emitted by default (no audit rule required)

Description

Not used

MAC_IPSEC_DELSA msgtype 1412

#
Message type
1412
Fires
Emitted by default (no audit rule required)

Description

Not used

MAC_IPSEC_ADDSPD msgtype 1413

#
Message type
1413
Fires
Emitted by default (no audit rule required)

Description

Not used

MAC_IPSEC_DELSPD msgtype 1414

#
Message type
1414
Fires
Emitted by default (no audit rule required)

Description

Not used

MAC_IPSEC_EVENT msgtype 1415

#
Message type
1415
Fires
Emitted by default (no audit rule required)

Description

Audit an IPsec event

Fields #

NameDescription
opthe operation being performed that is audited
auidlogin user ID
seslogin session ID
subjlspp subject's context string
srcsource address of the IPsec security association
dstdestination address of the IPsec security association
spiIPsec Security Parameter Index
src_prefixlensource address prefix length
dst_prefixlendestination address prefix length
sec_objsecurity context label of the IPsec object
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "auid": "1000",
    "dst": "192.0.2.2",
    "op": "SAD-add",
    "res": "1",
    "ses": "15",
    "spi": "1(0x1)",
    "src": "192.0.2.1",
    "subj": "unconfined"
  },
  "raw": [
    "node=JD-debian-12-workstation type=MAC_IPSEC_EVENT msg=audit(1781632420.375:1883324): op=SAD-add auid=1000 ses=15 subj=unconfined src=192.0.2.1 dst=192.0.2.2 spi=1(0x1) res=1",
    "AUID=\"debian\"",
    "node=JD-debian-12-workstation type=SYSCALL msg=audit(1781632420.375:1883324): arch=c000003e syscall=46 success=yes exit=432 a0=4 a1=7ffdf4dabb80 a2=0 a3=7ffdf4dabc04 items=0 ppid=51449 pid=51553 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=15 comm=\"ip\" exe=\"/usr/bin/ip\" subj=unconfined key=\"T1071_msg_transfer\"",
    "ARCH=x86_64 SYSCALL=sendmsg AUID=\"debian\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
    "node=JD-debian-12-workstation type=SOCKADDR msg=audit(1781632420.375:1883324): saddr=100000000000000000000000",
    "SADDR={ saddr_fam=netlink nlnk-fam=16 nlnk-pid=0 }",
    "node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781632420.375:1883324): proctitle=6970007866726D0073746174650061646400737263003139322E302E322E3100647374003139322E302E322E320070726F746F006573700073706900307831006D6F6465007472616E73706F72740061757468007368613235360030783031303230333034303530363037303830393061306230633064306530663130313131"
  ],
  "record_type": "MAC_IPSEC_EVENT"
}

MAC_UNLBL_STCADD msgtype 1416

#
Message type
1416
Fires
Emitted by default (no audit rule required)

Description

NetLabel: add a static label

Fields #

NameDescription
auidlogin user ID
seslogin session ID
subjlspp subject's context string
netifnetwork interface the static NetLabel mapping is bound to (absent for default all-interface entries)
srcsource address of the static NetLabel unlabeled-traffic mapping
src_prefixlensource address prefix length
sec_objLSM security context assigned to unlabeled traffic matching this static NetLabel mapping
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "auid": "1000",
    "res": "1",
    "sec_obj": "system_u:object_r:unlabeled_t:s0",
    "ses": "1",
    "src": "198.51.100.0",
    "src_prefixlen": "24",
    "subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023"
  },
  "raw": [
    "node=JD-debian-12-workstation type=MAC_UNLBL_STCADD msg=audit(1781635211.640:942744): netlabel: auid=1000 ses=1 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 src=198.51.100.0 src_prefixlen=24 sec_obj=system_u:object_r:unlabeled_t:s0 res=1",
    "AUID=\"debian\""
  ],
  "record_type": "MAC_UNLBL_STCADD"
}

References #

MAC_UNLBL_STCDEL msgtype 1417

#
Message type
1417
Fires
Emitted by default (no audit rule required)

Description

NetLabel: del a static label

Fields #

NameDescription
auidlogin user ID
seslogin session ID
subjlspp subject's context string
netifnetwork interface the static NetLabel mapping is bound to (absent for default all-interface entries)
srcsource address of the static NetLabel unlabeled-traffic mapping
src_prefixlensource address prefix length
sec_objLSM security context assigned to unlabeled traffic matching this static NetLabel mapping
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "auid": "1000",
    "res": "1",
    "sec_obj": "system_u:object_r:unlabeled_t:s0",
    "ses": "1",
    "src": "198.51.100.0",
    "src_prefixlen": "24",
    "subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023"
  },
  "raw": [
    "node=JD-debian-12-workstation type=MAC_UNLBL_STCDEL msg=audit(1781635211.644:942826): netlabel: auid=1000 ses=1 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 src=198.51.100.0 src_prefixlen=24 sec_obj=system_u:object_r:unlabeled_t:s0 res=1",
    "AUID=\"debian\""
  ],
  "record_type": "MAC_UNLBL_STCDEL"
}

References #

MAC_CALIPSO_ADD msgtype 1418

#
Message type
1418
Fires
Emitted by default (no audit rule required)

Description

NetLabel: add CALIPSO DOI (Domain of Interpretation) entry

Fields #

NameDescription
auidlogin user ID
seslogin session ID
subjlspp subject's context string
calipso_doiCALIPSO domain of interpretation
calipso_typeCALIPSO mapping type
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "auid": "1000",
    "calipso_doi": "200",
    "calipso_type": "pass",
    "res": "1",
    "ses": "15",
    "subj": "unconfined"
  },
  "raw": [
    "node=JD-debian-12-workstation type=MAC_CALIPSO_ADD msg=audit(1781632713.500:2112517): netlabel: auid=1000 ses=15 subj=unconfined calipso_doi=200 calipso_type=pass res=1",
    "AUID=\"debian\"",
    "node=JD-debian-12-workstation type=SYSCALL msg=audit(1781632713.500:2112517): arch=c000003e syscall=46 success=yes exit=36 a0=3 a1=7ffd0bc59260 a2=0 a3=7f524c214050 items=0 ppid=56702 pid=56724 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=15 comm=\"netlabelctl\" exe=\"/usr/sbin/netlabelctl\" subj=unconfined key=\"T1071_msg_transfer\"",
    "ARCH=x86_64 SYSCALL=sendmsg AUID=\"debian\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
    "node=JD-debian-12-workstation type=SOCKADDR msg=audit(1781632713.500:2112517): saddr=100000000000000000000000",
    "SADDR={ saddr_fam=netlink nlnk-fam=16 nlnk-pid=0 }",
    "node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781632713.500:2112517): proctitle=6E65746C6162656C63746C0063616C6970736F00616464007061737300646F693A323030"
  ],
  "record_type": "MAC_CALIPSO_ADD"
}

References #

MAC_CALIPSO_DEL msgtype 1419

#
Message type
1419
Fires
Emitted by default (no audit rule required)

Description

NetLabel: delete CALIPSO DOI (Domain of Interpretation) entry

Fields #

NameDescription
auidlogin user ID
seslogin session ID
subjlspp subject's context string
calipso_doiCALIPSO domain of interpretation
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "auid": "1000",
    "calipso_doi": "200",
    "res": "1",
    "ses": "15",
    "subj": "unconfined"
  },
  "raw": [
    "node=JD-debian-12-workstation type=MAC_CALIPSO_DEL msg=audit(1781632713.516:2112798): netlabel: auid=1000 ses=15 subj=unconfined calipso_doi=200 res=1",
    "AUID=\"debian\"",
    "node=JD-debian-12-workstation type=SYSCALL msg=audit(1781632713.516:2112798): arch=c000003e syscall=46 success=yes exit=28 a0=3 a1=7ffddedd1830 a2=0 a3=7f1209fc6050 items=0 ppid=56702 pid=56732 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=15 comm=\"netlabelctl\" exe=\"/usr/sbin/netlabelctl\" subj=unconfined key=\"T1071_msg_transfer\"",
    "ARCH=x86_64 SYSCALL=sendmsg AUID=\"debian\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
    "node=JD-debian-12-workstation type=SOCKADDR msg=audit(1781632713.516:2112798): saddr=100000000000000000000000",
    "SADDR={ saddr_fam=netlink nlnk-fam=16 nlnk-pid=0 }",
    "node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781632713.516:2112798): proctitle=6E65746C6162656C63746C0063616C6970736F0064656C00646F693A323030"
  ],
  "record_type": "MAC_CALIPSO_DEL"
}

References #

IPE_ACCESS msgtype 1420

#
Message type
1420
Fires
Emitted by default (no audit rule required)

Description

Integrity Policy Enforcement (IPE) access decision (denial or grant)

Fields #

NameDescription
ipe_opIPE operation being evaluated
ipe_hookIPE enforcement hook point
enforcingwhether enforcing mode is active (1) or permissive (0)
pidprocess ID
commcommand line program name
pathfile system path name
devdevice identifier
inoinode number
rulethe policy rule that matched, quoted verbatim; the op= and action= (ALLOW/DENY) tokens inside the quotes are sub-tokens of this value, not independent record fields

Example Audit Record #

{
  "fields": {
    "comm": "kexec",
    "dev": "vda1",
    "enforcing": "1",
    "ino": "2490727",
    "ipe_hook": "KERNEL_READ",
    "ipe_op": "KEXEC_IMAGE",
    "path": "/boot/vmlinuz-6.19.14-ipe2",
    "pid": "5215",
    "rule": "op=KEXEC_IMAGE action=DENY"
  },
  "raw": [
    "node=JD-debian-12-workstation type=UNKNOWN[1420] msg=audit(1781728753.988:612193): ipe_op=KEXEC_IMAGE ipe_hook=KERNEL_READ enforcing=1 pid=5215 comm=\"kexec\" path=\"/boot/vmlinuz-6.19.14-ipe2\" dev=\"vda1\" ino=2490727 rule=\"op=KEXEC_IMAGE action=DENY\""
  ],
  "record_type": "IPE_ACCESS"
}

References #

IPE_CONFIG_CHANGE msgtype 1421

#
Message type
1421
Fires
Emitted by default (no audit rule required)

Description

IPE active policy change

Fields #

NameDescription
old_active_pol_namepreviously active IPE policy name
old_active_pol_versionpreviously active IPE policy version
old_policy_digestcontent digest of the previously active IPE policy
new_active_pol_namenewly active IPE policy name
new_active_pol_versionnewly active IPE policy version
new_policy_digestcontent digest of the newly active IPE policy
auidlogin user ID
seslogin session ID
lsmsecurity module that produced the record (always ipe)
resresult of the audited operation (hardcoded 1; activation only audits on success)

Example Audit Record #

{
  "fields": {
    "auid": "1000",
    "lsm": "ipe",
    "new_active_pol_name": "dwipe2",
    "new_active_pol_version": "1.0.0",
    "new_policy_digest": "sha256:51304269195B26473ACFAF49F0392662A180346AFEA5BFA6D09DD95D748A6B9F",
    "old_active_pol_name": "dwipe",
    "old_active_pol_version": "1.0.0",
    "old_policy_digest": "sha256:1CEE14128A111BD8D0A157CFE6025AB6119DF0589039DA709A949286ABBC6CA5",
    "res": "1",
    "ses": "27"
  },
  "raw": [
    "node=JD-debian-12-workstation type=UNKNOWN[1421] msg=audit(1781728753.955:612192): old_active_pol_name=\"dwipe\" old_active_pol_version=1.0.0 old_policy_digest=sha256:1CEE14128A111BD8D0A157CFE6025AB6119DF0589039DA709A949286ABBC6CA5 new_active_pol_name=\"dwipe2\" new_active_pol_version=1.0.0 new_policy_digest=sha256:51304269195B26473ACFAF49F0392662A180346AFEA5BFA6D09DD95D748A6B9F auid=1000 ses=27 lsm=ipe res=1",
    "AUID=\"debian\""
  ],
  "record_type": "IPE_CONFIG_CHANGE"
}

