finds.dev← search

// the find

trellix-enterprise/mysql-audit

★ 292 · C · NOASSERTION · updated Mar 2026

AUDIT Plugin for MySQL. See wiki and readme for description. If you find the plugin useful, please star us on GitHub. We love stars and it's a great way to show your feedback.

A MySQL audit logging plugin from Trellix (originally McAfee) that captures database activity, either standing alone or feeding into an external SIEM. It's aimed at DBAs and security teams who need audit trails on MySQL/MariaDB for compliance rather than developers doing app work.

Enterprise-backed and battle-tested with real production adoption (292 stars, 64 forks, still getting pushes); flexible deployment as standalone logging or as a feed into other monitoring tooling; supports both MySQL and MariaDB targets (separate .map files for each).

It works by hot-patching MySQL's binary at runtime (hot_patch.cc, plus an offset-extract.sh script to pull version-specific offsets) instead of using stable plugin hooks — that's inherently fragile and can silently break on a MySQL point release. The repo vendors entire copies of PCRE and udis86 rather than linking system libraries, so you inherit their bugs/CVEs until someone manually re-vendors a newer snapshot. The README itself has zero technical content — no build steps, no config example, no audit log format — everything is punted to an external wiki, so you can't evaluate or build this from the repo alone. No tests for the actual audit plugin logic (audit_handler.cc, audit_plugin.cc); the only test suites in the tree belong to the vendored pcre/udis86 dependencies.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →