suidsnoop is a tool based on eBPF LSM programs that logs whenever a suid binary is executed and implements custom allow/deny lists.
-
Updated
Oct 31, 2021 - Rust
suidsnoop is a tool based on eBPF LSM programs that logs whenever a suid binary is executed and implements custom allow/deny lists.
Add a description, image, and links to the suid-binaries topic page so that developers can more easily learn about it.
To associate your repository with the suid-binaries topic, visit your repo's landing page and select "manage topics."