// the find
devlab-group/immutable-audit
Tamper-evident audit trail for Linux process execution. eBPF captures execve, events are SHA-256 hash-chained, shipped to a separate collector, and independently verifiable by anyone holding the file. Educational proof of concept — detection, not prevention.
A proof-of-concept Linux process-execution auditor: eBPF captures execve events, an agent hash-chains them with SHA-256 and ships them to a collector, and a separate verifier can detect tampering without trusting the machine that produced the log. It's aimed at people studying tamper-evident log design or hash-chain mechanics, not anyone looking for a production audit pipeline — the author is explicit that this is detection, not prevention.
The security writeup is unusually honest about the actual limit of a hash chain: it states plainly that anyone who can edit the file can also recompute every hash after the edit, so the README builds a real answer (an externally-stored checkpoint hash+count) instead of pretending the chain alone proves immutability. The attack table mapping each tampering method to whether it needs that anchor is the kind of thing most 'tamper-evident' projects skip. Canonical, length-prefixed serialization before hashing closes a real gap — a naive JSON-hash-chain lets you rewrite a record's bytes (duplicate keys, reordering) without changing its decoded values, leaving every hash intact while a different value is read back. The reliability section is also concrete rather than hand-wavy: the agent rewinds its chain position on a failed delivery, but gives up after three consecutive disagreements instead of silently resyncing with the collector, which would otherwise let an unauthenticated caller rediscover the host's exact chain position.
Zero forks and 5 stars — this hasn't been exercised by anyone outside the author, so treat the test coverage claims and the eBPF cross-platform builds as unverified in practice. There's no agent authentication and transport is plain HTTP by the author's own admission, so the collector's host allowlist is the only thing stopping anyone who can reach it from inventing identities — fine for a demo, not fine for anything real. Sequence numbers restart when the agent restarts and there's no durable spool, so a crash loses in-flight events with no trace in the log and potentially desyncs the chain position from the collector's view. The project pins to Go 1.26.6 specifically for a net/http CVE fix, which is a tight, easy-to-violate toolchain dependency for anyone vendoring or packaging this rather than building from source directly.