References #

IPE_POLICY_LOAD msgtype 1422

#
Message type
1422
Fires
Emitted by default (no audit rule required)

Description

IPE policy load

Fields #

NameDescription
policy_nameIPE policy name
policy_versionIPE policy version
policy_digestIPE policy content digest
auidlogin user ID
seslogin session ID
lsmsecurity module that produced the record (selinux, apparmor, ...)
resresult of the audited operation(success/fail)
errnoerror code of the audited operation

Example Audit Record #

{
  "fields": {
    "auid": "1000",
    "errno": "0",
    "lsm": "ipe",
    "policy_digest": "sha256:51304269195B26473ACFAF49F0392662A180346AFEA5BFA6D09DD95D748A6B9F",
    "policy_name": "dwipe2",
    "policy_version": "1.0.0",
    "res": "1",
    "ses": "27"
  },
  "raw": [
    "node=JD-debian-12-workstation type=UNKNOWN[1422] msg=audit(1781728753.951:612191): policy_name=\"dwipe2\" policy_version=1.0.0 policy_digest=sha256:51304269195B26473ACFAF49F0392662A180346AFEA5BFA6D09DD95D748A6B9F auid=1000 ses=27 lsm=ipe res=1 errno=0",
    "AUID=\"debian\""
  ],
  "record_type": "IPE_POLICY_LOAD"
}

References #

LANDLOCK_ACCESS msgtype 1423

#
Message type
1423
Fires
Emitted by default (no audit rule required)

Description

Landlock access denial

Fields #

NameDescription
domainLandlock domain identifier
blockersLandlock access rights that blocked the operation
pathfile system path name
devdevice identifier
inoinode number

Example Audit Record #

{
  "fields": {
    "blockers": "fs.read_file",
    "dev": "vda1",
    "domain": "1dd9c92db",
    "ino": "11011796",
    "path": "/etc/ld.so.cache"
  },
  "raw": [
    "node=JD-debian-12-workstation type=UNKNOWN[1423] msg=audit(1781666556.057:244234): domain=1dd9c92db blockers=fs.read_file path=\"/etc/ld.so.cache\" dev=\"vda1\" ino=11011796",
    "node=JD-debian-12-workstation type=UNKNOWN[1424] msg=audit(1781666556.057:244234): domain=1dd9c92db status=allocated mode=enforcing pid=6720 uid=1000 exe=\"/tmp/sb2\" comm=\"sb2\"",
    "UID=\"debian\""
  ],
  "record_type": "LANDLOCK_ACCESS"
}

References #

LANDLOCK_DOMAIN msgtype 1424

#
Message type
1424
Fires
Emitted by default (no audit rule required)

Description

Landlock domain allocation or deallocation status

Fields #

NameDescription
domainLandlock domain identifier
statusLandlock domain status (allocated or deallocated)
modeLandlock domain enforcement mode (enforcing)
pidprocess ID
uiduser ID
exeexecutable name
commcommand line program name
denialscount of Landlock denials attributed to the domain

Example Audit Record #

{
  "fields": {
    "denials": "2",
    "domain": "1dd9c92e9",
    "status": "deallocated"
  },
  "raw": [
    "node=JD-debian-12-workstation type=UNKNOWN[1424] msg=audit(1781666597.958:244302): domain=1dd9c92e9 status=deallocated denials=2"
  ],
  "record_type": "LANDLOCK_DOMAIN"
}

References #

MAC_TASK_CONTEXTS msgtype 1425

#
Message type
1425
Fires
Emitted by default (no audit rule required)

Description

Subject security contexts when multiple LSMs are active

References #

MAC_OBJ_CONTEXTS msgtype 1426

#
Message type
1426
Fires
Emitted by default (no audit rule required)

Description

Object security contexts when multiple LSMs are active

References #

APPARMOR msgtype 1500

#
Message type
1500
Fires
Emitted by default (no audit rule required)

Description

AppArmor LSM audit event

APPARMOR_AUDIT msgtype 1501

#
Message type
1501
Fires
Emitted by default (no audit rule required)

Description

AppArmor access decision logged in audit mode

APPARMOR_ALLOWED msgtype 1502

#
Message type
1502
Fires
Emitted by default (no audit rule required)

Description

AppArmor access allowed (complain or learning mode)

APPARMOR_DENIED msgtype 1503

#
Message type
1503
Fires
Emitted by default (no audit rule required)

Description

AppArmor access denied in enforce mode

APPARMOR_HINT msgtype 1504

#
Message type
1504
Fires
Emitted by default (no audit rule required)

Description

AppArmor reserved audit type (unused in the current kernel)

APPARMOR_STATUS msgtype 1505

#
Message type
1505
Fires
Emitted by default (no audit rule required)

Description

AppArmor policy load or status change

APPARMOR_ERROR msgtype 1506

#
Message type
1506
Fires
Emitted by default (no audit rule required)

Description

AppArmor internal error

APPARMOR_KILL msgtype 1507

#
Message type
1507
Fires
Emitted by default (no audit rule required)

Description

AppArmor access denied with task kill

ANOM_PROMISCUOUS msgtype 1700

#
Message type
1700
Fires
Emitted by default (no audit rule required)

Description

Device changed promiscuous mode

Fields #

NameDescription
devNetwork device name
promPromiscuous mode state (256 for on, 0 for off)
old_promPrevious promiscuous mode state
auidAudit user ID (login UID)
uidUser ID
gidGroup ID
sesSession ID

Example Audit Record #

{
  "fields": {
    "auid": "4294967295",
    "dev": "vethe2919bc",
    "gid": "0",
    "old_prom": "0",
    "prom": "256",
    "ses": "4294967295",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=ANOM_PROMISCUOUS msg=audit(1781634257.762:512597): dev=vethe2919bc prom=256 old_prom=0 auid=4294967295 uid=0 gid=0 ses=4294967295",
    "AUID=\"unset\" UID=\"root\" GID=\"root\"",
    "node=JD-debian-12-workstation type=SYSCALL msg=audit(1781634257.762:512597): arch=c000003e syscall=44 success=yes exit=40 a0=f a1=2442de196c00 a2=28 a3=0 items=0 ppid=1 pid=671 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=\"dockerd\" exe=\"/usr/bin/dockerd\" subj=system_u:system_r:initrc_t:s0 key=\"T1071_data_transfer\"",
    "ARCH=x86_64 SYSCALL=sendto AUID=\"unset\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
    "node=JD-debian-12-workstation type=SOCKADDR msg=audit(1781634257.762:512597): saddr=100000000000000000000000",
    "SADDR={ saddr_fam=netlink nlnk-fam=16 nlnk-pid=0 }",
    "node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781634257.762:512597): proctitle=2F7573722F62696E2F646F636B657264002D480066643A2F2F002D2D636F6E7461696E6572643D2F72756E2F636F6E7461696E6572642F636F6E7461696E6572642E736F636B"
  ],
  "record_type": "ANOM_PROMISCUOUS"
}

References #

ANOM_ABEND msgtype 1701

#
Message type
1701
Fires
Emitted by default (no audit rule required)

Description

Process ended abnormally

Fields #

NameDescription
auidlogin user ID
uiduser ID
gidgroup ID
seslogin session ID
subjlspp subject's context string
pidprocess ID
commcommand line program name
exeexecutable name
sigsignal number
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "auid": "1000",
    "comm": "python3",
    "exe": "/usr/bin/python3.11",
    "gid": "0",
    "pid": "2916",
    "res": "1",
    "ses": "1",
    "sig": "6",
    "subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=ANOM_ABEND msg=audit(1781634272.640:540321): auid=1000 uid=0 gid=0 ses=1 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 pid=2916 comm=\"python3\" exe=\"/usr/bin/python3.11\" sig=6 res=1",
    "AUID=\"debian\" UID=\"root\" GID=\"root\""
  ],
  "record_type": "ANOM_ABEND"
}

References #

ANOM_LINK msgtype 1702

#
Message type
1702
Fires
Emitted by default (no audit rule required)

Description

Suspicious use of file links

Fields #

NameDescription
opthe operation being performed that is audited
ppidparent process ID
pidprocess ID
auidlogin user ID
uiduser ID
gidgroup ID
euideffective user ID
suidsent user ID
fsuidfile system user ID
egideffective group ID
sgidset group ID
fsgidfile system group ID
ttytty udevice the user is running programs on
seslogin session ID
commcommand line program name
exeexecutable name
subjlspp subject's context string
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "auid": "1000",
    "comm": "python3",
    "egid": "65534",
    "euid": "65534",
    "exe": "/usr/bin/python3.11",
    "fsgid": "65534",
    "fsuid": "65534",
    "gid": "65534",
    "op": "linkat",
    "pid": "2923",
    "ppid": "2922",
    "res": "0",
    "ses": "1",
    "sgid": "65534",
    "subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
    "suid": "65534",
    "tty": "(none)",
    "uid": "65534"
  },
  "raw": [
    "node=JD-debian-12-workstation type=ANOM_LINK msg=audit(1781634272.680:540622): op=linkat ppid=2922 pid=2923 auid=1000 uid=65534 gid=65534 euid=65534 suid=65534 fsuid=65534 egid=65534 sgid=65534 fsgid=65534 tty=(none) ses=1 comm=\"python3\" exe=\"/usr/bin/python3.11\" subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 res=0",
    "AUID=\"debian\" UID=\"nobody\" GID=\"nogroup\" EUID=\"nobody\" SUID=\"nobody\" FSUID=\"nobody\" EGID=\"nogroup\" SGID=\"nogroup\" FSGID=\"nogroup\"",
    "node=JD-debian-12-workstation type=SYSCALL msg=audit(1781634272.680:540622): arch=c000003e syscall=86 success=no exit=-1 a0=7fd459e6e570 a1=7fd459e6e540 a2=0 a3=7fd459e9ba18 items=2 ppid=2922 pid=2923 auid=1000 uid=65534 gid=65534 euid=65534 suid=65534 fsuid=65534 egid=65534 sgid=65534 fsgid=65534 tty=(none) ses=1 comm=\"python3\" exe=\"/usr/bin/python3.11\" subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key=\"T1136_identity_file\"",
    "ARCH=x86_64 SYSCALL=link AUID=\"debian\" UID=\"nobody\" GID=\"nogroup\" EUID=\"nobody\" SUID=\"nobody\" FSUID=\"nobody\" EGID=\"nogroup\" SGID=\"nogroup\" FSGID=\"nogroup\"",
    "node=JD-debian-12-workstation type=CWD msg=audit(1781634272.680:540622): cwd=\"/home/debian\"",
    "node=JD-debian-12-workstation type=PATH msg=audit(1781634272.680:540622): item=0 name=\"/tmp/\" inode=1835009 dev=fe:01 mode=041777 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:tmp_t:s0 nametype=PARENT cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
    "OUID=\"root\" OGID=\"root\"",
    "node=JD-debian-12-workstation type=PATH msg=audit(1781634272.680:540622): item=1 name=\"/etc/passwd\" inode=11011764 dev=fe:01 mode=0100644 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:etc_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
    "OUID=\"root\" OGID=\"root\"",
    "node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781634272.680:540622): proctitle=7375646F002D75006E6F626F647900707974686F6E33002D6300696D706F7274206F730A7472793A206F732E6C696E6B28272F6574632F706173737764272C272F746D702F72336C696E6B27290A657863657074204F534572726F723A2070617373"
  ],
  "record_type": "ANOM_LINK"
}

