Description
NightWatcher is a tool designed to log entire SSH sessions including commands and user switching. It achieves this by combining logs from journald and auditd. The system consists of an agent and a server. The agent collects the logs and sends them to the server which handles the actual grouping of the data to quickly move the logs away from the client.
Technologies used
- AuditD
- JournalD
- Golang
Demo Videos
This video shows NightWatcher in action.