September 27, 2003

Know Your Enemy: Sebek2 - A kernel based data capture tool

LogError writes "Sebek is a piece of code that lives entirely in kernel space and records either some or all data accessed by users on the system. This paper is a detailed discussion of Sebek, how it works and its value."



  • Linux
