Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
auditd-attack — A Linux Auditd rule set mapped to MITRE's Attack Framework | Kitploit
Tools/GitHubGitHub/bfuzzy/auditd-attack
Defensive ToolsThreat Feeds & AggregatorsConfiguration AuditingThreat IntelligenceIntrusion Detection
GitHubbfuzzy/auditd-attack

auditd-attack

A Linux Auditd rule set mapped to MITRE's Attack Framework

View Repository
8221327 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

auditd-attack

A Linux Auditd rule set mapped to MITRE's Attack Framework

Disclaimer

Please ensure you test these rules prior to pushing them into production. This rule set is NOT meant to have all of its rules enabled all at once (although that'd be ideal) it is setup to serve as guidance toward increasing detection/hunting coverage.

WIKI

WIKI

Special Thanks To:

Eric Gershman

iase.disa.mil

cyb3rops

ugurengin

checkraze

auditdBroFramework

@MITREattack

TODO

  • Increase MITRE ATT&CK coverage
  • Test rules across multiple flavors of Linux
  • Determine performance impacts of the ruleset
Download Tool