pirxthepilot
execve
syscalls, is that correct? If so, is osquery not a good fit then if we want to log other syscalls (sethostname
, settimeofday
etc)? in our case we're trying to follow CIS standards and the benchmarks for audit require more than execve
.alessandrogario
pirxthepilot
alessandrogario