Linux Base

Linux Base Sigma Model #

This model is designed for triage of dead disk or file based live analysis. The rules that use this model will be evaluated once on all events.

After all relevant rules are evaluated, the collection is complete.

NOTE: Auditd configuration based on https://raw.githubusercontent.com/Neo23x0/auditd/refs/heads/master/audit.rules

Log Sources #

Following is a list of recognized log sources.

Log SourceDesc
*/linux/*
*/linux/sshd
*/linux/cron
*/linux/auth
*/linux/syslog
*/linux/sudo
*/linux/auditd
network_connection/linux/*
process_creation/linux/*

Field Mappings #

The following field mappings can be used to access fields within the event. Note that it is also possible to access the fields directly (e.g. EventData.AccessMask)

View all Field Mappings

*/linux/* #

Details

*/linux/sshd #

Details

*/linux/cron #

Details

*/linux/auth #

Details

*/linux/syslog #

Details

*/linux/sudo #

Details

*/linux/auditd #

Details

network_connection/linux/* #

Details

process_creation/linux/* #

Details