| Jun 17, 2024 | 
| May 15, 2024 MiscellaneousAudit deprecated.Metadata updated.References updated.
 | 
| Apr 1, 2024 | 
| Mar 18, 2024 Functional Update4.1.4.5 Ensure audit configuration files are 640 or more restrictive4.1.4.6 Ensure audit configuration files are owned by root4.1.4.7 Ensure audit configuration files belong to group root
 | 
| Feb 1, 2024 Functional Update1.1.1.2 Ensure mounting of squashfs filesystems is disabled1.1.1.3 Ensure mounting of udf filesystems is disabled1.1.3.1 Ensure separate partition exists for /var1.1.4.1 Ensure separate partition exists for /var/tmp1.1.5.1 Ensure separate partition exists for /var/log1.1.6.1 Ensure separate partition exists for /var/log/audit1.1.7.1 Ensure separate partition exists for /home1.6.1.4 Ensure all AppArmor Profiles are enforcing - complain1.6.1.4 Ensure all AppArmor Profiles are enforcing - loaded1.6.1.4 Ensure all AppArmor Profiles are enforcing - unconfined1.8.1 Ensure GNOME Display Manager is removed3.1.3 Ensure DCCP is disabled - blacklist3.1.3 Ensure DCCP is disabled - lsmod3.1.3 Ensure DCCP is disabled - modprobe3.1.4 Ensure SCTP is disabled - blacklist3.1.4 Ensure SCTP is disabled - lsmod3.1.4 Ensure SCTP is disabled - modprobe3.1.5 Ensure RDS is disabled - blacklist3.1.5 Ensure RDS is disabled - lsmod3.1.5 Ensure RDS is disabled - modprobe3.1.6 Ensure TIPC is disabled - blacklist3.1.6 Ensure TIPC is disabled - lsmod3.1.6 Ensure TIPC is disabled - modprobe4.1.1.1 Ensure auditd is installed4.1.1.2 Ensure auditd service is enabled and active - active4.1.1.2 Ensure auditd service is enabled and active - enabled4.1.1.3 Ensure auditing for processes that start prior to auditd is enabled4.1.1.4 Ensure audit_backlog_limit is sufficient4.1.2.1 Ensure audit log storage size is configured4.1.2.2 Ensure audit logs are not automatically deleted4.1.2.3 Ensure system is disabled when audit logs are full - 'action_mail_acct = root'4.1.2.3 Ensure system is disabled when audit logs are full - 'admin_space_left_action'4.1.2.3 Ensure system is disabled when audit logs are full - 'space_left_action = email'4.1.3.20 Ensure the audit configuration is immutable4.1.3.21 Ensure the running and on disk configuration is the same4.1.4.1 Ensure audit log files are mode 0640 or less permissive4.1.4.10 Ensure audit tools belong to group root4.1.4.2 Ensure only authorized users own audit log files4.1.4.3 Ensure only authorized groups are assigned ownership of audit log files4.1.4.3 Ensure only authorized groups are assigned ownership of audit log files - auditd.conf log_group4.1.4.4 Ensure the audit log directory is 0750 or more restrictive4.1.4.5 Ensure audit configuration files are 640 or more restrictive4.1.4.6 Ensure audit configuration files are owned by root4.1.4.7 Ensure audit configuration files belong to group root4.1.4.8 Ensure audit tools are 755 or more restrictive4.1.4.9 Ensure audit tools are owned by root5.2.12 Ensure SSH X11 forwarding is disabled5.2.16 Ensure SSH AllowTcpForwarding is disabled5.3.4 Ensure users must provide password for privilege escalation
MiscellaneousMetadata updated.Variables updated.
