This made me a little paranoid about SystemD
https://ma.ttias.be/whats-new-systemd-2015-edition/
Specifically
"auditing: implemented for when your application needs to be NSA approved (that appeared to be the main reason, Lennart himself said he's not a big fan of it). Can log all system calls made to /etc/passwd etc to the audit log. Auditing is integrated with journald, audit-tools to read the logs have been improved."

Reply via email to