On Mon, Mar 13, 2017 at 12:31 PM, Jessica Yu wrote:
> +++ Paul Moore [13/03/17 10:16 -0400]:
>>
>> On Sat, Mar 11, 2017 at 9:24 PM, Richard Guy Briggs
>> wrote:
>>>
>>> When a sysadmin wishes to monitor module unloading with a syscall rule
>>> such as:
>>> -a
On Mon, Mar 13, 2017 at 12:31 PM, Jessica Yu wrote:
> +++ Paul Moore [13/03/17 10:16 -0400]:
>>
>> On Sat, Mar 11, 2017 at 9:24 PM, Richard Guy Briggs
>> wrote:
>>>
>>> When a sysadmin wishes to monitor module unloading with a syscall rule
>>> such as:
>>> -a always,exit -F arch=x86_64 -S
+++ Paul Moore [13/03/17 10:16 -0400]:
On Sat, Mar 11, 2017 at 9:24 PM, Richard Guy Briggs wrote:
When a sysadmin wishes to monitor module unloading with a syscall rule such as:
-a always,exit -F arch=x86_64 -S delete_module -F key=mod-unload
the SYSCALL record doesn't tell
+++ Paul Moore [13/03/17 10:16 -0400]:
On Sat, Mar 11, 2017 at 9:24 PM, Richard Guy Briggs wrote:
When a sysadmin wishes to monitor module unloading with a syscall rule such as:
-a always,exit -F arch=x86_64 -S delete_module -F key=mod-unload
the SYSCALL record doesn't tell us what module was
On Sat, Mar 11, 2017 at 9:24 PM, Richard Guy Briggs wrote:
> When a sysadmin wishes to monitor module unloading with a syscall rule such
> as:
> -a always,exit -F arch=x86_64 -S delete_module -F key=mod-unload
> the SYSCALL record doesn't tell us what module was requested for
On Sat, Mar 11, 2017 at 9:24 PM, Richard Guy Briggs wrote:
> When a sysadmin wishes to monitor module unloading with a syscall rule such
> as:
> -a always,exit -F arch=x86_64 -S delete_module -F key=mod-unload
> the SYSCALL record doesn't tell us what module was requested for unloading.
>
> Use
When a sysadmin wishes to monitor module unloading with a syscall rule such as:
-a always,exit -F arch=x86_64 -S delete_module -F key=mod-unload
the SYSCALL record doesn't tell us what module was requested for unloading.
Use the new KERN_MODULE auxiliary record to record it.
The SYSCALL record
When a sysadmin wishes to monitor module unloading with a syscall rule such as:
-a always,exit -F arch=x86_64 -S delete_module -F key=mod-unload
the SYSCALL record doesn't tell us what module was requested for unloading.
Use the new KERN_MODULE auxiliary record to record it.
The SYSCALL record
8 matches
Mail list logo