Sudo logs for Blue Teamers
Action | Key |
---|---|
Play / Pause | K or space |
Mute / Unmute | M |
Toggle fullscreen mode | F |
Select next subtitles | C |
Select next audio track | A |
Show slide in full page or toggle automatic source change | V |
Seek 5s backward | left arrow |
Seek 5s forward | right arrow |
Seek 10s backward | shift + left arrow or J |
Seek 10s forward | shift + right arrow or L |
Seek 60s backward | control + left arrow |
Seek 60s forward | control + right arrow |
Decrease volume | shift + down arrow |
Increase volume | shift + up arrow |
Decrease playback rate | < |
Increase playback rate | > |
Seek to end | end |
Seek to beginning | beginning |
Share this media
HLS video stream
You can use an external player to play this stream (like VLC).
HLS video streamWhen subscribed to notifications, an email will be sent to you for all added annotations.
Your user account has no email address.
Information on this media
What does this mean for your Blue Team? You have more control in defining both the people who can access your system, and the actions they can perform in it. The resulting log messages contain a lot more information in an easy to process format. This way you do not just collect more logs, but it becomes easier to detect and react to important sudo events.
From my talk, you can learn about JSON-formatted logging in sudo and how to work with those logs in syslog-ng. I will introduce you to some of the latest sudo features, like chroot and cwd support, and logging and intercepting sub-commands. I will also show you how to work with these logs within syslog-ng: for example, how to parse JSON-formatted log messages and working with name-value pairs to create alerts on critical sudo events.
Peter is an engineer working as open source evangelist at Balabit (a One Identity business), the company that developed syslog-ng. He assists distributions to maintain the syslog-ng package, follows bug trackers, helps users and talks regularly about sudo and syslog-ng at conferences (SCALE, All Things Open, FOSDEM, LOADays, and others). In his limited free time he is interested in non-x86 architectures, and works on one of his PPC or ARM machines.Note to recruiters to save time for both of us: even with 20+ years of Linux & FreeBSD sysadmin/engineer/architect/whatever experience I am NOT looking for my next sysadmin job. Peter is an engineer working as open source evangelist at Balabit (a One Identity business), the company that developed syslog-ng. He assists distributions to maintain the syslog-ng package, follows bug trackers, helps users and talks regularly about sudo and syslog-ng at conferences (SCALE, All Things Open, FOSDEM, LOADays, and others). In his limited free time he is interested in non-x86 architectures, and works on one of his PPC or ARM machines.
Other media in the channel "2022"
- 20 views, 1 this yearClosingJuly 6th, 2022
- 56 views, 10 this year, 3 this monthkdigger: A Context Discovery Tool for Kubernetes Penetration TestingJuly 6th, 2022
- 45 views, 6 this yearDissecting NTLM EPA & building a MitM proxyJuly 6th, 2022
- 81 views, 24 this year, 3 this monthFinding Java deserialization gadgets with CodeQLJuly 6th, 2022
- 82 views, 7 this yearMobSF for penetration testersJuly 6th, 2022
- 80 views, 7 this yearImprove your Malware Recipes with CyberchefJuly 6th, 2022