Skip to content
BSD syscall#359

svc · unix #359

auditctl

Opens or rotates the kernel audit trail file used by auditd.

Prototype

int auditctl(char *path);

Returns: int

Arguments

NameTypeDirDescription
pathchar-

Version history

XNU tagmacOS#
xnu-1456.1.26macOS 10.6 Snow Leopard359
xnu-1699.24.8macOS 10.7 Lion359
xnu-2050.18.24macOS 10.8 Mountain Lion359
xnu-2422.115.4macOS 10.9 Mavericks359
xnu-2782.40.9macOS 10.10 Yosemite359
xnu-3247.1.106macOS 10.11 El Capitan359
xnu-3789.1.32macOS 10.12 Sierra359
xnu-4570.1.46macOS 10.13 High Sierra359
xnu-4903.221.2macOS 10.14 Mojave359
xnu-6153.11.26macOS 10.15 Catalina359
xnu-7195.50.7.100.1macOS 11.0 Big Sur359
xnu-8019.41.5macOS 12.0 Monterey359
xnu-8792.41.9macOS 13.0 Ventura359
xnu-10002.1.13macOS 14.0 Sonoma359
xnu-11215.1.10macOS 15.0 Sequoia359
xnu-11417.101.15macOS 15.4 Sequoia359
xnu-12377.1.9macOS 26.0 Tahoe359
xnu-10002.41.9359
xnu-10002.61.3359
xnu-10002.81.5359
xnu-10063.101.15359
xnu-10063.121.3359
xnu-10063.141.1359
xnu-11215.41.3359
xnu-11215.61.5359
xnu-11215.81.4359
xnu-11417.121.6359
xnu-11417.140.69359
xnu-12377.101.15359
xnu-12377.41.6359
xnu-12377.61.12359
xnu-12377.81.4359
xnu-1486.2.11359
xnu-1504.15.3359
xnu-1504.3.12359
xnu-1504.7.4359
xnu-1504.9.17359
xnu-1504.9.26359
xnu-1504.9.37359
xnu-1699.22.73359
xnu-1699.22.81359
xnu-1699.24.23359
xnu-1699.26.8359
xnu-1699.32.7359
xnu-2050.22.13359
xnu-2050.24.15359
xnu-2050.48.11359
xnu-2050.7.9359
xnu-2050.9.2359
xnu-2422.1.72359
xnu-2422.100.13359
xnu-2422.110.17359
xnu-2422.90.20359
xnu-2782.1.97359
xnu-2782.10.72359
xnu-2782.20.48359
xnu-2782.30.5359
xnu-3247.10.11359
xnu-3248.20.55359
xnu-3248.30.4359
xnu-3248.40.184359
xnu-3248.50.21359
xnu-3248.60.10359
xnu-3789.21.4359
xnu-3789.31.2359
xnu-3789.41.3359
xnu-3789.51.2359
xnu-3789.60.24359
xnu-3789.70.16359
xnu-4570.20.62359
xnu-4570.31.3359
xnu-4570.41.2359
xnu-4570.51.1359
xnu-4570.61.1359
xnu-4570.71.2359
xnu-4903.231.4359
xnu-4903.241.1359
xnu-4903.270.47359
xnu-6153.101.6359
xnu-6153.121.1359
xnu-6153.141.1359
xnu-6153.41.3359
xnu-6153.61.1359
xnu-6153.81.5359
xnu-7195.101.1359
xnu-7195.121.3359
xnu-7195.141.2359
xnu-7195.60.75359
xnu-7195.81.3359
xnu-8019.61.5359
xnu-8019.80.24359
xnu-8020.101.4359
xnu-8020.121.3359
xnu-8020.140.41359
xnu-8792.61.2359
xnu-8792.81.2359
xnu-8796.101.5359
xnu-8796.121.2359
xnu-8796.141.3359

Notes

auditctl(2) takes a path and tells the kernel to start writing BSM records to that file, closing whatever trail was previously active. Passing NULL or an empty path stops auditing entirely. It is the mechanism behind audit(8) -s / -n and is restricted by the audit_control privilege; on modern macOS it is only meaningful when auditd is running.

Detection

Generates AUE_AUDITCTL. Defenders should treat any auditctl(NULL) from a non-auditd process as a high-confidence anti-forensics signal, and watch for trail rotation to paths outside /var/audit/.

Related APIs

auditauditonsetauidendpoint_security