A Linux Auditd rules configuration mapped to MITRE ATT&CK Framework
However this rule set can be ideal for forensics or real-time detection, it can generates a lot of logs. So please ensure you have enough available space (or configure log rotation) and sufficient hardware ressources.