SV-281163r1166441_rule
V-281163
SRG-OS-000037-GPOS-00015
RHEL-10-500780
CAT II
10
Configure RHEL 10 to generate audit records upon successful and unsuccessful attempts to use the "chmod", "fchmod", "fchmodat", and "fchmodat2" syscalls.
Add or update the following rules in "/etc/audit/rules.d/audit.rules":
-a always,exit -F arch=b32 -S chmod,fchmod,fchmodat,fchmodat2 -F auid>=1000 -F auid!=unset -k perm_mod
-a always,exit -F arch=b64 -S chmod,fchmod,fchmodat,fchmodat2 -F auid>=1000 -F auid!=unset -k perm_mod
Restart the audit daemon with the following command for the changes to take effect:
$ sudo service auditd restart
Verify RHEL 10 is configured to audit the execution of the "chmod", "fchmod", "fchmodat", and "fchmodat2" syscalls with the following command:
$ sudo auditctl -l | grep chmod
-a always,exit -F arch=b32 -S chmod,fchmod,fchmodat,fchmodat2 -F auid>=1000 -F auid!=unset -k perm_mod
-a always,exit -F arch=b64 -S chmod,fchmod,fchmodat,fchmodat2 -F auid>=1000 -F auid!=unset -k perm_mod
If both the "b32" and "b64" audit rules are not defined for the "chmod", "fchmod", "fchmodat", and "fchmodat2" syscalls, this is a finding.
V-281163
False
RHEL-10-500780
Verify RHEL 10 is configured to audit the execution of the "chmod", "fchmod", "fchmodat", and "fchmodat2" syscalls with the following command:
$ sudo auditctl -l | grep chmod
-a always,exit -F arch=b32 -S chmod,fchmod,fchmodat,fchmodat2 -F auid>=1000 -F auid!=unset -k perm_mod
-a always,exit -F arch=b64 -S chmod,fchmod,fchmodat,fchmodat2 -F auid>=1000 -F auid!=unset -k perm_mod
If both the "b32" and "b64" audit rules are not defined for the "chmod", "fchmod", "fchmodat", and "fchmodat2" syscalls, this is a finding.
M
5733