Glossary
auditd (Linux Audit Daemon)
auditd is the userspace daemon of the Linux Audit framework, writing kernel audit events such as syscalls, executions and logins to audit.log.
auditd is the userspace component of the Linux Audit framework. The kernel generates audit records for events matched by rules (system calls, file watches, authentication, SELinux decisions) and auditd writes them to /var/log/audit/audit.log. Rules are usually kept in /etc/audit/rules.d/*.rules and compiled into /etc/audit/audit.rules by augenrules; daemon settings live in /etc/audit/auditd.conf. It is installed and enabled by default on the RHEL family, while on Debian and Ubuntu it is an optional package.
A valuable field is auid, the login UID, which is set at login and preserved across su and sudo, so actions can be tied back to the original user. Records are grouped by an event ID in msg=audit(<epoch>.<ms>:<serial>), and a single event can span SYSCALL, EXECVE, CWD and PATH records.
ausearch -if /mnt/evidence/var/log/audit/audit.log -m EXECVE -i
ausearch -if /mnt/evidence/var/log/audit/audit.log -k exec_watch -i
aureport -if /mnt/evidence/var/log/audit/audit.log --login --summary
Audit logs only contain what the rules asked for; with a default rule set, command execution is often not recorded at all. Attackers with root can stop the daemon or delete rules, which itself generates CONFIG_CHANGE and DAEMON records worth looking for. See Linux log forensics.