Audit event class as defined in audit_class(5). Identifies the category of events being audited in the macOS BSM (Basic Security Module) audit subsystem. The class abbreviations correspond to entries in /etc/security/audit_class.
Values
| Enum Value | Description |
|---|---|
|
|
Authentication and Authorization events — tracks successful and failed authentication attempts and authorization decisions. |
|
|
Administrative events — tracks administrative actions taken on the system. |
|
|
All audit classes — a pseudo-class that matches every defined audit class. Use with care as it produces a very high volume of audit records. |
|
|
Application-defined events — tracks events generated by applications using the BSM audit API. |
|
|
File close events — tracks close(2) system calls on file descriptors. |
|
|
Program execution events — tracks execve(2) calls. When the argv or arge policy flags are set, command-line arguments and environment variables are also recorded. |
|
|
File and attribute access events — tracks stat(2) and similar calls that read file metadata without modifying the file. |
|
|
File create events — tracks creation of new files and directories. |
|
|
File delete events — tracks unlink(2), rmdir(2), and similar calls that remove file system objects. |
|
|
File attribute modify events — tracks chmod(2), chown(2), and similar calls that change file metadata. |
|
|
File read events — tracks read(2) and similar calls on file descriptors. |
|
|
File write events — tracks write(2) and similar calls on file descriptors. |
|
|
ioctl events — tracks ioctl(2) system calls. |
|
|
Interprocess communication events — tracks IPC operations such as shared memory, message queues, and semaphores. |
|
|
Login and logout events — tracks user login, logout, and session lifecycle events. This class is typically always enabled and corresponds to the lo flag in audit_control(5). |
|
|
Non-attributable events — tracks events that cannot be attributed to a specific user, such as actions taken before authentication completes. Corresponds to the naflags parameter in audit_control(5). |
|
|
Invalid audit class — when used as a prefix modifier in a flag set, disables auditing for the associated class. Not a real event class. |
|
|
Network events — tracks network-related system calls such as connect(2), bind(2), and accept(2). |
|
|
Other events — tracks miscellaneous events not covered by a more specific class. |
|
|
Process events — tracks process lifecycle operations such as fork(2), exit(2), and kill(2). |
|
|
System-wide security state change events — tracks audit configuration changes, audit log rotation, and other kernel-level security state transitions. |
Used by
AuditFlagtype: A single audit flag entry, combining an event class with its recording-mode prefix.
Example
Example
"AA"