References #

ANOM_CREAT msgtype 1703

#
Message type
1703
Fires
Emitted by default (no audit rule required)

Description

Suspicious file creation

Fields #

NameDescription
opthe operation being performed that is audited
ppidparent process ID
pidprocess ID
auidlogin user ID
uiduser ID
gidgroup ID
euideffective user ID
suidsent user ID
fsuidfile system user ID
egideffective group ID
sgidset group ID
fsgidfile system group ID
ttytty udevice the user is running programs on
seslogin session ID
commcommand line program name
exeexecutable name
subjlspp subject's context string
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "auid": "1000",
    "comm": "bash",
    "egid": "65534",
    "euid": "65534",
    "exe": "/usr/bin/bash",
    "fsgid": "65534",
    "fsuid": "65534",
    "gid": "65534",
    "op": "sticky_create",
    "pid": "84413",
    "ppid": "84412",
    "res": "0",
    "ses": "49",
    "sgid": "65534",
    "subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
    "suid": "65534",
    "tty": "(none)",
    "uid": "65534"
  },
  "raw": [
    "node=JD-debian-12-workstation type=ANOM_CREAT msg=audit(1781674283.166:244935): op=sticky_create ppid=84412 pid=84413 auid=1000 uid=65534 gid=65534 euid=65534 suid=65534 fsuid=65534 egid=65534 sgid=65534 fsgid=65534 tty=(none) ses=49 comm=\"bash\" exe=\"/usr/bin/bash\" subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 res=0",
    "AUID=\"debian\" UID=\"nobody\" GID=\"nogroup\" EUID=\"nobody\" SUID=\"nobody\" FSUID=\"nobody\" EGID=\"nogroup\" SGID=\"nogroup\" FSGID=\"nogroup\"",
    "node=JD-debian-12-workstation type=SYSCALL msg=audit(1781674283.166:244935): arch=c000003e syscall=257 success=no exit=-13 a0=ffffff9c a1=634277626d20 a2=241 a3=1b6 items=1 ppid=84412 pid=84413 auid=1000 uid=65534 gid=65534 euid=65534 suid=65534 fsuid=65534 egid=65534 sgid=65534 fsgid=65534 tty=(none) ses=49 comm=\"bash\" exe=\"/usr/bin/bash\" subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key=\"anomcreat\"",
    "ARCH=x86_64 SYSCALL=openat AUID=\"debian\" UID=\"nobody\" GID=\"nogroup\" EUID=\"nobody\" SUID=\"nobody\" FSUID=\"nobody\" EGID=\"nogroup\" SGID=\"nogroup\" FSGID=\"nogroup\"",
    "node=JD-debian-12-workstation type=CWD msg=audit(1781674283.166:244935): cwd=\"/home/debian\"",
    "node=JD-debian-12-workstation type=PATH msg=audit(1781674283.166:244935): item=0 name=\"/tmp/stickytest/victim\" inode=4757372 dev=fd:01 mode=0100666 ouid=1 ogid=1 rdev=00:00 obj=unconfined_u:object_r:user_tmp_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
    "OUID=\"daemon\" OGID=\"daemon\"",
    "node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781674283.166:244935): proctitle=62617368002D63006563686F20686178203E202F746D702F737469636B79746573742F76696374696D"
  ],
  "record_type": "ANOM_CREAT"
}

References #

INTEGRITY_DATA msgtype 1800

#
Message type
1800
Fires
Emitted by default (no audit rule required)

Description

Data integrity verification

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
causereason the integrity operation produced this result
commcommand line program name
namefile name in avcs
devdevice identifier
inoinode number
resresult of the audited operation(success/fail)
errnoerror code of the audited operation

Example Audit Record #

{
  "fields": {
    "auid": "4294967295",
    "cause": "missing-hash",
    "comm": "erts_dios_2",
    "dev": "overlay",
    "errno": "0",
    "ino": "3816158",
    "name": "/opt/erlang/lib/erlang/lib/kernel-9.2.4.10/ebin/inet6_tcp.beam",
    "op": "appraise_data",
    "pid": "1464",
    "res": "0",
    "ses": "4294967295",
    "subj": "system_u:system_r:initrc_t:s0",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=INTEGRITY_DATA msg=audit(1781635478.877:552310): pid=1464 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:initrc_t:s0 op=appraise_data cause=missing-hash comm=\"erts_dios_2\" name=\"/opt/erlang/lib/erlang/lib/kernel-9.2.4.10/ebin/inet6_tcp.beam\" dev=\"overlay\" ino=3816158 res=0 errno=0",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "INTEGRITY_DATA"
}

INTEGRITY_METADATA msgtype 1801

#
Message type
1801
Fires
Emitted by default (no audit rule required)

Description

Metadata integrity verification

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
causereason the integrity operation produced this result
commcommand line program name
namefile name in avcs
devdevice identifier
inoinode number
resresult of the audited operation(success/fail)
errnoerror code of the audited operation

Example Audit Record #

{
  "fields": {
    "auid": "4294967295",
    "cause": "no_label",
    "comm": "dockerd",
    "dev": "vda1",
    "errno": "0",
    "ino": "4756199",
    "name": "hostname",
    "op": "appraise_metadata",
    "pid": "737",
    "res": "0",
    "ses": "4294967295",
    "subj": "system_u:system_r:initrc_t:s0",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=INTEGRITY_METADATA msg=audit(1781644799.132:3070202): pid=737 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:initrc_t:s0 op=appraise_metadata cause=no_label comm=\"dockerd\" name=\"hostname\" dev=\"vda1\" ino=4756199 res=0 errno=0",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "INTEGRITY_METADATA"
}

References #

INTEGRITY_STATUS msgtype 1802

#
Message type
1802
Fires
Emitted by default (no audit rule required)

Description

Integrity enable status

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
causereason the integrity operation produced this result
commcommand line program name
resresult of the audited operation(success/fail)
errnoerror code of the audited operation

Example Audit Record #

{
  "fields": {
    "auid": "1000",
    "cause": "completed",
    "comm": "tee",
    "errno": "0",
    "op": "policy_update",
    "pid": "76552",
    "res": "1",
    "ses": "15",
    "subj": "unconfined",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=INTEGRITY_STATUS msg=audit(1781633139.102:2169048): pid=76552 uid=0 auid=1000 ses=15 subj=unconfined op=policy_update cause=completed comm=\"tee\" res=1 errno=0",
    "UID=\"root\" AUID=\"debian\""
  ],
  "record_type": "INTEGRITY_STATUS"
}

INTEGRITY_HASH msgtype 1803

#
Message type
1803
Fires
Emitted by default (no audit rule required)

Description

Integrity HASH type

INTEGRITY_PCR msgtype 1804

#
Message type
1804
Fires
Emitted by default (no audit rule required)

Description

PCR (Platform Configuration Register) invalidation messages

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
causereason the integrity operation produced this result
commcommand line program name
namefile name in avcs
devdevice identifier
inoinode number
resresult of the audited operation(success/fail)
errnoerror code of the audited operation

Example Audit Record #

{
  "fields": {
    "auid": "4294967295",
    "cause": "open_writers",
    "comm": "journalctl",
    "dev": "vda1",
    "errno": "0",
    "ino": "2887054",
    "name": "/var/log/journal/370e939bc3344c2e8efe8cb82c4bc43a/system.journal",
    "op": "invalid_pcr",
    "pid": "744",
    "res": "1",
    "ses": "4294967295",
    "subj": "system_u:system_r:initrc_t:s0",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=INTEGRITY_PCR msg=audit(1781635957.029:400312): pid=744 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:initrc_t:s0 op=invalid_pcr cause=open_writers comm=\"journalctl\" name=\"/var/log/journal/370e939bc3344c2e8efe8cb82c4bc43a/system.journal\" dev=\"vda1\" ino=2887054 res=1 errno=0",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "INTEGRITY_PCR"
}

INTEGRITY_RULE msgtype 1805

#
Message type
1805
Fires
Emitted by default (no audit rule required)

Description

Integrity Policy action

Fields #

NameDescription
filefile name
hashhash of the measured file (from an IMA policy rule with the audit action)
ppidparent process ID
pidprocess ID
auidlogin user ID
uiduser ID
gidgroup ID
euideffective user ID
suidsent user ID
fsuidfile system user ID
egideffective group ID
sgidset group ID
fsgidfile system group ID
ttytty udevice the user is running programs on
seslogin session ID
commcommand line program name
exeexecutable name
subjlspp subject's context string

Example Audit Record #

{
  "fields": {
    "auid": "4294967295",
    "comm": "sh",
    "egid": "0",
    "euid": "0",
    "exe": "/bin/busybox",
    "file": "/health_check.sh",
    "fsgid": "0",
    "fsuid": "0",
    "gid": "0",
    "hash": "sha256:38744345348ee83905d0f018826d9baa84704d55c3ed1babe13c62e32064be3a",
    "pid": "76553",
    "ppid": "76539",
    "ses": "4294967295",
    "sgid": "0",
    "subj": "unconfined",
    "suid": "0",
    "tty": "(none)",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=INTEGRITY_RULE msg=audit(1781633139.126:2169049): file=\"/health_check.sh\" hash=\"sha256:38744345348ee83905d0f018826d9baa84704d55c3ed1babe13c62e32064be3a\" ppid=76539 pid=76553 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=\"sh\" exe=\"/bin/busybox\" subj=unconfined",
    "AUID=\"unset\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\""
  ],
  "record_type": "INTEGRITY_RULE"
}

References #

INTEGRITY_EVM_XATTR msgtype 1806

#
Message type
1806
Fires
Emitted by default (no audit rule required)

Description

EVM XATTRS modifications

Fields #

NameDescription
xattrextended attribute name involved in the EVM operation
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "res": "0",
    "xattr": "security.detectionwiki"
  },
  "raw": [
    "node=JD-debian-12-workstation type=INTEGRITY_EVM_XATTR msg=audit(1781674118.342:244839): xattr=\"security.detectionwiki\" res=0"
  ],
  "record_type": "INTEGRITY_EVM_XATTR"
}

References #

INTEGRITY_POLICY_RULE msgtype 1807

#
Message type
1807
Fires
Emitted by default (no audit rule required)

Description

Integrity Policy rule

Fields #

NameDescription
actionpolicy action taken (for example ALLOW or DENY)
resresult of the audited operation(success/fail)
funcIMA policy hook the rule applies to
maskIMA policy permission mask the rule matches

Example Audit Record #

{
  "fields": {
    "action": "measure",
    "func": "BPRM_CHECK",
    "res": "1"
  },
  "raw": [
    "node=JD-debian-12-workstation type=INTEGRITY_POLICY_RULE msg=audit(1781633139.102:2169045): action=measure func=BPRM_CHECK res=1"
  ],
  "record_type": "INTEGRITY_POLICY_RULE"
}

References #

INTEGRITY_USERSPACE msgtype 1808

#
Message type
1808
Fires
Emitted by default (no audit rule required)

Description

IMA appraisal of userspace-supplied data

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
causereason the integrity operation produced this result
commcommand line program name
namefile name in avcs
devdevice identifier
inoinode number
resresult of the audited operation(success/fail)
errnoerror code of the audited operation

