auditd
auditd copied to clipboard
Update audit.rules
trafficstars
Added it as there are still many Linux distributions that this can be leveraged by attackers to configure boot-time tasks or establish persistence