Added4.1.3.1 Ensure changes to system administration scope (sudoers) is collected4.1.3.10 Ensure successful file system mounts are collected4.1.3.11 Ensure session initiation information is collected4.1.3.12 Ensure login and logout events are collected4.1.3.13 Ensure file deletion events by users are collected4.1.3.14 Ensure events that modify the system's Mandatory Access Controls are collected4.1.3.15 Ensure successful and unsuccessful attempts to use the chcon command are recorded4.1.3.16 Ensure successful and unsuccessful attempts to use the setfacl command are recorded4.1.3.17 Ensure successful and unsuccessful attempts to use the chacl command are recorded4.1.3.18 Ensure successful and unsuccessful attempts to use the usermod command are recorded4.1.3.19 Ensure kernel module loading unloading and modification is collected4.1.3.2 Ensure actions as another user are always logged4.1.3.3 Ensure events that modify the sudo log file are collected4.1.3.4 Ensure events that modify date and time information are collected4.1.3.5 Ensure events that modify the system's network environment are collected4.1.3.6 Ensure use of privileged commands are collected4.1.3.7 Ensure unsuccessful file access attempts are collected4.1.3.8 Ensure events that modify user/group information are collected4.1.3.9 Ensure discretionary access control permission modification events are collected
Removed4.1.3.1 Ensure changes to system administration scope (sudoers) is collected - auditctl sudoers4.1.3.1 Ensure changes to system administration scope (sudoers) is collected - auditctl sudoers.d4.1.3.1 Ensure changes to system administration scope (sudoers) is collected - sudoers4.1.3.1 Ensure changes to system administration scope (sudoers) is collected - sudoers.d4.1.3.10 Ensure successful file system mounts are collected - 32-bit4.1.3.10 Ensure successful file system mounts are collected - 64-bit4.1.3.10 Ensure successful file system mounts are collected - auditctl (32-bit)4.1.3.10 Ensure successful file system mounts are collected - auditctl (64-bit)4.1.3.11 Ensure session initiation information is collected - auditctl btmp4.1.3.11 Ensure session initiation information is collected - auditctl utmp4.1.3.11 Ensure session initiation information is collected - auditctl wtmp4.1.3.11 Ensure session initiation information is collected - btmp4.1.3.11 Ensure session initiation information is collected - utmp4.1.3.11 Ensure session initiation information is collected - wtmp4.1.3.12 Ensure login and logout events are collected - /var/log/lastlog4.1.3.12 Ensure login and logout events are collected - /var/run/faillock4.1.3.12 Ensure login and logout events are collected - auditctl /var/log/lastlog4.1.3.12 Ensure login and logout events are collected - auditctl /var/run/faillock4.1.3.13 Ensure file deletion events by users are collected - 32-bit4.1.3.13 Ensure file deletion events by users are collected - 64-bit4.1.3.13 Ensure file deletion events by users are collected - auditctl (32-bit)4.1.3.13 Ensure file deletion events by users are collected - auditctl (64-bit)4.1.3.14 Ensure events that modify the system's Mandatory Access Controls are collected - /etc/apparmor.d/4.1.3.14 Ensure events that modify the system's Mandatory Access Controls are collected - /etc/apparmor/4.1.3.14 Ensure events that modify the system's Mandatory Access Controls are collected - auditctl /etc/apparmor.d/4.1.3.14 Ensure events that modify the system's Mandatory Access Controls are collected - auditctl /etc/apparmor/4.1.3.15 Ensure successful and unsuccessful attempts to use the chcon command are recorded - /etc/audit/rules.d/*.rules4.1.3.15 Ensure successful and unsuccessful attempts to use the chcon command are recorded - auditctl4.1.3.16 Ensure successful and unsuccessful attempts to use the setfacl command are recorded - /etc/audit/rules.d/*.rules4.1.3.16 Ensure successful and unsuccessful attempts to use the setfacl command are recorded - auditctl4.1.3.17 Ensure successful and unsuccessful attempts to use the chacl command are recorded - /etc/audit/rules.d/*.rules4.1.3.17 Ensure successful and unsuccessful attempts to use the chacl command are recorded - auditctl4.1.3.18 Ensure successful and unsuccessful attempts to use the usermod command are recorded - /etc/audit/rules.d/*.rules4.1.3.18 Ensure successful and unsuccessful attempts to use the usermod command are recorded - auditctl4.1.3.19 Ensure kernel module loading unloading and modification is collected - /usr/bin/kmod (64-bit)4.1.3.19 Ensure kernel module loading unloading and modification is collected - auditctl /usr/bin/kmod (64-bit)4.1.3.19 Ensure kernel module loading unloading and modification is collected - auditctl modules (64-bit)4.1.3.19 Ensure kernel module loading unloading and modification is collected - kmod symlinks4.1.3.19 Ensure kernel module loading unloading and modification is collected - kmod symlinks (64-bit)4.1.3.19 Ensure kernel module loading unloading