Example Audit Record #

{
  "fields": {
    "auid": "1000",
    "cause": "missing-hash",
    "comm": "dwtrigger",
    "dev": "vda1",
    "errno": "0",
    "ino": "2887116",
    "name": "/var/tmp/dwexec",
    "op": "appraise_data",
    "pid": "100540",
    "res": "0",
    "ses": "72",
    "subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=UNKNOWN[1808] msg=audit(1781719000.505:245392): pid=100540 uid=0 auid=1000 ses=72 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 op=appraise_data cause=missing-hash comm=\"dwtrigger\" name=\"/var/tmp/dwexec\" dev=\"vda1\" ino=2887116 res=0 errno=0",
    "UID=\"root\" AUID=\"debian\"",
    "node=JD-debian-12-workstation type=SYSCALL msg=audit(1781719000.505:245392): arch=c000003e syscall=322 success=no exit=-13 a0=3 a1=612293e7800d a2=7ffee3d07a58 a3=7ffee3d07a50 items=1 ppid=100522 pid=100540 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=72 comm=\"dwtrigger\" exe=\"/var/tmp/dwtrigger\" subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key=\"integuser\"",
    "ARCH=x86_64 SYSCALL=execveat AUID=\"debian\" UID=\"root\" GID=\"root\" EUID=\"root\" SUID=\"root\" FSUID=\"root\" EGID=\"root\" SGID=\"root\" FSGID=\"root\"",
    "node=JD-debian-12-workstation type=CWD msg=audit(1781719000.505:245392): cwd=\"/home/debian\"",
    "node=JD-debian-12-workstation type=PATH msg=audit(1781719000.505:245392): item=0 name=\"\" inode=2887116 dev=fd:01 mode=0100755 ouid=9999 ogid=9999 rdev=00:00 obj=unconfined_u:object_r:user_tmp_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0",
    "OUID=\"unknown(9999)\" OGID=\"unknown(9999)\"",
    "node=JD-debian-12-workstation type=PROCTITLE msg=audit(1781719000.505:245392): proctitle=2F7661722F746D702F647774726967676572002F7661722F746D702F647765786563"
  ],
  "record_type": "INTEGRITY_USERSPACE"
}

References #

KERNEL msgtype 2000

#
Message type
2000
Fires
Emitted by default (no audit rule required)

Description

Kernel audit status

Fields #

NameDescription
stateaudit daemon configuration resulting state
audit_enabledaudit subsystem enabled state
resresult of the audited operation(success/fail)

References #

ANOM_LOGIN_FAILURES msgtype 2100

#
Message type
2100
Fires
Emitted by default (no audit rule required)

Description

Failed login limit reached

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "acct": "catalog",
    "addr": "?",
    "auid": "4294967295",
    "exe": "/usr/bin/python3.11",
    "failures": "3",
    "hostname": "?",
    "op": "login",
    "pid": "2324",
    "res": "failed",
    "ses": "4294967295",
    "subj": "system_u:system_r:auditd_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=ANOM_LOGIN_FAILURES msg=audit(1781634271.619:539463): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_LOGIN_FAILURES op=login acct=\"catalog\" failures=3 res=failed exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "ANOM_LOGIN_FAILURES"
}

Example keys not documented in the fields table: acct, failures

ANOM_LOGIN_TIME msgtype 2101

#
Message type
2101
Fires
Emitted by default (no audit rule required)

Description

Login attempted at bad time

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "acct": "catalog",
    "addr": "?",
    "auid": "4294967295",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "op": "login",
    "pid": "2324",
    "res": "failed",
    "ses": "4294967295",
    "subj": "system_u:system_r:auditd_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=ANOM_LOGIN_TIME msg=audit(1781634271.619:539470): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_LOGIN_TIME op=login acct=\"catalog\" res=failed exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "ANOM_LOGIN_TIME"
}

Example keys not documented in the fields table: acct

ANOM_LOGIN_SESSIONS msgtype 2102

#
Message type
2102
Fires
Emitted by default (no audit rule required)

Description

Maximum concurrent sessions reached

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "acct": "catalog",
    "addr": "?",
    "auid": "4294967295",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "maxsessions": "1",
    "op": "login",
    "pid": "2324",
    "res": "failed",
    "ses": "4294967295",
    "subj": "system_u:system_r:auditd_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=ANOM_LOGIN_SESSIONS msg=audit(1781634271.619:539477): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_LOGIN_SESSIONS op=login acct=\"catalog\" maxsessions=1 res=failed exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "ANOM_LOGIN_SESSIONS"
}

Example keys not documented in the fields table: acct, maxsessions

ANOM_LOGIN_ACCT msgtype 2103

#
Message type
2103
Fires
Emitted by default (no audit rule required)

Description

Login attempted to watched account

Fields #

NameDescription
accta user's account name
daddrremote IP address
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "acct": "catalog",
    "addr": "?",
    "auid": "4294967295",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "op": "login",
    "pid": "2324",
    "res": "failed",
    "ses": "4294967295",
    "subj": "system_u:system_r:auditd_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=ANOM_LOGIN_ACCT msg=audit(1781634271.619:539484): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_LOGIN_ACCT op=login acct=\"catalog\" res=failed exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "ANOM_LOGIN_ACCT"
}

ANOM_LOGIN_LOCATION msgtype 2104

#
Message type
2104
Fires
Emitted by default (no audit rule required)

Description

Login from forbidden location

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "acct": "catalog",
    "addr": "198.51.100.9",
    "auid": "4294967295",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "op": "login",
    "pid": "2324",
    "res": "failed",
    "ses": "4294967295",
    "subj": "system_u:system_r:auditd_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=ANOM_LOGIN_LOCATION msg=audit(1781634271.619:539491): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_LOGIN_LOCATION op=login acct=\"catalog\" addr=198.51.100.9 res=failed exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "ANOM_LOGIN_LOCATION"
}

Example keys not documented in the fields table: acct

ANOM_MAX_DAC msgtype 2105

#
Message type
2105
Fires
Emitted by default (no audit rule required)

Description

Max DAC (Discretionary Access Control) failures reached

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "acct": "catalog",
    "addr": "?",
    "auid": "4294967295",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "op": "dac-check",
    "pid": "2324",
    "res": "failed",
    "ses": "4294967295",
    "subj": "system_u:system_r:auditd_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=ANOM_MAX_DAC msg=audit(1781634271.619:539498): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_MAX_DAC op=dac-check acct=\"catalog\" res=failed exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "ANOM_MAX_DAC"
}

Example keys not documented in the fields table: acct

ANOM_MAX_MAC msgtype 2106

#
Message type
2106
Fires
Emitted by default (no audit rule required)

Description

Max MAC (Mandatory Access Control) failures reached

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "acct": "catalog",
    "addr": "?",
    "auid": "4294967295",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "op": "mac-check",
    "pid": "2324",
    "res": "failed",
    "ses": "4294967295",
    "subj": "system_u:system_r:auditd_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=ANOM_MAX_MAC msg=audit(1781634271.619:539505): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_MAX_MAC op=mac-check acct=\"catalog\" res=failed exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "ANOM_MAX_MAC"
}

Example keys not documented in the fields table: acct

ANOM_AMTU_FAIL msgtype 2107

#
Message type
2107
Fires
Emitted by default (no audit rule required)

Description

AMTU (Abstract Machine Test Utility) failure

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "4294967295",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "op": "amtu",
    "pid": "2324",
    "res": "failed",
    "ses": "4294967295",
    "subj": "system_u:system_r:auditd_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=ANOM_AMTU_FAIL msg=audit(1781634271.619:539512): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_AMTU_FAIL op=amtu res=failed exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "ANOM_AMTU_FAIL"
}

ANOM_RBAC_FAIL msgtype 2108

#
Message type
2108
Fires
Emitted by default (no audit rule required)

Description

RBAC (Role-Based Access Control) self test failure

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "4294967295",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "op": "rbac-check",
    "pid": "2324",
    "res": "failed",
    "ses": "4294967295",
    "subj": "system_u:system_r:auditd_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=ANOM_RBAC_FAIL msg=audit(1781634271.619:539519): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_RBAC_FAIL op=rbac-check res=failed exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "ANOM_RBAC_FAIL"
}

ANOM_RBAC_INTEGRITY_FAIL msgtype 2109

#
Message type
2109
Fires
Emitted by default (no audit rule required)

Description

RBAC (Role-Based Access Control) file integrity test failure

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "4294967295",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "op": "rbac-integrity",
    "pid": "2324",
    "res": "failed",
    "ses": "4294967295",
    "subj": "system_u:system_r:auditd_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=ANOM_RBAC_INTEGRITY_FAIL msg=audit(1781634271.619:539526): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_RBAC_INTEGRITY_FAIL op=rbac-integrity res=failed exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "ANOM_RBAC_INTEGRITY_FAIL"
}

ANOM_CRYPTO_FAIL msgtype 2110

#
Message type
2110
Fires
Emitted by default (no audit rule required)

Description

Crypto system test failure

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "4294967295",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "op": "crypto",
    "pid": "2324",
    "res": "failed",
    "ses": "4294967295",
    "subj": "system_u:system_r:auditd_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=ANOM_CRYPTO_FAIL msg=audit(1781634271.619:539533): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_CRYPTO_FAIL op=crypto res=failed exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "ANOM_CRYPTO_FAIL"
}

ANOM_ACCESS_FS msgtype 2111

#
Message type
2111
Fires
Emitted by default (no audit rule required)

Description

Access of file or directory ended abnormally

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "4294967295",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "op": "fs-access",
    "path": "/etc/shadow",
    "pid": "2324",
    "res": "failed",
    "ses": "4294967295",
    "subj": "system_u:system_r:auditd_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=ANOM_ACCESS_FS msg=audit(1781634271.619:539540): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_ACCESS_FS op=fs-access path=\"/etc/shadow\" res=failed exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "ANOM_ACCESS_FS"
}

Example keys not documented in the fields table: path

ANOM_EXEC msgtype 2112

#
Message type
2112
Fires
Emitted by default (no audit rule required)

Description

Execution of file ended abnormally

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "4294967295",
    "cmd": "/tmp/suspicious",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "op": "exec",
    "pid": "2324",
    "res": "failed",
    "ses": "4294967295",
    "subj": "system_u:system_r:auditd_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=ANOM_EXEC msg=audit(1781634271.619:539547): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_EXEC op=exec cmd=\"/tmp/suspicious\" res=failed exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "ANOM_EXEC"
}

Example keys not documented in the fields table: cmd

ANOM_MK_EXEC msgtype 2113

#
Message type
2113
Fires
Emitted by default (no audit rule required)

Description

Make an executable

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "4294967295",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "op": "mk-exec",
    "path": "/tmp/x",
    "pid": "2324",
    "res": "failed",
    "ses": "4294967295",
    "subj": "system_u:system_r:auditd_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=ANOM_MK_EXEC msg=audit(1781634271.619:539554): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_MK_EXEC op=mk-exec path=\"/tmp/x\" res=failed exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "ANOM_MK_EXEC"
}

