Bio: Ryan Huber does security things at Slack. Before that Ryan Huber did other security things. When he was 12, he wrote malware in Pascal + inline asm to steal his teacher’s password. His teacher wasn’t impressed.

Brief Overview of Ryan Huber’s Upcoming Modern Security Episode

Auditd is a very useful feature on the linux kernel. We’ve written a golang-based open source alternative to the userspace auditd daemon that ships with most distros. We use go-audit to help us monitor activity on thousands of hosts. We will discuss using go audit along with a reliable logging pipeline consisting of streamstash, elasticsearch, and elastalert, which we use to collect and process data from thousands of hosts.

