Protecting Oracle Solaris Audit trail files from tampering/removal – even by root
Starting in Oracle Solaris 11.4.87 the auditd plugin audit_binfile, which is responsible for writing to the local binary format audit files, now marks the active audit file as append_only when it is first created, and will remove all write permissions when it is closed and renamed from <start_time>.not_terminated.<hostname> to <start_time>.<end_time>.<hostname>. This means we can now use ZFS File Retention to provide additional protection for the audit trail files.
For more details, please visit: Protecting Oracle Solaris Audit trail files from tampering/removal – even by root