Dumps all filesystem events for a specific mount using the Linux fanotify interface
Switch branches/tags
Nothing to show
Clone or download
Fetching latest commit…
Cannot retrieve the latest commit at this time.
Permalink
Failed to load latest commit information.
.gitignore
LICENSE
Makefile
README.md
cache.c
cache.h
dll.c
dll.h
fsnoop.c
resolve.c
resolve.h

README.md

fsnoop

Dumps all filesystem operations from the specified mount point using the Linux fanotify interface.

Requirements

  • Linux >= 2.6.36 compiled with fanotify support
  • Linux headers
  • Make
  • GCC

Building

Clone the repo and make

git clone https://github.com/jeffwalter/fsnoop.git
cd fsnoop
make

That's it.

Usage

To be completed...