Example keys not documented in the fields table: path

ANOM_ADD_ACCT msgtype 2114

#
Message type
2114
Fires
Emitted by default (no audit rule required)

Description

Adding a user account ended abnormally

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "acct": "catalog",
    "addr": "?",
    "auid": "4294967295",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "op": "add-acct",
    "pid": "2324",
    "res": "success",
    "ses": "4294967295",
    "subj": "system_u:system_r:auditd_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=ANOM_ADD_ACCT msg=audit(1781634271.619:539561): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_ADD_ACCT op=add-acct acct=\"catalog\" res=success exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "ANOM_ADD_ACCT"
}

Example keys not documented in the fields table: acct

ANOM_DEL_ACCT msgtype 2115

#
Message type
2115
Fires
Emitted by default (no audit rule required)

Description

Deleting a user account ended abnormally

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "acct": "catalog",
    "addr": "?",
    "auid": "4294967295",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "op": "del-acct",
    "pid": "2324",
    "res": "success",
    "ses": "4294967295",
    "subj": "system_u:system_r:auditd_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=ANOM_DEL_ACCT msg=audit(1781634271.619:539568): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_DEL_ACCT op=del-acct acct=\"catalog\" res=success exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "ANOM_DEL_ACCT"
}

Example keys not documented in the fields table: acct

ANOM_MOD_ACCT msgtype 2116

#
Message type
2116
Fires
Emitted by default (no audit rule required)

Description

Changing an account ended abnormally

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "acct": "catalog",
    "addr": "?",
    "auid": "4294967295",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "op": "mod-acct",
    "pid": "2324",
    "res": "success",
    "ses": "4294967295",
    "subj": "system_u:system_r:auditd_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=ANOM_MOD_ACCT msg=audit(1781634271.619:539575): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_MOD_ACCT op=mod-acct acct=\"catalog\" res=success exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "ANOM_MOD_ACCT"
}

Example keys not documented in the fields table: acct

ANOM_ROOT_TRANS msgtype 2117

#
Message type
2117
Fires
Emitted by default (no audit rule required)

Description

User became root

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "acct": "catalog",
    "addr": "?",
    "auid": "4294967295",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "op": "root-trans",
    "pid": "2324",
    "res": "success",
    "ses": "4294967295",
    "subj": "system_u:system_r:auditd_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=ANOM_ROOT_TRANS msg=audit(1781634271.619:539582): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_ROOT_TRANS op=root-trans acct=\"catalog\" res=success exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "ANOM_ROOT_TRANS"
}

Example keys not documented in the fields table: acct

ANOM_LOGIN_SERVICE msgtype 2118

#
Message type
2118
Fires
Emitted by default (no audit rule required)

Description

Service acct attempted login

Fields #

NameDescription
accta user's account name
daddrremote IP address
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "4294967295",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "op": "login",
    "pid": "2324",
    "res": "failed",
    "ses": "4294967295",
    "subj": "system_u:system_r:auditd_t:s0",
    "svc": "sshd",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=ANOM_LOGIN_SERVICE msg=audit(1781634271.619:539589): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_LOGIN_SERVICE op=login svc=sshd res=failed exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "ANOM_LOGIN_SERVICE"
}

Example keys not documented in the fields table: svc

ANOM_LOGIN_ROOT msgtype 2119

#
Message type
2119
Fires
Emitted by default (no audit rule required)

Description

Root login attempted

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "acct": "root",
    "addr": "?",
    "auid": "4294967295",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "op": "login",
    "pid": "2324",
    "res": "failed",
    "ses": "4294967295",
    "subj": "system_u:system_r:auditd_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=ANOM_LOGIN_ROOT msg=audit(1781634271.619:539596): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_LOGIN_ROOT op=login acct=\"root\" res=failed exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "ANOM_LOGIN_ROOT"
}

Example keys not documented in the fields table: acct

ANOM_ORIGIN_FAILURES msgtype 2120

#
Message type
2120
Fires
Emitted by default (no audit rule required)

Description

Origin has too many failed login attempts

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "198.51.100.9",
    "auid": "4294967295",
    "exe": "/usr/bin/python3.11",
    "failures": "5",
    "hostname": "?",
    "op": "origin",
    "pid": "2324",
    "res": "failed",
    "ses": "4294967295",
    "subj": "system_u:system_r:auditd_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=ANOM_ORIGIN_FAILURES msg=audit(1781634271.619:539603): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_ORIGIN_FAILURES op=origin addr=198.51.100.9 failures=5 res=failed exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "ANOM_ORIGIN_FAILURES"
}

Example keys not documented in the fields table: failures

ANOM_SESSION msgtype 2121

#
Message type
2121
Fires
Emitted by default (no audit rule required)

Description

The user session is bad

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "acct": "catalog",
    "addr": "?",
    "auid": "4294967295",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "op": "session",
    "pid": "2324",
    "res": "failed",
    "ses": "4294967295",
    "subj": "system_u:system_r:auditd_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=ANOM_SESSION msg=audit(1781634271.619:539610): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='ANOM_SESSION op=session acct=\"catalog\" res=failed exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "ANOM_SESSION"
}

Example keys not documented in the fields table: acct

RESP_ANOMALY msgtype 2200

#
Message type
2200
Fires
Emitted by default (no audit rule required)

Description

Anomaly not reacted to

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "4294967295",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "op": "anomaly-detected",
    "pid": "2324",
    "res": "success",
    "ses": "4294967295",
    "subj": "system_u:system_r:auditd_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=RESP_ANOMALY msg=audit(1781634272.652:540389): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='RESP_ANOMALY op=anomaly-detected res=success exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "RESP_ANOMALY"
}

RESP_ALERT msgtype 2201

#
Message type
2201
Fires
Emitted by default (no audit rule required)

Description

Alert notification action (email or log): the email/log reactions are unimplemented FIXME stubs in upstream audisp-ids 3.x (reactions.c:370-372); emittable by custom plugins

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "4294967295",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "op": "alert",
    "pid": "2324",
    "res": "success",
    "ses": "4294967295",
    "subj": "system_u:system_r:auditd_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=RESP_ALERT msg=audit(1781634272.676:540608): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='RESP_ALERT op=alert res=success exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "RESP_ALERT"
}

RESP_KILL_PROC msgtype 2202

#
Message type
2202
Fires
Emitted by default (no audit rule required)

Description

Kill program

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "4294967295",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "op": "kill-process",
    "pid": "2324",
    "res": "success",
    "ses": "4294967295",
    "subj": "system_u:system_r:auditd_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=RESP_KILL_PROC msg=audit(1781634272.652:540397): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='RESP_KILL_PROC op=kill-process pid=12345 res=success exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "RESP_KILL_PROC"
}

RESP_TERM_ACCESS msgtype 2203

#
Message type
2203
Fires
Emitted by default (no audit rule required)

Description

Terminate session

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "4294967295",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "op": "terminate-session",
    "pid": "2324",
    "res": "success",
    "ses": "4294967295",
    "subj": "system_u:system_r:auditd_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=RESP_TERM_ACCESS msg=audit(1781634272.716:540658): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='RESP_TERM_ACCESS op=terminate-session res=success exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "RESP_TERM_ACCESS"
}

RESP_ACCT_REMOTE msgtype 2204

#
Message type
2204
Fires
Emitted by default (no audit rule required)

Description

User account locked from remote access

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "acct": "catalog",
    "addr": "?",
    "auid": "4294967295",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "op": "lock-acct-remote",
    "pid": "2324",
    "res": "success",
    "ses": "4294967295",
    "subj": "system_u:system_r:auditd_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=RESP_ACCT_REMOTE msg=audit(1781634271.623:539645): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='RESP_ACCT_REMOTE op=lock-acct-remote acct=\"catalog\" res=success exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "RESP_ACCT_REMOTE"
}

Example keys not documented in the fields table: acct

RESP_ACCT_LOCK_TIMED msgtype 2205

#
Message type
2205
Fires
Emitted by default (no audit rule required)

Description

User account locked for time

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "acct": "catalog",
    "addr": "?",
    "auid": "4294967295",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "op": "lock-acct-timed",
    "pid": "2324",
    "res": "success",
    "ses": "4294967295",
    "subj": "system_u:system_r:auditd_t:s0",
    "terminal": "?",
    "timeout": "600",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=RESP_ACCT_LOCK_TIMED msg=audit(1781634271.623:539652): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='RESP_ACCT_LOCK_TIMED op=lock-acct-timed acct=\"catalog\" timeout=600 res=success exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "RESP_ACCT_LOCK_TIMED"
}

Example keys not documented in the fields table: acct, timeout

RESP_ACCT_UNLOCK_TIMED msgtype 2206

#
Message type
2206
Fires
Emitted by default (no audit rule required)

Description

User account unlocked from time

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "acct": "catalog",
    "addr": "?",
    "auid": "4294967295",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "op": "unlock-acct-timed",
    "pid": "2324",
    "res": "success",
    "ses": "4294967295",
    "subj": "system_u:system_r:auditd_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=RESP_ACCT_UNLOCK_TIMED msg=audit(1781634271.623:539659): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='RESP_ACCT_UNLOCK_TIMED op=unlock-acct-timed acct=\"catalog\" res=success exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "RESP_ACCT_UNLOCK_TIMED"
}

Example keys not documented in the fields table: acct

RESP_ACCT_LOCK msgtype 2207

#
Message type
2207
Fires
Emitted by default (no audit rule required)

Description

User account was locked

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "acct": "catalog",
    "addr": "?",
    "auid": "4294967295",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "op": "lock-acct",
    "pid": "2324",
    "res": "success",
    "ses": "4294967295",
    "subj": "system_u:system_r:auditd_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=RESP_ACCT_LOCK msg=audit(1781634271.623:539667): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='RESP_ACCT_LOCK op=lock-acct acct=\"catalog\" res=success exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "RESP_ACCT_LOCK"
}

Example keys not documented in the fields table: acct

RESP_TERM_LOCK msgtype 2208

#
Message type
2208
Fires
Emitted by default (no audit rule required)

Description

Terminal was locked

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "4294967295",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "op": "lock-session",
    "pid": "2324",
    "res": "success",
    "ses": "4294967295",
    "subj": "system_u:system_r:auditd_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=RESP_TERM_LOCK msg=audit(1781634271.623:539674): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='RESP_TERM_LOCK op=lock-session res=success exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "RESP_TERM_LOCK"
}

RESP_SEBOOL msgtype 2209

#
Message type
2209
Fires
Emitted by default (no audit rule required)

Description

Set an SELinux boolean

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "4294967295",
    "bool": "httpd_enable_homedirs",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "op": "set-sebool",
    "pid": "2324",
    "res": "success",
    "ses": "4294967295",
    "subj": "system_u:system_r:auditd_t:s0",
    "terminal": "?",
    "uid": "0",
    "val": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=RESP_SEBOOL msg=audit(1781634271.623:539681): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='RESP_SEBOOL op=set-sebool bool=httpd_enable_homedirs val=0 res=success exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "RESP_SEBOOL"
}

Example keys not documented in the fields table: bool, val

RESP_EXEC msgtype 2210

#
Message type
2210
Fires
Emitted by default (no audit rule required)

Description

Execute a script

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "4294967295",
    "cmd": "/usr/local/sbin/respond",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "op": "exec-response",
    "pid": "2324",
    "res": "success",
    "ses": "4294967295",
    "subj": "system_u:system_r:auditd_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=RESP_EXEC msg=audit(1781634271.623:539688): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='RESP_EXEC op=exec-response cmd=\"/usr/local/sbin/respond\" res=success exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "RESP_EXEC"
}

