Skip to main content


Nessun agente? Nuovo approccio all'EDR su sistemi Windows
#CyberSecurity
insicurezzadigitale.com/nessun…

The Pirate Post reshared this.

in reply to N_{Dario Fadda}

friendica (DFRN) - Link to source
plan-A
 — (Proud Eskimo!)

@N_{Dario Fadda}
And if Linux users think they are untouchable because the article concentrates on Windows as ost use OS yet.. think again.
You'll need to in case of one of those applying tour distro>

auditd (Linux Audit System): For monitoring system calls, file access, and process activity.
systemd-journald: For logging and monitoring system events.
ethtool and tcpdump: For network traffic analysis.
inotify or audit rules: For file system changes detection.
syslog or rsyslog: For centralized log collection and analysis.


Each has his personal choice as long he know what he do.
I use WireShark instead but that is for each to choose as it demands a basic understanding of it and for the rest there is this handy site thx 2 Foss Community.
linux-audit.com/system-adminis…