// the find
microsoft/OmniLog
System Audit Architecture with High Event Coverage and Synchronous Log Availability
OmniLog is Microsoft Research's prototype for system audit collection, released alongside a USENIX Security 2023 paper on high event coverage with synchronous log availability. The repo has separate arm/ and x86/ prototypes, and the arm/ side is mostly a vendored copy of imx-atf (the i.MX fork of Trusted Firmware-A) with i.MX build scripts. It is for security researchers designing audit infrastructure below the OS, not for application logging.
- Collection sits in firmware, below the OS. The arm/ prototype is built on TF-A, which runs at EL3, and a kernel-level audit hook is only as trustworthy as the kernel it lives in. The README's focus on synchronous log availability points at the same goal, though the code is where I'd check the mechanism.
- Keeping arm/ and x86/ as separate prototypes instead of forcing one abstraction is the right call for research code, since audit hook points are architecture-specific.
- It is tied to a peer-reviewed paper, and the README says so up front, so the claims have a published place to be checked against.
- The CodeQL workflow is wired into .github/workflows, which most research drops don't bother with.
- The README is one page that defers every technical detail to the paper. Nothing in the repo says which events are hooked, what the coverage numbers are, or what the overhead costs.
- The last push was 27 November 2024, almost two years ago, with 19 stars and no forks. This is a paper artifact, not a maintained project, and nothing here shows it still builds against current TF-A.
- Most of the arm/ tree is upstream imx-atf with its own docs, CI, and build system. The README doesn't say which imx-atf version it forked from, so finding OmniLog's own changes means diffing the whole tree.
- The pipeline scripts target i.MX boards, and the README gives no path to running it in QEMU or a VM, so a reader without the hardware is stuck.