canonical / canonical/auditd-operator
Add audit watch rules for file transfer protocols
Open
- Dominant language
- Python
- Stars
- 2
- Forks
- 1
- PR merge metrics
- No merged PRs in 30d
Description
File transfer (scp, rsync, etc.) from client machine is blind to the session recording.
So auditd should watch them as well, and we should have corresponding alert rules.
Contributor guide
Research direction
Start by locating the auditd rule configuration and the existing alert-rule definitions for monitored commands. Review how current rules and alerts are represented, then add coverage for scp and rsync file transfers and verify that the corresponding alerts trigger as expected.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- linux
- Domain
- operating-systems, security
- Issue type
- Feature
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 52/100