Overview
Syllabus
Intro
Today's Agenda
Runtime Audit Hooks (PED 578)
Python Security Engineer Checklist
Listening to audit hooks
What events should you expect?
What to do with an event?
Creating audit events
Why would you hook io.open_code()?
What else do you need to do?
Integrating with Windows
Windows Event Log features
Code Signing
Windows Defender Application Control
Integrating with Linux
Prerequisites
DTrace / System Tap instrumentation
io.open code() on Linux
Extended file attributes
Securing xattr
Open issues and exploits
Summary
Resources
Taught by
EuroPython Conference