how could I intercept linux sys calls?

前端 未结 9 2165
夕颜
夕颜 2020-11-28 07:31

Besides the LD_PRELOAD trick , and Linux Kernel Modules that replace a certain syscall with one provided by you , is there any possibility to intercept a syscall ( open for

9条回答
  •  暗喜
    暗喜 (楼主)
    2020-11-28 08:32

    Sounds like you need auditd.

    Auditd allows global tracking of all syscalls or accesses to files, with logging. You can set keys for specific events that you are interested in.

提交回复
热议问题