Example keys not documented in the fields table: cmd

RESP_SINGLE msgtype 2211

#
Message type
2211
Fires
Emitted by default (no audit rule required)

Description

Go to single user mode

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "4294967295",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "op": "single-user-mode",
    "pid": "2324",
    "res": "success",
    "ses": "4294967295",
    "subj": "system_u:system_r:auditd_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=RESP_SINGLE msg=audit(1781634271.623:539695): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='RESP_SINGLE op=single-user-mode res=success exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "RESP_SINGLE"
}

RESP_HALT msgtype 2212

#
Message type
2212
Fires
Emitted by default (no audit rule required)

Description

Take the system down

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "4294967295",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "op": "halt",
    "pid": "2324",
    "res": "success",
    "ses": "4294967295",
    "subj": "system_u:system_r:auditd_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=RESP_HALT msg=audit(1781634271.623:539702): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='RESP_HALT op=halt res=success exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "RESP_HALT"
}

RESP_ORIGIN_BLOCK msgtype 2213

#
Message type
2213
Fires
Emitted by default (no audit rule required)

Description

Remote address blocked by firewall rule (iptables or nftables depending on system configuration)

Fields #

NameDescription
daddrremote IP address
reasonreason for the operation
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited

Example Audit Record #

{
  "fields": {
    "addr": "198.51.100.9",
    "auid": "4294967295",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "op": "block-origin",
    "pid": "2324",
    "res": "success",
    "ses": "4294967295",
    "subj": "system_u:system_r:auditd_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=RESP_ORIGIN_BLOCK msg=audit(1781634272.676:540615): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='RESP_ORIGIN_BLOCK op=block-origin addr=198.51.100.9 res=success exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "RESP_ORIGIN_BLOCK"
}

RESP_ORIGIN_BLOCK_TIMED msgtype 2214

#
Message type
2214
Fires
Emitted by default (no audit rule required)

Description

Address blocked for time

Fields #

NameDescription
daddrremote IP address
reasonreason for the operation
time_outblock timeout in minutes for the timed response
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited

Example Audit Record #

{
  "fields": {
    "addr": "198.51.100.9",
    "auid": "4294967295",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "op": "block-origin-timed",
    "pid": "2324",
    "res": "success",
    "ses": "4294967295",
    "subj": "system_u:system_r:auditd_t:s0",
    "terminal": "?",
    "timeout": "600",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=RESP_ORIGIN_BLOCK_TIMED msg=audit(1781634271.627:539743): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='RESP_ORIGIN_BLOCK_TIMED op=block-origin-timed addr=198.51.100.9 timeout=600 res=success exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "RESP_ORIGIN_BLOCK_TIMED"
}

Example keys not documented in the fields table: timeout

RESP_ORIGIN_UNBLOCK_TIMED msgtype 2215

#
Message type
2215
Fires
Emitted by default (no audit rule required)

Description

Address unblocked from timed

Fields #

NameDescription
daddrremote IP address
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited

Example Audit Record #

{
  "fields": {
    "addr": "198.51.100.9",
    "auid": "4294967295",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "op": "unblock-origin-timed",
    "pid": "2324",
    "res": "success",
    "ses": "4294967295",
    "subj": "system_u:system_r:auditd_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=RESP_ORIGIN_UNBLOCK_TIMED msg=audit(1781634271.627:539750): pid=2324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditd_t:s0 msg='RESP_ORIGIN_UNBLOCK_TIMED op=unblock-origin-timed addr=198.51.100.9 res=success exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "RESP_ORIGIN_UNBLOCK_TIMED"
}

USER_ROLE_CHANGE msgtype 2300

#
Message type
2300
Fires
Emitted by default (no audit rule required)

Description

User changed to a new SELinux role

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
default-contextSELinux context offered as the default at login
selected-contextSELinux context the user selected at login
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "10.2.20.61",
    "auid": "1000",
    "default-context": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
    "exe": "/usr/sbin/sshd",
    "hostname": "10.2.20.61",
    "pid": "996",
    "res": "success",
    "selected-context": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
    "ses": "1",
    "subj": "system_u:system_r:sshd_t:s0",
    "terminal": "ssh",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=USER_ROLE_CHANGE msg=audit(1781634177.960:186480): pid=996 uid=0 auid=1000 ses=1 subj=system_u:system_r:sshd_t:s0 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe=\"/usr/sbin/sshd\" hostname=10.2.20.61 addr=10.2.20.61 terminal=ssh res=success'",
    "UID=\"root\" AUID=\"debian\""
  ],
  "record_type": "USER_ROLE_CHANGE"
}

ROLE_ASSIGN msgtype 2301

#
Message type
2301
Fires
Emitted by default (no audit rule required)

Description

Administrator assigned user to SELinux role

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
accta user's account name
old-seuserSELinux user before the role change
old-roleSELinux role before the role change
old-rangeSELinux MLS range before the role change
new-seuserSELinux user after the role change
new-roleSELinux role after the role change
new-rangeSELinux MLS range after the role change
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "acct": "r3usr",
    "addr": "?",
    "auid": "1000",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "new-range": "s0",
    "new-role": "user_r",
    "new-seuser": "user_u",
    "old-range": "?",
    "old-role": "?",
    "old-seuser": "?",
    "op": "login-sename,role,range",
    "pid": "2819",
    "res": "success",
    "ses": "1",
    "subj": "unconfined_u:unconfined_r:semanage_t:s0-s0:c0.c1023",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=ROLE_ASSIGN msg=audit(1781634269.359:532608): pid=2819 uid=0 auid=1000 ses=1 subj=unconfined_u:unconfined_r:semanage_t:s0-s0:c0.c1023 msg='op=login-sename,role,range acct=\"r3usr\" old-seuser=? old-role=? old-range=? new-seuser=user_u new-role=user_r new-range=s0 exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"debian\""
  ],
  "record_type": "ROLE_ASSIGN"
}

ROLE_REMOVE msgtype 2302

#
Message type
2302
Fires
Emitted by default (no audit rule required)

Description

Administrator removed user from SELinux role

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
accta user's account name
old-seuserSELinux user before the role change
old-roleSELinux role before the role change
old-rangeSELinux MLS range before the role change
new-seuserSELinux user after the role change
new-roleSELinux role after the role change
new-rangeSELinux MLS range after the role change
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "acct": "r3usr",
    "addr": "?",
    "auid": "1000",
    "exe": "/usr/bin/python3.11",
    "hostname": "?",
    "new-range": "?",
    "new-role": "?",
    "new-seuser": "?",
    "old-range": "s0",
    "old-role": "user_r",
    "old-seuser": "user_u",
    "op": "login",
    "pid": "2884",
    "res": "success",
    "ses": "1",
    "subj": "unconfined_u:unconfined_r:semanage_t:s0-s0:c0.c1023",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=ROLE_REMOVE msg=audit(1781634270.619:537790): pid=2884 uid=0 auid=1000 ses=1 subj=unconfined_u:unconfined_r:semanage_t:s0-s0:c0.c1023 msg='op=login acct=\"r3usr\" old-seuser=user_u old-role=user_r old-range=s0 new-seuser=? new-role=? new-range=? exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"debian\""
  ],
  "record_type": "ROLE_REMOVE"
}

LABEL_OVERRIDE msgtype 2303

#
Message type
2303
Fires
Emitted by default (no audit rule required)

Description

Administrator is overriding a SELinux label

Fields #

NameDescription
pidprocess ID (cupsd)
uiduser ID
auidlogin user ID
seslogin session ID
subjthe subject's context string (the cupsd domain)
jobthe print job ID
job-sheetsthe banner (job-sheets) the user supplied (start,end)
bannersthe banner pages cupsd applied to the job (start,end)
exeexecutable name (cupsd)
hostnamethe hostname the request came from
addrthe remote address the request came from
terminalterminal name
resresult of the audited operation (success/failed)

Example Audit Record #

{
  "fields": {
    "addr": "::1",
    "auid": "4294967295",
    "banners": "unclassified,unclassified",
    "exe": "/usr/sbin/cupsd",
    "hostname": "localhost.localdomain",
    "job": "18",
    "job-sheets": "unclassified,unclassified",
    "pid": "5469",
    "res": "failed",
    "ses": "4294967295",
    "subj": "system_u:system_r:cupsd_t:s15:c0.c1023",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=localhost type=LABEL_OVERRIDE msg=audit(1782745213.098:2375): pid=5469 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:cupsd_t:s15:c0.c1023 msg='job=18 user supplied job-sheets=unclassified,unclassified ignored banners=unclassified,unclassified exe=\"/usr/sbin/cupsd\" hostname=localhost.localdomain addr=::1 terminal=? res=failed'"
  ],
  "record_type": "LABEL_OVERRIDE"
}

LABEL_LEVEL_CHANGE msgtype 2304

#
Message type
2304
Fires
Emitted by default (no audit rule required)

Description

Object level SELinux label modified

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjthe subject's context string (the cupsd domain)
printerthe destination print queue
urithe device URI the queue prints to
bannersthe banner pages attached to the job (start,end)
rangethe MLS sensitivity range applied to the job
exeexecutable name (cupsd)
hostnamethe hostname the request came from
addrthe remote address the request came from
terminalterminal name
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "::1",
    "auid": "4294967295",
    "banners": "none,none",
    "exe": "/usr/sbin/cupsd",
    "hostname": "localhost.localdomain",
    "pid": "5124",
    "printer": "dwfile",
    "range": "unknown",
    "res": "success",
    "ses": "4294967295",
    "subj": "system_u:system_r:cupsd_t:s15:c0.c1023",
    "terminal": "?",
    "uid": "0",
    "uri": "file:/tmp/dwprint.out"
  },
  "raw": [
    "node=localhost type=LABEL_LEVEL_CHANGE msg=audit(1782740116.657:1729): pid=5124 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:cupsd_t:s15:c0.c1023 msg='printer=dwfile uri=file:/tmp/dwprint.out banners=none,none range=unknown exe=\"/usr/sbin/cupsd\" hostname=localhost.localdomain addr=::1 terminal=? res=success'"
  ],
  "record_type": "LABEL_LEVEL_CHANGE"
}

USER_LABELED_EXPORT msgtype 2305

#
Message type
2305
Fires
Emitted by default (no audit rule required)

Description

Object exported with SELinux label

Fields #

NameDescription
pidprocess ID (cupsd)
uiduser ID
auidlogin user ID
seslogin session ID
subjthe subject's context string (the cupsd domain)
jobthe print job ID
acctthe account that owns the job
printerthe destination print queue
titlethe job title (source document name)
objthe SELinux context of the exported job
labelthe resolved classification label applied to the export
exeexecutable name (cupsd)
hostnamethe hostname the request came from
addrthe remote address the request came from
terminalterminal name
resresult of the audited operation (success/failed)

Example Audit Record #

{
  "fields": {
    "acct": "root",
    "addr": "::1",
    "auid": "4294967295",
    "exe": "/usr/sbin/cupsd",
    "hostname": "localhost.localdomain",
    "job": "18",
    "label": "unclassified",
    "obj": "sysadm_u:sysadm_r:lpr_t:s0-s15:c0.c1023",
    "pid": "5469",
    "printer": "dwk",
    "res": "success",
    "ses": "4294967295",
    "subj": "system_u:system_r:cupsd_t:s15:c0.c1023",
    "terminal": "?",
    "title": "j.txt",
    "uid": "0"
  },
  "raw": [
    "node=localhost type=USER_LABELED_EXPORT msg=audit(1782745213.114:2377): pid=5469 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:cupsd_t:s15:c0.c1023 msg='job=18 auid=0 acct=root printer=dwk title=j.txt obj=sysadm_u:sysadm_r:lpr_t:s0-s15:c0.c1023 label=unclassified exe=\"/usr/sbin/cupsd\" hostname=localhost.localdomain addr=::1 terminal=? res=success'"
  ],
  "record_type": "USER_LABELED_EXPORT"
}

