What problem does it solve?
Standard audit logging controls fail to protect against tampering by privileged attackers or insiders, and legacy compliance frameworks (NIST 800-53, ISO 27001, SOC 2) do not require the integrity controls needed to make audit trails reliable evidence in mid-2026 threat environments.
Core Features & Use Cases
- Tamper-Evident Hash Chaining: Verifies log continuity on read to detect history rewrites.
- Off-Host Signing: Uses keys stored separate from the log-writing host to prevent signature forgery.
- Compliance WORM & Legal Hold: Enforces immutable storage that even privileged users cannot bypass, with legal holds that block retention purges.
- Writer/Custodian Separation: Splits log writing and deletion rights to prevent single-identity trail erasure.
- Honeytoken Deception: Seeds canary tokens on high-value surfaces to detect unauthorized log access.
Use Case: Security teams use this skill to assess whether their audit trails can withstand insider or privileged attacker tampering for regulatory compliance and incident response.
Quick Start
Use the audit-log-integrity skill to evaluate your organization's audit logging controls for resistance to privileged attacker tampering and compliance with mid-2026 threat requirements.