Procwatch

Procwatch is security monitor written in Perl that watches a /proc filesystem for new processes. When a process is created, procwatch reports the time, the username, the PID, and the binary that was run. Its output is suitable for logging to log files and is geared for system administrators who are testing a new but as yet untrusted UNIX system. Although it cannot detect, and is not proof against, hacked loadable kernel modules that have modified /proc, it is useful in watching for possible rogue binaries.

Tags
Licenses
Operating Systems
Implementation

Tweet this project Short link

Rss Recent releases

Changes: This release can run as a daemon and log to a specified file.

No changes have been submitted for this release.

E89673ab96a273efa44cba6830816ea4_thumb

Project Spotlight

Ex-Crawler

A modern and fast Web crawler.

D257baeeaa9bbfe41055583a607083a5_thumb

Project Spotlight

JumpBox for MoinMoin

A virtual appliance for the MoinMoin wiki system.