SV-269483r1134836_rule
V-269483
SRG-OS-000037-GPOS-00015
ALMA-09-048970
CAT II
10
Configure AlmaLinux OS 9 to generate audit records upon successful/unsuccessful attempts to use the "rename", "unlink", "rmdir", "renameat", and "unlinkat" syscalls.
Add the following to the "/etc/audit/rules.d/audit.rules" file:
-a always,exit -F arch=b64 -S rename,unlink,rmdir,unlinkat,renameat -F auid>=1000 -F auid!=unset -F key=delete
-a always,exit -F arch=b32 -S rename,unlink,rmdir,unlinkat,renameat -F auid>=1000 -F auid!=unset -F key=delete
Merge the rules into /etc/audit/audit.rules:
$ augenrules --load
Verify that AlmaLinux OS 9 is configured to audit the execution of the "rename", "unlink", "rmdir", "renameat", and "unlinkat" system calls with the following command:
$ auditctl -l | grep rename
-a always,exit -F arch=b32 -S unlink,rename,rmdir,unlinkat,renameat -F auid>=1000 -F auid!=unset -F key=delete
-a always,exit -F arch=b64 -S rename,rmdir,unlink,unlinkat,renameat -F auid>=1000 -F auid!=unset -F key=delete
If both the "b32" and "b64" audit rules are not defined for the "rename", "unlink", "rmdir", "renameat", and "unlinkat" system calls, or any of the lines returned are commented out, this is a finding.
V-269483
False
ALMA-09-048970
Verify that AlmaLinux OS 9 is configured to audit the execution of the "rename", "unlink", "rmdir", "renameat", and "unlinkat" system calls with the following command:
$ auditctl -l | grep rename
-a always,exit -F arch=b32 -S unlink,rename,rmdir,unlinkat,renameat -F auid>=1000 -F auid!=unset -F key=delete
-a always,exit -F arch=b64 -S rename,rmdir,unlink,unlinkat,renameat -F auid>=1000 -F auid!=unset -F key=delete
If both the "b32" and "b64" audit rules are not defined for the "rename", "unlink", "rmdir", "renameat", and "unlinkat" system calls, or any of the lines returned are commented out, this is a finding.
M
5664