You can use auditctl.
# sudo apt-get install auditd
Gives a conclusion, for example
type = UNKNOWN [1327] msg = audit (1459766547.822: 130): proctitle = 2F7573722F7362696E2F61706163686532002D6B007374617274 type = PATH msg = audit (1459766547.822: 130): item = 0 name = "/ path / to15 / 1661 00 mode = 0100444 ouid = 33 ogid = 33 rdev = 00: 00 nametype = NORMAL type = CWD msg = audit (1459766547.822: 130): cwd = "/" type = SYSCALL msg = audit (1459766547.822: 130): arch = c000003e syscall = 2 success = yes exit = 41 a0 = 7f3c23034cd0 a1 = 80,000 a2 = 1b6 a3 = 8 items = 1 ppid = 24452 pid = 6797 auid = 42949672 95 uid = 33 gid = 33 euid = 33 suid = 33 fsuid = 33 egid = 33 sgid = 33 fsgid = 33 tty = (none) ses = 4294967295 comm = "apache2" exe = "/ usr / sbin / apache2" key = "hosts file"
source share