SV-281116r1166300_rule
V-281116
SRG-OS-000326-GPOS-00126
RHEL-10-500300
CAT II
10
Configure RHEL 10 to generate audit records upon successful and unsuccessful attempts to use the "execve" system call.
Add or update the following file system rules to "/etc/audit/rules.d/audit.rules":
-a always,exit -F arch=b32 -S execve -C uid!=euid -F euid=0 -k execpriv
-a always,exit -F arch=b64 -S execve -C uid!=euid -F euid=0 -k execpriv
-a always,exit -F arch=b32 -S execve -C gid!=egid -F egid=0 -k execpriv
-a always,exit -F arch=b64 -S execve -C gid!=egid -F egid=0 -k execpriv
Restart the audit daemon with the following command for the changes to take effect:
$ sudo service auditd restart
Verify RHEL 10 is configured to audit the execution of the "execve" system call with the following command:
$ sudo auditctl -l | grep execve
-a always,exit -F arch=b32 -S execve -C uid!=euid -F euid=0 -F key=execpriv
-a always,exit -F arch=b64 -S execve -C uid!=euid -F euid=0 -F key=execpriv
-a always,exit -F arch=b32 -S execve -C gid!=egid -F egid=0 -F key=execpriv
-a always,exit -F arch=b64 -S execve -C gid!=egid -F egid=0 -F key=execpriv
If the command does not return all lines, or the lines are commented out, this is a finding.
V-281116
False
RHEL-10-500300
Verify RHEL 10 is configured to audit the execution of the "execve" system call with the following command:
$ sudo auditctl -l | grep execve
-a always,exit -F arch=b32 -S execve -C uid!=euid -F euid=0 -F key=execpriv
-a always,exit -F arch=b64 -S execve -C uid!=euid -F euid=0 -F key=execpriv
-a always,exit -F arch=b32 -S execve -C gid!=egid -F egid=0 -F key=execpriv
-a always,exit -F arch=b64 -S execve -C gid!=egid -F egid=0 -F key=execpriv
If the command does not return all lines, or the lines are commented out, this is a finding.
M
5733