Hacker News new | ask | show | jobs
by MrSec 3807 days ago
Look into auditd for logging execve() syscall instead. OSSEC can (directly) report or act on any thing reported through logs.
1 comments