The audit package contains the user-spaceutilities for creating audit rules, as well as forstoring and searching the audit records generateby the audit subsystem in the Linux 2.6 kernel. It also has a basic Intrusion Detection plugin based on audit events capable of IDMEF alerting using prelude.
License: GNU General Public License (GPL)
Changes:
libauparse iteration bugs were fixed. Path nameprocessing is done in avc alerts. Key formattingis done in ausearch. mmap page 0 alert was addedfor the prelude plugin. audispd now has a separatepriority boost configuration option.
More...