Linux Audit System Call Events

Hassaan edited this page May 2, 2018 · 22 revisions

SPADE's Linux Audit Reporter interprets a subset of system calls. The table below summarizes the OPM edge(s), if any, that are generated and the value of the operation annotation on the edge(s). Note that some system calls only have an indirect effect (by updating SPADE's internal state).

System call OPM edge Operation
clone() WasTriggeredBy clone
or
fork
fork()
vfork()
WasTriggeredBy fork
setuid()
setreuid()
setresuid()
setfsuid()
WasTriggeredBy setuid
setgid()
setregid()
setresgid()
setfsgid()
WasTriggeredBy setgid
exit()
exit_group()
WasTriggeredBy exit
kill()* WasTriggeredBy unit
or
unit dependency
accept()
accept4()
Used accept
preadv()
pread()
read()
readv()
Used read
recvfrom()
recvmsg()
Used recv
init_module()
finit_module()
Used init_module
finit_module
creat() WasGeneratedBy create
chmod()
fchmod()
fchmodat()
WasGeneratedBy chmod
connect() WasGeneratedBy connect
ftruncate()
truncate()
WasGeneratedBy truncate
mprotect() WasGeneratedBy mprotect
sendto()
sendmsg()
WasGeneratedBy send
unlink()
unlinkat()
WasGeneratedBy unlink
vmsplice() WasGeneratedBy vmsplice
execve() Used

WasTriggeredBy
load

execve
close() Used
or
WasGeneratedBy
close
link()
linkat()
symlink()
symlinkat()
Used
and
WasGeneratedBy
and
WasDerivedFrom
link (read)

link (write)

link
tee() Used
and
WasGeneratedBy
and
WasDerivedFrom
tee (read)

tee (write)

tee
splice() Used
and
WasGeneratedBy
and
WasDerivedFrom
splice (read)

splice (write)

splice
mmap() Used
and
WasGeneratedBy
and
WasDerivedFrom
mmap (read)

mmap (write)

mmap
open()
openat()
Used
or
WasGeneratedBy
open

open/create
pwritev()
pwrite()
write()
writev()
WasGeneratedBy
and
WasDerivedFrom
write

update
rename()
renameat()
Used
and
WasGeneratedBy
and
WasDerivedFrom
rename (read)

rename (write)

rename
bind()
dup()
dup2()
dup3()
mknod()
mknodat()
pipe()
pipe2()
socket()
fcntl()
socketpair()
None (Interpretation has indirect effect)

*Only BEEP events, not signals, are reported.

Clone this wiki locally
You can’t perform that action at this time.
You signed in with another tab or window. Reload to refresh your session. You signed out in another tab or window. Reload to refresh your session.
Press h to open a hovercard with more details.