IT Forensics · Linux

Forensic analysis of SELinux audit logs – evaluating Mandatory Access Control events

SELinux extends traditional Unix permissions with a rule-based Mandatory Access Control system and logs policy violations as so-called AVC denials, typically via the audit subsystem.

Enquire without obligation

These log entries may indicate both actual unauthorised access attempts and standard application functions that are not yet covered by the policy. Careful analysis is therefore required.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.

Our services

We analyse existing SELinux audit entries, map AVC denials to the relevant processes and resources, and assess whether these represent security-related breaches or routine configuration changes.

Typical areas of application

Investigation of blocked attempts to access protected resources
Detection of policy breaches in hardened environments
Assessment of subsequent SELinux configuration changes
Support with compliance investigations
Incident Response on Linux Systems
Judicial and non-judicial expert reports

How a SELinux audit analysis works

Once the backup has been completed, any existing AVC denials and other SELinux audit events are extracted and mapped to the relevant processes, files and security contexts. The results are evaluated in the context of the active policy configuration to distinguish between actual security incidents and routine configuration issues.

Why is SELinux analysis relevant to forensic investigations?

In hardened environments where SELinux is enabled, audit logs can provide valuable clues about attempts to access protected resources beyond the scope of standard permissions.

As not every AVC denial constitutes an actual attempt at an attack, expert assessment within the relevant application context is necessary to avoid misinterpretations.

Frequently Asked Questions

What is an AVC denial?+
An access attempt by a process to a resource, which was denied by the active policy and logged by SELinux.
Does an AVC denial automatically constitute an attack?+
No, these are often standard application functions that are not yet covered by the current policy.
Is SELinux enabled on all Linux distributions?+
No, its prevalence and default configuration vary depending on the distribution; amongst other things, it is often enabled on Red Hat-based systems.

LanCologne – Linux Forensics Cologne

Do you require a professional forensic investigation into „forensic analysis of SELinux audit logs"? LanCologne can assist you with the court-admissible preservation of digital evidence and the transparent analysis of relevant Linux artefacts.

Get in touch now