and modification is collected - modules (64-bit)4.1.3.2 Ensure actions as another user are always logged - auditctl b324.1.3.2 Ensure actions as another user are always logged - auditctl b644.1.3.2 Ensure actions as another user are always logged - rules.d b324.1.3.2 Ensure actions as another user are always logged - rules.d b644.1.3.3 Ensure events that modify the sudo log file are collected - auditctl sudo log4.1.3.3 Ensure events that modify the sudo log file are collected - sudo log4.1.3.4 Ensure events that modify date and time information are collected - (32-bit)4.1.3.4 Ensure events that modify date and time information are collected - (64-bit)4.1.3.4 Ensure events that modify date and time information are collected - /etc/localtime4.1.3.4 Ensure events that modify date and time information are collected - audiitctl (32-bit)4.1.3.4 Ensure events that modify date and time information are collected - auditctl (64-bit)4.1.3.4 Ensure events that modify date and time information are collected - auditctl /etc/localtime4.1.3.5 Ensure events that modify the system's network environment are collected - /etc/hosts4.1.3.5 Ensure events that modify the system's network environment are collected - /etc/network/4.1.3.5 Ensure events that modify the system's network environment are collected - /etc/networks4.1.3.5 Ensure events that modify the system's network environment are collected - auditctl /etc/networks4.1.3.5 Ensure events that modify the system's network environment are collected - auditctl hosts4.1.3.5 Ensure events that modify the system's network environment are collected - auditctl issue4.1.3.5 Ensure events that modify the system's network environment are collected - auditctl issue.net4.1.3.5 Ensure events that modify the system's network environment are collected - auditctl network4.1.3.5 Ensure events that modify the system's network environment are collected - auditctl sethostname (32-bit)4.1.3.5 Ensure events that modify the system's network environment are collected - auditctl sethostname (64-bit)4.1.3.5 Ensure events that modify the system's network environment are collected - issue4.1.3.5 Ensure events that modify the system's network environment are collected - issue.net4.1.3.5 Ensure events that modify the system's network environment are collected - sethostname (32-bit)4.1.3.5 Ensure events that modify the system's network environment are collected - sethostname (64-bit)4.1.3.6 Ensure use of privileged commands are collected - /etc/audit/rules.d4.1.3.6 Ensure use of privileged commands are collected - auditctl4.1.3.7 Ensure unsuccessful file access attempts are collected - EACCES b324.1.3.7 Ensure unsuccessful file access attempts are collected - EACCES b644.1.3.7 Ensure unsuccessful file access attempts are collected - EPERM b324.1.3.7 Ensure unsuccessful file access attempts are collected - EPERM b644.1.3.7 Ensure unsuccessful file access attempts are collected - auditctl EACCES b324.1.3.7 Ensure unsuccessful file access attempts are collected - auditctl EACCES b644.1.3.7 Ensure unsuccessful file access attempts are collected - auditctl EPERM b324.1.3.7 Ensure unsuccessful file access attempts are collected - auditctl EPERM b644.1.3.8 Ensure events that modify user/group information are collected - /etc/group4.1.3.8 Ensure events that modify user/group information are collected - /etc/gshadow4.1.3.8 Ensure events that modify user/group information are collected - /etc/passwd4.1.3.8 Ensure events that modify user/group information are collected - /etc/security/opasswd4.1.3.8 Ensure events that modify user/group information are collected - /etc/shadow4.1.3.8 Ensure events that modify user/group information are collected - auditctl /etc/group4.1.3.8 Ensure events that modify user/group information are collected - auditctl /etc/gshadow4.1.3.8 Ensure events that modify user/group information are collected - auditctl /etc/passwd4.1.3.8 Ensure events that modify user/group information are collected - auditctl /etc/security/opasswd4.1.3.8 Ensure events that modify user/group information are collected - auditctl /etc/shadow4.1.3.9 Ensure discretionary access control permission modification events are collected - auditctl b64 chmod/fchmod/fchmodat4.1.3.9 Ensure discretionary access control permission modification events are collected - auditctl b64 chown/fchown/fchownat/lchown4.1.3.9 Ensure discretionary access control permission modification events are collected - auditctl b64 setxattr/lsetxattr/fsetxattr/removexattr4.1.3.9 Ensure discretionary access control permission modification events are collected - auditctl chmod/fchmod/fchmodat4.1.3.9 Ensure discretionary access control permission modification events are collected - auditctl chown/fchown/fchownat/lchown4.1.3.9 Ensure discretionary access control permission modification events are collected - auditctl setxattr/lsetxattr/fsetxattr/removexattr4.1.3.9 Ensure discretionary access control permission modification events are collected - b64 chmod/fchmod/fchmodat4.1.3.9 Ensure discretionary access control permission modification events are collected - b64 chown/fchown/fchownat/lchown4.1.3.9 Ensure discretionary access control permission modification events are collected - b64 setxattr/lsetxattr/fsetxattr/removexattr4.1.3.9 Ensure discretionary access control permission modification events are collected - chmod/fchmod/fchmodat4.1.3.9 Ensure discretionary access control permission modification events are collected - chown/fchown/fchownat/lchown4.1.3.9 Ensure discretionary access control permission modification events are collected - setxattr/lsetxattr/fsetxattr/removexattr
