Skip to content

Releases: threathunters-io/laurel

Release v0.3.0

01 Feb 14:56
Compare
Choose a tag to compare
  • Feature: Process label feature
  • Add fields (comm, exe, ID) to PROCESS_INFO
  • Periodic status reports to syslog
  • Parser bugfixes
  • Add logo provided by Birgit Meyer

Release v0.2.2

22 Dec 00:15
Compare
Choose a tag to compare

Various fixes to parser and coalesce logic

Release v0.2.1

21 Dec 08:45
Compare
Choose a tag to compare
  • Fix for wrong Syslog for error messages

Release v0.2.0

20 Dec 00:08
Compare
Choose a tag to compare
  • Impement translation of numeric/binary values equivalent to auditd log_format=ENRICHED
  • Deal with input streams without EOE messages
  • Provide a library crate
  • Reimplement audit message parser using nom

Release v0.1.5

01 Nov 10:48
Compare
Choose a tag to compare

Fix bug in process tracking implementation that could lead to an infinite loop and break logging

Release v0.1.4

25 Oct 15:25
Compare
Choose a tag to compare
  • Log selected environment variables on execve
  • SELinux policy
  • Workarounds for irregularly formatted kernel/apparmor messages

Release v0.1.3

25 Sep 21:55
Compare
Choose a tag to compare
  • Option to output EXECVE arguments as single string
  • Valid UTF-8 sequences in strings are no longer percent-encoded
  • Add --dry-run switch to only check the configuration file
  • Documentation imprrovements

Release v0.1.2

20 Sep 21:42
Compare
Choose a tag to compare
  • parser: Properly recognize SELINUX AVC and netlabel messages
  • parser: Process partially parseable lines
  • Small error message and documentation improvements

Release v0.1.1

10 Sep 13:46
Compare
Choose a tag to compare
  • Fix musl-libc-specific bug where syslog messages carried an empty name
  • Documentation updates