audit_events Sandbox violations #306

Closed
opened 2026-01-19 18:30:00 +00:00 by michael · 2 comments
Owner

Originally created by @robertgendler on GitHub.

Audit is overly busy and talkative

Editing the audit_event file and changing
43127:AUE_MAC_SYSCALL:mac_syscall(2):ad
to
43127:AUE_MAC_SYSCALL:mac_syscall(2):zz
Will stop sandbox violations from being in the audit logs but make them still auditable if desired using the zz flag.

Possibly adding an audit supplemental or rule.

Originally created by @robertgendler on GitHub. Audit is overly busy and talkative Editing the audit_event file and changing `43127:AUE_MAC_SYSCALL:mac_syscall(2):ad` to `43127:AUE_MAC_SYSCALL:mac_syscall(2):zz` Will stop sandbox violations from being in the audit logs but make them still auditable if desired using the zz flag. Possibly adding an audit supplemental or rule.
Author
Owner

@golbiga commented on GitHub:

merged with main

@golbiga commented on GitHub: merged with `main`
Author
Owner

@robertgendler commented on GitHub:

Added a note in audit_flags_ad_configure with commit dc3e5e1e27

@robertgendler commented on GitHub: Added a note in audit_flags_ad_configure with commit dc3e5e1e278b95b5c6dc4cf2a69265f1af07ff6e
Sign in to join this conversation.
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: usnistgov/macos_security#306