willfindlay / suidsnoop

suidsnoop is a tool based on eBPF LSM programs that logs whenever a suid binary is executed and implements custom allow/deny lists.
ā˜†15Updated 3 years ago

Alternatives and similar repositories for suidsnoop:

Users that are interested in suidsnoop are comparing it to the libraries listed below