Access Trailing
You may trust your operational team but sometimes, mistakes happen.
As secure as you thought you could have been, your system might have been breached (from the inside or from the outside).
When this happens (or at least when you have any reasonable suspicion), the first thing to do is to block all system accesses. Next thing to do is forensic work. What could have happen ? Where ? Who did ?
Dalet Flex integrates native Linux Audit Deamon support.
In a nutshell, auditd will collect every action on the system (tracking all Linux syscalls at kernel level) and write it to log files. With remote logging enabled as well, you'll have a certitude that whatever happened on the instance and whoever might have tampered the system, traces of it are stored on a remote logging engine for further analytics.
Auditd will basically track everything:
- SSH connections
- Admin user launching a given shell command
- Opened files
- Privileges escalation
- ...
Enabling access trailing can be done by extending your ansible/vars/variables.yml file with:
dalet_baseos_security_access_trail_enabled: true
And rolling out infrastructure update:
$ opsctl deploy -p dalet.flex.infra