Dumps all filesystem operations from the specified mount point using the Linux fanotify interface.
- Linux >= 2.6.36 compiled with fanotify support
- Linux headers
- Make
- GCC
Clone the repo and make
git clone https://github.com/jeffwalter/fsnoop.git
cd fsnoop
make
That's it.
To be completed...