Configure Auditd and how to leverage it
Learn how to config and write rules to detect malicious activities
Refs
How to configure it

Script to install and applied Neo23x rules
Configure Syslog to send the auditd log
Configure Rsyslog
Use case
Last updated