 | 
| Dec 27, 2023 Functional Update4.1.4.4 Ensure the audit log directory is 0750 or more restrictive
 | 
| Nov 17, 2023 Functional Update5.2.12 Ensure SSH X11 forwarding is disabled5.2.16 Ensure SSH AllowTcpForwarding is disabled
 | 
| Nov 1, 2023 | 
| Oct 24, 2023 Functional Update5.2.12 Ensure SSH X11 forwarding is disabled5.2.16 Ensure SSH AllowTcpForwarding is disabled
 | 
| Sep 19, 2023 Functional Update4.1.3.10 Ensure successful file system mounts are collected - 32-bit4.1.3.10 Ensure successful file system mounts are collected - 64-bit4.1.3.11 Ensure session initiation information is collected - auditctl btmp4.1.3.11 Ensure session initiation information is collected - auditctl wtmp4.1.3.11 Ensure session initiation information is collected - btmp4.1.3.11 Ensure session initiation information is collected - wtmp4.1.3.13 Ensure file deletion events by users are collected - 32-bit4.1.3.13 Ensure file deletion events by users are collected - 64-bit4.1.3.13 Ensure file deletion events by users are collected - auditctl (32-bit)4.1.3.13 Ensure file deletion events by users are collected - auditctl (64-bit)4.1.3.17 Ensure successful and unsuccessful attempts to use the chacl command are recorded - /etc/audit/rules.d/*.rules4.1.3.17 Ensure successful and unsuccessful attempts to use the chacl command are recorded - auditctl4.1.3.4 Ensure events that modify date and time information are collected - /etc/localtime4.1.3.4 Ensure events that modify date and time information are collected - auditctl /etc/localtime4.1.3.5 Ensure events that modify the system's network environment are collected - auditctl network4.1.3.5 Ensure events that modify the system's network environment are collected - sethostname (32-bit)4.1.3.5 Ensure events that modify the system's network environment are collected - sethostname (64-bit)4.1.3.9 Ensure discretionary access control permission modification events are collected - auditctl chmod/fchmod/fchmodat4.1.3.9 Ensure discretionary access control permission modification events are collected - auditctl chown/fchown/fchownat/lchown4.1.3.9 Ensure discretionary access control permission modification events are collected - auditctl setxattr/lsetxattr/fsetxattr/removexattr4.1.3.9 Ensure discretionary access control permission modification events are collected - chmod/fchmod/fchmodat4.1.3.9 Ensure discretionary access control permission modification events are collected - chown/fchown/fchownat/lchown4.1.3.9 Ensure discretionary access control permission modification events are collected - setxattr/lsetxattr/fsetxattr/removexattr4.1.4.3 Ensure only authorized groups are assigned ownership of audit log files
Added4.1.3.12 Ensure login and logout events are collected - /var/run/faillock4.1.3.12 Ensure login and logout events are collected - auditctl /var/run/faillock4.1.3.19 Ensure kernel module loading unloading and modification is collected - /usr/bin/kmod (64-bit)4.1.3.19 Ensure kernel module loading unloading and modification is collected - auditctl /usr/bin/kmod (64-bit)4.1.3.19 Ensure kernel module loading unloading and modification is collected - auditctl modules (64-bit)4.1.3.19 Ensure kernel module loading unloading and modification is collected - kmod symlinks4.1.3.19 Ensure kernel module loading unloading and modification is collected - kmod symlinks (64-bit)4.1.3.19 Ensure kernel module loading unloading and modification is collected - modules (64-bit)4.1.3.4 Ensure events that modify date and time information are collected - (32-bit)4.1.3.4 Ensure events that modify date and time information are collected - (64-bit)4.1.3.4 Ensure events that modify date and time information are collected - audiitctl (32-bit)4.1.3.4 Ensure events that modify date and time information are collected - auditctl (64-bit)4.1.3.5 Ensure events that modify the system's network environment are collected - /etc/network/4.1.3.5 Ensure events that modify the system's network environment are collected - /etc/networks4.1.3.5 Ensure events that modify the system's network environment are collected - auditctl /etc/networks4.1.3.7 Ensure unsuccessful file access attempts are collected - EACCES b324.1.3.7 Ensure unsuccessful file access attempts are collected - EACCES b644.1.3.7 Ensure unsuccessful file access attempts are