Skip to content

Auditctl Logging Actions In Containers

The following rule captures all executions in Linux, and therefore in containers running on a host.

Terminal window
-a always,exit -F arch=b64 -S execve -F key=execve