# Getting all Shell activity

**URL:** <https://discuss.elastic.co/t/getting-all-shell-activity/170236>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [February 27, 2019, 7:45pm UTC](https://discuss.elastic.co/t/getting-all-shell-activity/170236 "2019-02-27T19:45:19Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![nwed](https://avatars.discourse-cdn.com/v4/letter/n/dbc845/32.png) [@nwed](https://discuss.elastic.co/u/nwed)\
**Post date:** [February 27, 2019, 7:45pm UTC](https://discuss.elastic.co/t/getting-all-shell-activity/170236/1 "2019-02-27T19:45:20Z")

</div>

We have been doing some diligent testing against auditbeat and auditd. This is a very strong solution that doesn't require too much of the host system(with the right rules). We have expanded our testing to make sure that we aren't missing context for ANY FIM events.

What we are coming to find, is that auditd will miss shell built-ins. This is even if you are collecting all execve. If the built-in manipulates a process, you should get a related syscall. But if someone is using the built-in to establish persistence, you may not see it. You might see it in "-S write" but that's not very scalable.

Does anyone have any suggestions on how to address this? It seems like pam\_tty\_audit.so may be a solution but output is not real time, spawning another shell can continue to delay output. Is auditbeat able to consume the output of aureport -tty?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 1, 2019, 3:48pm UTC](https://discuss.elastic.co/t/getting-all-shell-activity/170236/2 "2019-03-01T15:48:57Z")

</div>

> [@nwed](#):
>
> Is auditbeat able to consume the output of aureport -tty?

Yeah, that should work. I tested a while back and was seeing activity in the shell.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 22, 2019, 3:49pm UTC](https://discuss.elastic.co/t/getting-all-shell-activity/170236/3 "2019-03-22T15:49:29Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
