Andrew Mercer
on this page

auditd is the userspace daemon for the Linux kernel's audit subsystem: real-time, syscall-level logging of security-relevant events — who read/wrote/executed what, configuration changes, authentication events, and arbitrary custom watch rules. Unlike AIDE/Tripwire, which detect that a file changed on the next scheduled check, auditd logs the event as it happens, including which process and user did it.

Install and enable

sudo dnf install audit               # often preinstalled on RHEL family
sudo apt-get install auditd audispd-plugins
sudo systemctl enable --now auditd

Rule files

Persistent rules live in /etc/audit/rules.d/*.rules (compiled into /etc/audit/audit.rules by augenrules on RHEL family, or written directly on Debian/Ubuntu). Load rules immediately without a reboot with auditctl, and make them persistent by also adding them to a rules file.

sudo auditctl -l                    # list currently loaded rules
sudo auditctl -s                    # audit daemon status

Watch a file or directory for changes

sudo auditctl -w /etc/passwd -p wa -k passwd_changes
sudo auditctl -w /etc/shadow -p wa -k shadow_changes
sudo auditctl -w /etc/ssh/sshd_config -p wa -k sshd_config_changes

-p is the permission set to watch: r read, w write, x execute, a attribute change. -k tags matching events with a searchable key.

Track a syscall

sudo auditctl -a always,exit -F arch=b64 -S execve -k exec_tracking     # log every program execution
sudo auditctl -a always,exit -F arch=b64 -S connect -k network_connects  # log outbound connect() calls

A baseline rules file (persistent)

# /etc/audit/rules.d/hardening.rules
-w /etc/passwd -p wa -k identity
-w /etc/group -p wa -k identity
-w /etc/shadow -p wa -k identity
-w /etc/sudoers -p wa -k privilege_escalation
-w /etc/sudoers.d/ -p wa -k privilege_escalation
-w /var/log/auth.log -p wa -k auth_log
-a always,exit -F arch=b64 -S execve -k exec_tracking
-e 2      # make the running config immutable until reboot (optional, hardened systems)
sudo augenrules --load               # RHEL family: compile rules.d/*.rules into the running config
sudo systemctl restart auditd        # Debian/Ubuntu: restart to pick up /etc/audit/audit.rules

The final -e 2 line locks the audit configuration against further changes until reboot — useful for compliance profiles (PCI-DSS, CIS benchmarks reference this), but it also means you cannot loosen a bad rule without rebooting, so add it only once rules are proven.

Search and report

sudo ausearch -k passwd_changes                     # events tagged with a given key
sudo ausearch -f /etc/shadow                         # events touching a specific file
sudo ausearch -ua alice                              # events by a specific user
sudo ausearch -ts today                              # events since midnight
sudo aureport -au                                    # summarized authentication report
sudo aureport --summary                              # overview across all event types

ausearch filters raw events; aureport produces the summarized/tabular views, both reading from /var/log/audit/audit.log.

Notes

  • Audit rules add per-syscall overhead; broad execve/connect tracking on a busy host generates a lot of log volume — start narrow (specific files, specific syscalls) and widen deliberately.
  • CIS Benchmarks and most compliance frameworks (PCI-DSS, STIG) publish specific auditd rule sets; see cisecurity.org's benchmarks as a starting reference point rather than writing rules from scratch.
  • Forward audit.log off-host (syslog/audispd, or a log pipeline) for the same reason noted under AIDE: a root-level attacker can otherwise edit local logs to cover their tracks.