Tools/auditd
auditd
Linux kernel-level audit logging daemon — records system calls, file access, and authentication events per-host, configured via audit rules. The on-prem/host equivalent to AWS_CloudTrail when there's no cloud control plane to log: CloudTrail covers the AWS account, auditd covers a single Linux box. Typically feeds into Wazuh (which ships an auditd integration) or another SIEM for centralized analysis rather than being read directly.