Skip to content

xnumon self-defense #18

@droe

Description

@droe

Config changes are already monitorable by watching eventcode 0 for unexpected settings and agent restarts. However, self-defense could be further improved, perhaps by:

  • Including hashes of configuration file in eventcode 0 events
  • Logging writes to configuration, binary, control utility, log files

Having said that, an attacker with escalated privileges will always be able to disrupt or disable xnumon.

Metadata

Metadata

Assignees

No one assigned

    Labels

    pri:lownot a priority but contribution welcometype:featurerequest for additional functionality

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions