-S Syscall: specifies which system call (syscall) should be monitored.
See this for reference: https://filippo.io/linux-syscall-table/
-S Syscall: specifies which system call (syscall) should be monitored.
See this for reference: https://filippo.io/linux-syscall-table/
exit
the event to be logged should occur when a system call finishes, rather than when it starts or during its execution
always
always monitor
Trigger alerts when execute permission is added to a script
Good Idea for the /tmp directory! isn't it?