USER_UNLABELED_EXPORT msgtype 2306

#
Message type
2306
Fires
Emitted by default (no audit rule required)

Description

Object exported without SELinux label

DEV_ALLOC msgtype 2307

#
Message type
2307
Fires
Emitted by default (no audit rule required)

Description

Device was allocated

DEV_DEALLOC msgtype 2308

#
Message type
2308
Fires
Emitted by default (no audit rule required)

Description

Device was deallocated

FS_RELABEL msgtype 2309

#
Message type
2309
Fires
Emitted by default (no audit rule required)

Description

Filesystem relabeled

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "1000",
    "exe": "/usr/sbin/setfiles",
    "hostname": "?",
    "op": "mass relabel",
    "pid": "54891",
    "res": "success",
    "ses": "4",
    "subj": "unconfined_u:unconfined_r:setfiles_t:s0-s0:c0.c1023",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=FS_RELABEL msg=audit(1781641141.755:2056951): pid=54891 uid=0 auid=1000 ses=4 subj=unconfined_u:unconfined_r:setfiles_t:s0-s0:c0.c1023 msg='op=mass relabel exe=\"/usr/sbin/setfiles\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"debian\""
  ],
  "record_type": "FS_RELABEL"
}

USER_MAC_POLICY_LOAD msgtype 2310

#
Message type
2310
Fires
Emitted by default (no audit rule required)

Description

Userspace daemon loaded SELinux policy

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
lsmsecurity module that produced the record (selinux, apparmor, ...)
seqnosequence number
resresult of the audited operation(success/fail)
exeexecutable name
sauidsent login user ID
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "4294967295",
    "exe": "/usr/bin/dbus-daemon",
    "hostname": "?",
    "lsm": "selinux",
    "op": "load_policy",
    "pid": "504",
    "res": "1",
    "sauid": "100",
    "seqno": "6",
    "ses": "4294967295",
    "subj": "system_u:system_r:system_dbusd_t:s0",
    "terminal": "?",
    "uid": "100"
  },
  "raw": [
    "node=JD-debian-12-workstation type=USER_MAC_POLICY_LOAD msg=audit(1781634271.163:538052): pid=504 uid=100 auid=4294967295 ses=4294967295 subj=system_u:system_r:system_dbusd_t:s0 msg='avc:  op=load_policy lsm=selinux seqno=6 res=1 exe=\"/usr/bin/dbus-daemon\" sauid=100 hostname=? addr=? terminal=?'",
    "UID=\"messagebus\" AUID=\"unset\" SAUID=\"messagebus\""
  ],
  "record_type": "USER_MAC_POLICY_LOAD"
}

ROLE_MODIFY msgtype 2311

#
Message type
2311
Fires
Emitted by default (no audit rule required)

Description

Administrator modified an SELinux role

USER_MAC_CONFIG_CHANGE msgtype 2312

#
Message type
2312
Fires
Emitted by default (no audit rule required)

Description

Change made to MAC (Mandatory Access Control) policy

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
resrcresource the record applies to (disk, mem, net for VIRT; object type for MAC config changes)
opthe operation being performed that is audited
tglobfile-context glob pattern
ftypefile type the context rule applies to
tcontextthe target's or object's context string
commcommand line program name
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "1000",
    "comm": "semanage",
    "exe": "/usr/bin/python3.11",
    "ftype": "any",
    "hostname": "?",
    "op": "delete",
    "pid": "57695",
    "res": "success",
    "resrc": "fcontext",
    "ses": "4",
    "subj": "unconfined_u:unconfined_r:semanage_t:s0-s0:c0.c1023",
    "terminal": "?",
    "tglob": "/catalogtest(/.*)?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=USER_MAC_CONFIG_CHANGE msg=audit(1781641148.319:2066513): pid=57695 uid=0 auid=1000 ses=4 subj=unconfined_u:unconfined_r:semanage_t:s0-s0:c0.c1023 msg='resrc=fcontext op=delete tglob=\"/catalogtest(/.*)?\" ftype=any comm=\"semanage\" exe=\"/usr/bin/python3.11\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"debian\""
  ],
  "record_type": "USER_MAC_CONFIG_CHANGE"
}

USER_MAC_STATUS msgtype 2313

#
Message type
2313
Fires
Emitted by default (no audit rule required)

Description

Userspace daemon enforcing change

Fields #

NameDescription
pidprocess ID (dbus-broker)
uiduser ID (the message bus user, typically dbus/81)
auidlogin user ID (unset for the bus daemon)
seslogin session ID
subjthe subject's context string (the dbus-broker domain)
opthe operation that changed MAC status (setenforce)
lsmthe Linux Security Module reporting the change (selinux)
enforcingthe new enforcing state (1 enforcing, 0 permissive)
resresult of the audited operation (1 success)
exeexecutable name (dbus-broker)
sauidthe sender audit user ID
hostnamethe hostname the request came from
addrthe remote address the request came from
terminalterminal name

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "4294967295",
    "enforcing": "0",
    "exe": "/usr/bin/dbus-broker",
    "hostname": "?",
    "lsm": "selinux",
    "op": "setenforce",
    "pid": "769",
    "res": "1",
    "sauid": "81",
    "ses": "4294967295",
    "subj": "system_u:system_r:system_dbusd_t:s0-s0:c0.c1023",
    "terminal": "?",
    "uid": "81"
  },
  "raw": [
    "type=USER_MAC_STATUS msg=audit(1782743524.377:437): pid=769 uid=81 auid=4294967295 ses=4294967295 subj=system_u:system_r:system_dbusd_t:s0-s0:c0.c1023 msg='avc:  op=setenforce lsm=selinux enforcing=0 res=1 exe=\"/usr/bin/dbus-broker\" sauid=81 hostname=? addr=? terminal=?'"
  ],
  "record_type": "USER_MAC_STATUS"
}

CRYPTO_TEST_USER msgtype 2400

#
Message type
2400
Fires
Emitted by default (no audit rule required)

Description

Cryptographic test results

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "1000",
    "exe": "/usr/bin/certutil",
    "hostname": "?",
    "pid": "147033",
    "res": "failed",
    "ses": "156",
    "subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=CRYPTO_TEST_USER msg=audit(1781742805.668:3014500): pid=147033 uid=0 auid=1000 ses=156 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='NSS libsoftokn3.so: C_Initialize()=0x00000030 power-up self-tests failed exe=\"/usr/bin/certutil\" hostname=? addr=? terminal=? res=failed'",
    "UID=\"root\" AUID=\"debian\""
  ],
  "record_type": "CRYPTO_TEST_USER"
}

CRYPTO_PARAM_CHANGE_USER msgtype 2401

#
Message type
2401
Fires
Emitted by default (no audit rule required)

Description

Cryptographic attribute change

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "1000",
    "exe": "/tmp/nss_fail",
    "hostname": "?",
    "pid": "146120",
    "res": "success",
    "ses": "150",
    "subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=CRYPTO_PARAM_CHANGE_USER msg=audit(1781742719.774:2986384): pid=146120 uid=0 auid=1000 ses=150 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='NSS libsoftokn3.so: C_SetPIN(hSession=0x80000004)=0x00000000 exe=\"/tmp/nss_fail\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"debian\""
  ],
  "record_type": "CRYPTO_PARAM_CHANGE_USER"
}

CRYPTO_LOGIN msgtype 2402

#
Message type
2402
Fires
Emitted by default (no audit rule required)

Description

Cryptographic officer login

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "1000",
    "exe": "/tmp/nss_fips",
    "hostname": "?",
    "pid": "143186",
    "res": "success",
    "ses": "141",
    "subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=CRYPTO_LOGIN msg=audit(1781742444.164:2919469): pid=143186 uid=0 auid=1000 ses=141 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='NSS libsoftokn3.so: C_Login(hSession=0x80000004, userType=0)=0x00000000 exe=\"/tmp/nss_fips\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"debian\""
  ],
  "record_type": "CRYPTO_LOGIN"
}

CRYPTO_LOGOUT msgtype 2403

#
Message type
2403
Fires
Emitted by default (no audit rule required)

Description

Cryptographic officer logout

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "1000",
    "exe": "/tmp/nss_fail",
    "hostname": "?",
    "pid": "146120",
    "res": "failed",
    "ses": "150",
    "subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=CRYPTO_LOGOUT msg=audit(1781742719.774:2986394): pid=146120 uid=0 auid=1000 ses=150 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='NSS libsoftokn3.so: C_Logout(hSession=0x80000001)=0x00000101 exe=\"/tmp/nss_fail\" hostname=? addr=? terminal=? res=failed'",
    "UID=\"root\" AUID=\"debian\""
  ],
  "record_type": "CRYPTO_LOGOUT"
}

CRYPTO_KEY_USER msgtype 2404

#
Message type
2404
Fires
Emitted by default (no audit rule required)

Description

Create, delete, negotiate cryptographic key identifier

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
kindserver or client in crypto operation
fpcrypto key fingerprint
directionIPsec SA direction
spidsent process ID
suiduser ID that initiated the crypto operation
rportremote port number
laddrlocal network address
lportlocal network port
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "127.0.0.1",
    "auid": "1000",
    "direction": "both",
    "exe": "/usr/local/libexec/sshd-session",
    "fp": "?",
    "hostname": "?",
    "kind": "session",
    "laddr": "127.0.0.1",
    "lport": "2222",
    "op": "destroy",
    "pid": "138898",
    "res": "success",
    "rport": "58318",
    "ses": "120",
    "spid": "138899",
    "subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
    "suid": "101",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=CRYPTO_KEY_USER msg=audit(1781721196.292:246634): pid=138898 uid=0 auid=1000 ses=120 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=138899 suid=101 rport=58318 laddr=127.0.0.1 lport=2222  exe=\"/usr/local/libexec/sshd-session\" hostname=? addr=127.0.0.1 terminal=? res=success'",
    "UID=\"root\" AUID=\"debian\" SUID=\"sshd\""
  ],
  "record_type": "CRYPTO_KEY_USER"
}

CRYPTO_FAILURE_USER msgtype 2405

#
Message type
2405
Fires
Emitted by default (no audit rule required)

Description

Fail decrypt, encrypt or randomize operation

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "1000",
    "exe": "/tmp/nss_fail2",
    "hostname": "?",
    "pid": "146639",
    "res": "failed",
    "ses": "153",
    "subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=CRYPTO_FAILURE_USER msg=audit(1781742765.075:3001374): pid=146639 uid=0 auid=1000 ses=153 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='NSS libsoftokn3.so: C_EncryptInit(hSession=0x80000005, pMechanism=7ffcd29cca50 {mechanism=0x00000111, ...}, hKey=0x00000002)=0x00000063 exe=\"/tmp/nss_fail2\" hostname=? addr=? terminal=? res=failed'",
    "UID=\"root\" AUID=\"debian\""
  ],
  "record_type": "CRYPTO_FAILURE_USER"
}

