Linux Audit Subsystem Disabled or SELinux Set Permissive - T1562.012
This rule monitors system logs for attempts to disable or stop the Linux Audit daemon (auditd) or modify its configuration via auditctl or system management commands (systemctl, service). Disabling the audit system is a common technique used by adversaries to hide malicious activity from security monitoring.
Microsoft Sentinel (KQL)

