Exec call auditing

Wahaj Ali wahajali at gmail.com
Thu May 6 18:04:52 UTC 2010


Hello,

As part of my course I am required to look at the auditing code in the linux
kernel, more specifically the part where the exec() calls are being logged.
I would really appreciate any help, especially regarding where exactly that
code in the whole database can be found, i.e. the part of the code that is
logging the environment variables. My guess so far is that
audit_log_single_execve_arg in auditsc.c is doing most part of the work.


I would be really grateful for your help.

Regards,
Wahaj Ali
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://listman.redhat.com/archives/linux-audit/attachments/20100506/fad34917/attachment.htm>


More information about the Linux-audit mailing list