Skip to content

Add PAM Sessions from auth.log and secure - #369

Merged
abrignoni merged 1 commit into
mainfrom
feat/pam-sessions
Sep 28, 2026
Merged

abrignoni merged 1 commit into
mainfrom
feat/pam-sessions

Conversation

@abrignoni

Copy link
Copy Markdown
Owner

Adds a PAM Sessions artifact for Linux images, read from auth.log and secure and their rotations. Each row is a pam_unix "session opened" or "session closed" line, for any service, with:

  • the time in UTC for RFC 3339 stamps, beside the time as recorded
  • the service, user, the user's UID where Linux-PAM 1.7.0 writes it, the login name and the process's user ID

It reads the forms of Linux-PAM 1.7.0 and 1.0.1. The shared syslog reader gains a function that returns every line, which program_lines now uses; the other syslog artifacts' output is unchanged.

🤖 Generated with Claude Code

One artifact under Logins (Linux): each line in which pam_unix recorded a
session being opened or closed, for any service (sshd, su, sudo, cron,
GDM, the systemd user manager and others), with the service, user, the
user's UID where Linux-PAM 1.7.0 writes it, the login name and the
process's user ID split out. Both the 1.7.0 and the 1.0.1 forms are read.

The shared syslog reader gains syslog_lines() and reported_time(), and
program_lines() now uses them; SSH Server Log, sudo Commands and Account
Changes give byte-identical output before and after on the tested images.

Checked on ubuntu2604_arm64_triage (1,370 rows), ubuntu2604_arm64_authlog
(1,404) and honeynet_fc7_debian5 (18, each console login matching a wtmp
record at the same second).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@abrignoni
abrignoni merged commit d5e9c32 into main Sep 28, 2026
11 checks passed
@abrignoni
abrignoni deleted the feat/pam-sessions branch September 28, 2026 11:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant