Process accounting and lastcomm(1) can detect execve(2) violations
authorbluhm <bluhm@openbsd.org>
Fri, 3 Mar 2023 16:22:57 +0000 (16:22 +0000)
committerbluhm <bluhm@openbsd.org>
Fri, 3 Mar 2023 16:22:57 +0000 (16:22 +0000)
commit693dc5e1c009c5ddba5b7e66566029d2e38cec79
tree6c33a6434aa2b114f8c69179965d4edf2e566d46
parentbb47adf3f139e34b4de384972875ddec90dd74b3
Process accounting and lastcomm(1) can detect execve(2) violations
of pinsyscall(2) policy.  Report such findings in daily mail like
other security violations.  User has to turn on accounting=YES in
rc.conf.local to utilize this feature.
OK deraadt@
etc/daily