mirror of
https://github.com/usnistgov/macos_security.git
synced 2026-02-03 14:03:24 +00:00
audit_events Sandbox violations #306
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @robertgendler on GitHub.
Audit is overly busy and talkative
Editing the audit_event file and changing
43127:AUE_MAC_SYSCALL:mac_syscall(2):adto
43127:AUE_MAC_SYSCALL:mac_syscall(2):zzWill stop sandbox violations from being in the audit logs but make them still auditable if desired using the zz flag.
Possibly adding an audit supplemental or rule.
@golbiga commented on GitHub:
merged with
main@robertgendler commented on GitHub:
Added a note in audit_flags_ad_configure with commit
dc3e5e1e27