Unix

Unix allows you to monitor and identify threats in your organization using Unix data. LogPoint aggregates and normalizes the Unix logs so you can analyze the information through dashboards and security reports. Unix dashboards and reports provide visualization of event details for authentication requests, privilege escalation, and user account management of the Unix environment detected in your network.

Unix consists of the following components:

  1. Dashboard Packages

    • LP_Unix Overview

    • LP_Unix Privilege Escalation

    • LP_UNIX: AUTHENTICATION

    • LP_Unix: User Account Management

  2. Normalization Packages

    • LP_Unix Dovecot

    • LP_Unix Scponly

    • LP_Unix Nullmailer

    • LP_Unix Iptables

    • LP_Unix Syscall

    • LP_Unix Ftpd

    • LP_Unix Zookeeper

    • LP_Unix Vasd

    • LP_Unix Etcd

    • LP_Unix Rtkit

    • LP_Unix SQL Query

    • LP_Unix clurgmgrd

    • LP_Unix Iptables

    • LP_Unix Logger

    • LP_Unix Ftp

    • LP_Unix Xntpd

    • LP_Unix Redis Server

    • LP_Unix Chkpwd

    • LP_Unix IPsec

    • LP_Unix Kubelet

    • LP_Unix Generic

    • LP_Unix adcli

    • LP_Unix Dockerd

    • LP_Unix Chef Client

    • LP_Unix SNMP Traps

    • LP_Unix Auditd

    • LP_Unix Crond

    • LP_Unix Pure Ftpd

    • LP_Unix Inetd

    • LP_Unix SNMP

    • LP_Unix Dhclient

    • LP_Unix Cron

    • LP_Unix Infinity

    • LP_Unix Vparmodify

    • LP_Unix VS Ftpd

    • LP_Unix Rsandbox

    • LP_Unix Runuser

    • LP_Unix Devd

    • LP_Unix Proftpd

    • LP_Solaris OS

    • LP_Unix SSL Proxy

    • LP_Unix SCC

    • LP_Unix Audispd

    • LP_UNIX NFS

    • LP_Unix nslcd

    • LP_Unix Httpd

    • LP_Unix Mountd

    • LP_Unix dnsmasq

    • LP_Unix Run-parts

    • LP_Unix Kafka

    • LP_Unix Ipmserver

    • LP_Unix check nrpe

    • LP_Unix Anacron

    • LP_Unix php

    • LP_Unix Xpand

    • LP_Unix Routed

    • LP_Unix Bash

    • LP_UNIX Nscd

    • LP_Unix Lvm

    • LP_Unix Pengine

    • LP_Unix Stonith NG

    • LP_Unix Goferd

    • LP_Unix Nagios

    • LP_Unix IPMIEVD

    • LP_Unix SAP

    • LP_Unix Vmunix

    • LP_Unix Savd

    • LP_Unix Winbindd

    • LP_Unix Syslog NG

    • LP_Unix SU

    • LP_Unix l4d

    • LP_Unix Rsyslogd

    • LP_Unix Rhnsd

    • LP_Unix puppet-agent

    • LP_Unix Suhosin

    • LP_Unix Sudo

    • LP_Unix ptymonitor

    • LP_Unix Sfd

    • LP_Unix Smbd

    • LP_Unix passwd

    • LP_Unix sssd

    • LP_Unix Lrmd

    • LP_Unix InotifyWait

    • LP_Unix UCARP

    • LP_Red Hat Linux

    • LP_Unix rear

    • LP_Unix NTPD

    • LP_Unix RpcMountd

    • LP_Unix Lighttpd

    • LP_Unix Cimserver

    • LP_Unix Cmclconfd

    • LP_Unix Lvmpud

    • LP_Unix NS

    • LP_Unix ndo2db

    • LP_Kernel

    • LP_Unix Agetty

    • LP_Unix Sudoscriptd

    • LP_Docker

    • LP_Unix Rshd

    • LP_Unix xinetd

    • LP_Unix SSHD

    • LP_Unix Cifs Upcall

    • LP_Unix Auditlog

    • LP_Unix Sftp Server

    • LP_Unix rgmanager

    • LP_Unix PAM Tally

    • LP_Unix subscription-manager

    • LP_Unix Syslogd

    • LP_Common Unix System

    • LP_Unix Systemd

    • LP_Unix Yum

    • LP_Unix Snmpd

    • LP_Unix Named

    • LP_Unix Newrelic Infra

    • LP_Unix Crmd

  3. Alert Packages

    • LP_Unix Possible Bruteforce Attack

    • LP_Unix Kernel Logging Stopped

    • LP_Unix User Deleted

    • LP_Unix Password Expiry Changed for User

    • LP_Unix Group Deleted

    • LP_Unix Privilege Escalation Failed

    • LP_Unix Security Violation

    • LP_Unix User Account Unlocked

    • LP_Unix Excessive Denied Connection

    • LP_Unix User Session Alert

    • LP_Unix User Removed from Privileged Group

  4. Label Packages

    • LP_Unix SSHD

    • LP_Common Unix Systems

    • LP_Unix

  5. Compiled Normalizers

    • UnixSysmonCompiledNormalizer

    • UnixCompiledNormalizer

    • UnixAuditLogNormalizer

  6. Report Packages

    • LP_Unix: User Privilege Escalation

    • LP_Unix: User Account Management

    • LP_UNIX: AUTHENTICATION

  7. Knowledge Base Lists

    • ADMINS

    • ADMIN_GROUPS


Helpful?

We are glad this guide helped.


Please don't include any personal information in your comment

Contact Support