collected - EPERM b324.1.3.7 Ensure unsuccessful file access attempts are collected - EPERM b644.1.3.7 Ensure unsuccessful file access attempts are collected - auditctl EACCES b324.1.3.7 Ensure unsuccessful file access attempts are collected - auditctl EACCES b644.1.3.7 Ensure unsuccessful file access attempts are collected - auditctl EPERM b324.1.3.7 Ensure unsuccessful file access attempts are collected - auditctl EPERM b644.1.3.9 Ensure discretionary access control permission modification events are collected - auditctl b64 chmod/fchmod/fchmodat4.1.3.9 Ensure discretionary access control permission modification events are collected - auditctl b64 chown/fchown/fchownat/lchown4.1.3.9 Ensure discretionary access control permission modification events are collected - auditctl b64 setxattr/lsetxattr/fsetxattr/removexattr4.1.3.9 Ensure discretionary access control permission modification events are collected - b64 chmod/fchmod/fchmodat4.1.3.9 Ensure discretionary access control permission modification events are collected - b64 chown/fchown/fchownat/lchown4.1.3.9 Ensure discretionary access control permission modification events are collected - b64 setxattr/lsetxattr/fsetxattr/removexattr4.1.4.3 Ensure only authorized groups are assigned ownership of audit log files - auditd.conf log_group
Removed4.1.3.12 Ensure login and logout events are collected - /var/log/faillog4.1.3.12 Ensure login and logout events are collected - /var/log/tallylog4.1.3.12 Ensure login and logout events are collected - auditctl /var/log/faillog4.1.3.12 Ensure login and logout events are collected - auditctl /var/log/tallylog4.1.3.19 Ensure kernel module loading unloading and modification is collected - auditctl init_module/delete_module (32-bit)4.1.3.19 Ensure kernel module loading unloading and modification is collected - auditctl init_module/delete_module (64-bit)4.1.3.19 Ensure kernel module loading unloading and modification is collected - auditctl insmod4.1.3.19 Ensure kernel module loading unloading and modification is collected - auditctl modprobe4.1.3.19 Ensure kernel module loading unloading and modification is collected - auditctl rmmod4.1.3.19 Ensure kernel module loading unloading and modification is collected - init_module/delete_module  (64-bit)4.1.3.19 Ensure kernel module loading unloading and modification is collected - init_module/delete_module (32-bit)4.1.3.19 Ensure kernel module loading unloading and modification is collected - insmod4.1.3.19 Ensure kernel module loading unloading and modification is collected - modprobe4.1.3.19 Ensure kernel module loading unloading and modification is collected - rmmod4.1.3.4 Ensure events that modify date and time information are collected - adjtimex (32-bit)4.1.3.4 Ensure events that modify date and time information are collected - adjtimex (64-bit)4.1.3.4 Ensure events that modify date and time information are collected - auditctl adjtimex (32-bit)4.1.3.4 Ensure events that modify date and time information are collected - auditctl adjtimex (64-bit)4.1.3.4 Ensure events that modify date and time information are collected - auditctl clock_settime (32-bit)4.1.3.4 Ensure events that modify date and time information are collected - auditctl clock_settime (64-bit)4.1.3.4 Ensure events that modify date and time information are collected - clock_settime (32-bit)4.1.3.4 Ensure events that modify date and time information are collected - clock_settime (64-bit)4.1.3.5 Ensure events that modify the system's network environment are collected - /etc/network4.1.3.6 Ensure use of privileged commands are collected4.1.3.7 Ensure unsuccessful file access attempts are collected - EACCES4.1.3.7 Ensure unsuccessful file access attempts are collected - EACCES (64-bit)4.1.3.7 Ensure unsuccessful file access attempts are collected - EPERM4.1.3.7 Ensure unsuccessful file access attempts are collected - EPERM (64-bit)4.1.3.7 Ensure unsuccessful file access attempts are collected - auditctl EACCES4.1.3.7 Ensure unsuccessful file access attempts are collected - auditctl EACCES (64-bit)4.1.3.7 Ensure unsuccessful file access attempts are collected - auditctl EPERM4.1.3.7 Ensure unsuccessful file access attempts are collected - auditctl EPERM (64-bit)4.1.3.9 Ensure discretionary access control permission modification events are collected - auditctl chmod/fchmod/fchmodat (64-bit)4.1.3.9 Ensure discretionary access control permission modification events are collected - auditctl chown/fchown/fchownat/lchown (64-bit)4.1.3.9 Ensure discretionary access control permission modification events are collected - auditctl xattr (64-bit)4.1.3.9 Ensure discretionary access control permission modification events are collected - chmod/fchmod/fchmodat (64-bit)4.1.3.9 Ensure discretionary access control permission modification events are collected - chown/fchown/fchownat/lchown (64-bit)4.1.3.9 Ensure discretionary access control permission modification events are collected - xattr (64-bit)
 |