SV-248722r1208714_rule
V-248722
SRG-OS-000326-GPOS-00126
OL08-00-030000
CAT II
10
Configure OL 8 to audit the execution of the "execve" system call.
Add or update the following file system rules to "/etc/audit/rules.d/audit.rules":
-a always,exit -F arch=b32 -S execve -C uid!=euid -F euid=0 key=execpriv
-a always,exit -F arch=b64 -S execve -C uid!=euid -F euid=0 key=execpriv
-a always,exit -F arch=b32 -S execve -C gid!=egid -F egid=0 key=execpriv
-a always,exit -F arch=b64 -S execve -C gid!=egid -F egid=0 key=execpriv
The audit daemon must be restarted for the changes to take effect. To restart the audit daemon, run the following command:
$ sudo service auditd restart
Verify OL 8 audits the execution of privileged functions.
Check if OL 8 is configured to audit the execution of the "execve" system call by running the following command:
$ sudo grep execve /etc/audit/audit.rules
-a always,exit -F arch=b32 -S execve -C uid!=euid -F euid=0 key=execpriv
-a always,exit -F arch=b64 -S execve -C uid!=euid -F euid=0 key=execpriv
-a always,exit -F arch=b32 -S execve -C gid!=egid -F egid=0 key=execpriv
-a always,exit -F arch=b64 -S execve -C gid!=egid -F egid=0 key=execpriv
If the command does not return all lines or the lines are commented out, this is a finding.
V-248722
False
OL08-00-030000
Verify OL 8 audits the execution of privileged functions.
Check if OL 8 is configured to audit the execution of the "execve" system call by running the following command:
$ sudo grep execve /etc/audit/audit.rules
-a always,exit -F arch=b32 -S execve -C uid!=euid -F euid=0 key=execpriv
-a always,exit -F arch=b64 -S execve -C uid!=euid -F euid=0 key=execpriv
-a always,exit -F arch=b32 -S execve -C gid!=egid -F egid=0 key=execpriv
-a always,exit -F arch=b64 -S execve -C gid!=egid -F egid=0 key=execpriv
If the command does not return all lines or the lines are commented out, this is a finding.
M
5416