Homebrew Security Alerts with Dtrace by Tim Elniski BSDCan 2023 @BsdcanOrg
Homebrew Security Alerts with Dtrace by Tim Elniski BSDCan 2023  @BsdcanOrg
Uploaded August 2023 | Updated September 2026, 1 hour ago
Homebrew Security Alerts with Dtrace by Tim Elniski

This talk will discuss simple in-base tools that a regular sysadmin can use to help respond to malware and intrusions on a freebsd host or jail. This will mostly revolve around building dtrace programs to alert on system behaviours that could be suspicious.

The talk will summarize basic defense methodology, ie firewalling, hardening and patching, and discuss how behavior monitoring can be an extra useful step with certain caveats. It will include a brief overview of the MITRE framework, why it helps, and a quick lament over the total lack of BSD related support.

Finally the majority of the talk will discuss the methodology of building attack scenarios and corresponding alerts using dtrace.

This grew out of dissatisfaction with large scale distributed monitoring systems, I wanted something that worked at home just on the laptop.
Homebrew Security Alerts with Dtrace by Tim Elniski BSDCan 2023User Friendly bhyve   Michael DexterOpening SessionSmartixOS and FreeBSD: Extending the Bootloader with a theming system By: GhislainWhy fsync() on OpenZFS cant fail, and what happens when it does By: Rob NorrisAli Mashtizadeh: Why Did My Application Crash   BSDCan 2018Modern BSD Computing for Fun on a VAX! Trying to use a VAX in todays world by Jeff ArmstrongBSDCan Saturday 2025-06-14:1160How to get started hacking NetBSD By: Taylor CampbellPerformance Analysis of DTrace on FreeBSD and eBPF on Linux By:Mateusz PiotrowskiPostgreSQL on FreeBSD: Thomas MunroBSDCan Saturday 2026-06-20: 1110
BSDCan |

Homebrew Security Alerts with Dtrace by Tim Elniski BSDCan 2023

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER