SV-268226r1038378_rule
V-268226
SRG-APP-000343-NDM-000289
HYCU-ND-000080
CAT II
10
Configure HYCU to audit the execution of the "execve" system call.
Add or update the following file system rules to "/etc/audit/rules.d/audit.rules":
-a always,exit -F arch=b32 -S execve -C uid!=euid -F euid=0 -k execpriv
-a always,exit -F arch=b64 -S execve -C uid!=euid -F euid=0 -k execpriv
-a always,exit -F arch=b32 -S execve -C gid!=egid -F egid=0 -k execpriv
-a always,exit -F arch=b64 -S execve -C gid!=egid -F egid=0 -k execpriv
Reboot the appliance to take effect.
Check the contents of the "/var/log/audit/audit.log" file.
HYCU also maintains Event (Audit) information in the HYCU Web UI Events menu.
Verify the audit log contains records showing when the execution of privileged functions occurred.
If the audit log is not configured or does not have the required contents, this is a finding.
V-268226
False
HYCU-ND-000080
Check the contents of the "/var/log/audit/audit.log" file.
HYCU also maintains Event (Audit) information in the HYCU Web UI Events menu.
Verify the audit log contains records showing when the execution of privileged functions occurred.
If the audit log is not configured or does not have the required contents, this is a finding.
M
5660