936fc446c1
bsmtrace is a audit driven host based intrusion detection system which operates on finite state machine principles. Since it's audit driven, it requires that operating system security auditing be enabled. This requires FreeBSD 6.2 at a minimum. By default it provides real-time analysis through the use of an audit pipe, however it can operate on regular audit trail files as well. Approved by: Pav Reviewed by: Pav (and others)
3 lines
67 B
Text
3 lines
67 B
Text
sbin/bsmtrace
|
|
%%EXAMPLESDIR%%/bsmtrace.conf
|
|
@dirrm %%EXAMPLESDIR%%
|