CRYPTO_REPLAY_USER msgtype 2406

#
Message type
2406
Fires
Emitted by default (no audit rule required)

Description

Cryptographic replay attack detected

CRYPTO_SESSION msgtype 2407

#
Message type
2407
Fires
Emitted by default (no audit rule required)

Description

Parameters set during TLS session establishment

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
directionIPsec SA direction
ciphername of crypto cipher selected
ksizekey size for crypto operation
maccrypto MAC algorithm selected
pfskey-exchange group negotiated for perfect forward secrecy
spidsent process ID
suiduser ID that initiated the crypto operation
rportremote port number
laddrlocal network address
lportlocal network port
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "127.0.0.1",
    "auid": "1000",
    "cipher": "chacha20-poly1305@openssh.com",
    "direction": "from-server",
    "exe": "/usr/local/libexec/sshd-session",
    "hostname": "?",
    "ksize": "512",
    "laddr": "127.0.0.1",
    "lport": "2222",
    "mac": "<implicit>",
    "op": "start",
    "pfs": "sntrup761x25519-sha512",
    "pid": "138898",
    "res": "success",
    "rport": "58318",
    "ses": "120",
    "spid": "138899",
    "subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
    "suid": "101",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=CRYPTO_SESSION msg=audit(1781721196.086:246626): pid=138898 uid=0 auid=1000 ses=120 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=chacha20-poly1305@openssh.com ksize=512 mac=<implicit> pfs=sntrup761x25519-sha512 spid=138899 suid=101 rport=58318 laddr=127.0.0.1 lport=2222  exe=\"/usr/local/libexec/sshd-session\" hostname=? addr=127.0.0.1 terminal=? res=success'",
    "UID=\"root\" AUID=\"debian\" SUID=\"sshd\""
  ],
  "record_type": "CRYPTO_SESSION"
}

CRYPTO_IKE_SA msgtype 2408

#
Message type
2408
Fires
Emitted by default (no audit rule required)

Description

Parameters related to IKE SA

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
directionIPsec SA direction
conn-nameIPsec connection name
connstatepluto's internal state-object serial number for this negotiation (increments per state; not an enumerated connection status)
ike-versionIKE protocol version
authauthentication method negotiated for the IKE SA
ciphername of crypto cipher selected
ksizekey size for crypto operation
integintegrity algorithm negotiated for the IKE SA
prfpseudo-random function negotiated for the IKE SA
pfskey-exchange group negotiated for perfect forward secrecy
raddrremote address of the connection
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "192.0.2.1",
    "auid": "4294967295",
    "auth": "PRESHARED_KEY",
    "cipher": "none",
    "conn-name": "r5",
    "connstate": "1",
    "direction": "initiator",
    "exe": "/usr/libexec/ipsec/pluto",
    "hostname": "?",
    "ike-version": "2.0",
    "integ": "none",
    "ksize": "0",
    "op": "start",
    "pfs": "MODP2048",
    "pid": "61499",
    "prf": "none",
    "raddr": "192.0.2.250",
    "res": "failed",
    "ses": "4294967295",
    "subj": "system_u:system_r:ipsec_t:s0",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=CRYPTO_IKE_SA msg=audit(1781641429.666:2206992): pid=61499 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:ipsec_t:s0 msg='op=start direction=initiator conn-name=\"r5\" connstate=1 ike-version=2.0 auth=PRESHARED_KEY cipher=none ksize=0 integ=none prf=none pfs=MODP2048  raddr=192.0.2.250 exe=\"/usr/libexec/ipsec/pluto\" hostname=? addr=192.0.2.1 terminal=? res=failed'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "CRYPTO_IKE_SA"
}

CRYPTO_IPSEC_SA msgtype 2409

#
Message type
2409
Fires
Emitted by default (no audit rule required)

Description

Parameters related to IPSEC SA

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
opthe operation being performed that is audited
conn-nameIPsec connection name
connstatepluto's internal state-object serial number for this negotiation (increments per state; not an enumerated connection status)
satypeIPsec SA type (ipsec-esp, ipsec-ah, or ipsec-policy)
samodeIPsec SA mode (transport or tunnel)
ciphername of crypto cipher selected
ksizekey size for crypto operation
integintegrity algorithm negotiated for the IPsec SA
in-spiinbound IPsec Security Parameter Index
out-spioutbound IPsec Security Parameter Index
in-ipcompinbound IP compression CPI
out-ipcompoutbound IP compression CPI
raddrremote address of the connection
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "192.0.2.1",
    "auid": "1000",
    "cipher": "AES_GCM_C",
    "conn-name": "r5",
    "connstate": "2,",
    "exe": "/usr/libexec/ipsec/pluto",
    "hostname": "?",
    "in-ipcomp": "0(0x00000000)",
    "in-spi": "2296459588(0x2296459588)",
    "integ": "NONE",
    "ksize": "256",
    "op": "start",
    "out-ipcomp": "0(0x00000000)",
    "out-spi": "2215416355(0x2215416355)",
    "pid": "88553",
    "raddr": "192.0.2.2",
    "res": "success",
    "samode": "tunnel",
    "satype": "ipsec-esp",
    "ses": "7",
    "subj": "unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023",
    "terminal": "?",
    "uid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=CRYPTO_IPSEC_SA msg=audit(1781643889.065:2839748): pid=88553 uid=0 auid=1000 ses=7 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=start conn-name=\"r5\" connstate=2, satype=ipsec-esp samode=tunnel cipher=AES_GCM_C ksize=256 integ=NONE in-spi=2296459588(0x2296459588) out-spi=2215416355(0x2215416355) in-ipcomp=0(0x00000000) out-ipcomp=0(0x00000000) raddr=192.0.2.2 exe=\"/usr/libexec/ipsec/pluto\" hostname=? addr=192.0.2.1 terminal=? res=success'",
    "UID=\"root\" AUID=\"debian\""
  ],
  "record_type": "CRYPTO_IPSEC_SA"
}

VIRT_CONTROL msgtype 2500

#
Message type
2500
Fires
Emitted by default (no audit rule required)

Description

Start, Pause, Stop VM

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
virtvirtualization driver (qemu, lxc, ...)
opthe operation being performed that is audited
reasonreason for the operation
vmname of the virtual machine
uuidUUID of the virtual machine
vm-pidprocess ID of the virtual machine (0 if not yet started)
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "4294967295",
    "exe": "/usr/sbin/libvirtd",
    "hostname": "?",
    "op": "start",
    "pid": "58538",
    "reason": "booted",
    "res": "failed",
    "ses": "4294967295",
    "subj": "system_u:system_r:virtd_t:s0",
    "terminal": "?",
    "uid": "0",
    "uuid": "fb5e54c6-0345-4b27-b694-688d88eb48d0",
    "virt": "qemu",
    "vm": "r5vm",
    "vm-pid": "0"
  },
  "raw": [
    "node=JD-debian-12-workstation type=VIRT_CONTROL msg=audit(1781641224.555:2099420): pid=58538 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:virtd_t:s0 msg='virt=qemu op=start reason=booted vm=\"r5vm\" uuid=fb5e54c6-0345-4b27-b694-688d88eb48d0 vm-pid=0 exe=\"/usr/sbin/libvirtd\" hostname=? addr=? terminal=? res=failed'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "VIRT_CONTROL"
}

VIRT_RESOURCE msgtype 2501

#
Message type
2501
Fires
Emitted by default (no audit rule required)

Description

Resource assignment

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
virtvirtualization driver (qemu, lxc, ...)
resrcresource the record applies to (disk, mem, net for VIRT; object type for MAC config changes)
reasonreason for the operation
vmname of the virtual machine
uuidUUID of the virtual machine
old-diskprevious resource value; the field is named old-<resrc> (old-disk, old-mem, ...)
new-disknew resource value; the field is named new-<resrc> (new-disk, new-mem, ...)
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "4294967295",
    "exe": "/usr/sbin/libvirtd",
    "hostname": "?",
    "new-disk": "/tmp/r5disk.qcow2",
    "old-disk": "?",
    "pid": "58538",
    "reason": "start",
    "res": "success",
    "resrc": "disk",
    "ses": "4294967295",
    "subj": "system_u:system_r:virtd_t:s0",
    "terminal": "?",
    "uid": "0",
    "uuid": "fb5e54c6-0345-4b27-b694-688d88eb48d0",
    "virt": "qemu",
    "vm": "r5vm"
  },
  "raw": [
    "node=JD-debian-12-workstation type=VIRT_RESOURCE msg=audit(1781641224.551:2099397): pid=58538 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:virtd_t:s0 msg='virt=qemu resrc=disk reason=start vm=\"r5vm\" uuid=fb5e54c6-0345-4b27-b694-688d88eb48d0 old-disk=\"?\" new-disk=\"/tmp/r5disk.qcow2\" exe=\"/usr/sbin/libvirtd\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "VIRT_RESOURCE"
}

VIRT_MACHINE_ID msgtype 2502

#
Message type
2502
Fires
Emitted by default (no audit rule required)

Description

Binding of label to VM

Fields #

NameDescription
pidprocess ID
uiduser ID
auidlogin user ID
seslogin session ID
subjlspp subject's context string
virtvirtualization driver (qemu, lxc, ...)
vmname of the virtual machine
uuidUUID of the virtual machine
vm-ctxSELinux process context assigned to the VM
img-ctxSELinux file context assigned to the VM image
modelsecurity model used for VM labeling (selinux, apparmor, dac)
exeexecutable name
hostnamethe hostname that the user is connecting from
addrthe remote address that the user is connecting from
terminalterminal name the user is running programs on
resresult of the audited operation(success/fail)

Example Audit Record #

{
  "fields": {
    "addr": "?",
    "auid": "4294967295",
    "exe": "/usr/sbin/libvirtd",
    "hostname": "?",
    "img-ctx": "system_u:object_r:svirt_image_t:s0:c62,c990",
    "model": "selinux",
    "pid": "58538",
    "res": "success",
    "ses": "4294967295",
    "subj": "system_u:system_r:virtd_t:s0",
    "terminal": "?",
    "uid": "0",
    "uuid": "fb5e54c6-0345-4b27-b694-688d88eb48d0",
    "virt": "qemu",
    "vm": "r5vm",
    "vm-ctx": "system_u:system_r:svirt_t:s0:c62,c990"
  },
  "raw": [
    "node=JD-debian-12-workstation type=VIRT_MACHINE_ID msg=audit(1781641224.479:2099037): pid=58538 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:virtd_t:s0 msg='virt=qemu vm=\"r5vm\" uuid=fb5e54c6-0345-4b27-b694-688d88eb48d0 vm-ctx=system_u:system_r:svirt_t:s0:c62,c990 img-ctx=system_u:object_r:svirt_image_t:s0:c62,c990 model=selinux exe=\"/usr/sbin/libvirtd\" hostname=? addr=? terminal=? res=success'",
    "UID=\"root\" AUID=\"unset\""
  ],
  "record_type": "VIRT_MACHINE_ID"
}

VIRT_INTEGRITY_CHECK msgtype 2503

#
Message type
2503
Fires
Emitted by default (no audit rule required)

Description

Guest integrity results

VIRT_CREATE msgtype 2504

#
Message type
2504
Fires
Emitted by default (no audit rule required)

Description

Creation of guest image

VIRT_DESTROY msgtype 2505

#
Message type
2505
Fires
Emitted by default (no audit rule required)

Description

Destruction of guest image

VIRT_MIGRATE_IN msgtype 2506

#
Message type
2506
Fires
Emitted by default (no audit rule required)

Description

Inbound guest migration info

VIRT_MIGRATE_OUT msgtype 2507

#
Message type
2507
Fires
Emitted by default (no audit rule required)

Description

Outbound guest migration info

References