Categories
procwatch
Procwatch watches a /proc filesystem for new processes. When a process is created, procwatch reports the time, the username, the PID, and the binary that was run. Its output is suitable for logging to log files and is geared for system administrators who are testing a new but as yet untrusted UNIX system. Although it cannot detect, and is not proof against, hacked loadable kernel modules that have modified /proc, it is useful in watching for possible rogue binaries.
Last updated 26 Nov, 2001
Versions
1.2
1.2 stable released 2001-11-23
- Released: 23 Nov, 2001
- Code Maturity: Stable
- Source Archive: http://www.speakeasy.net/~aguyot/procwatch/proc...
- Licenses: Perl
- Interfaces: Command Line




