LinuxCommandLibrary

pam_tty_audit

logs TTY keystrokes

TLDR

Enable TTY auditing

$ session required pam_tty_audit.so enable=*
copy
Audit specific users
$ session required pam_tty_audit.so enable=admin,root
copy
Disable for users
$ session required pam_tty_audit.so disable=service_account
copy

SYNOPSIS

pam_tty_audit.so [options]

DESCRIPTION

pam_tty_audit logs TTY keystrokes. Enables session auditing.
The module records terminal input. Requires audit daemon.

PARAMETERS

enable=USERS

Enable auditing for users.
disable=USERS
Disable auditing for users.
open_only
Audit session open only.
log_password
Include password typing.

CAVEATS

Requires auditd. Privacy implications. May log sensitive data.

HISTORY

pamttyaudit provides keystroke auditing for compliance requirements.

SEE ALSO

pam(8), auditd(8), aureport(8)

> TERMINAL_GEAR

Curated for the Linux community

Copied to clipboard

> TERMINAL_GEAR

Curated for the Linux community