Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -59,6 +59,7 @@ references:
stigid@ol8: OL08-00-030490
stigid@sle12: SLES-12-020460
stigid@sle15: SLES-15-030290
stigid@ubuntu2404: UBTU-24-900150

ocil_clause: 'the system is not configured to audit permission changes'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -59,6 +59,7 @@ references:
stigid@ol8: OL08-00-030480
stigid@sle12: SLES-12-020420
stigid@sle15: SLES-15-030250
stigid@ubuntu2404: UBTU-24-900140

{{{ complete_ocil_entry_audit_syscall(syscall="chown") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -57,6 +57,7 @@ references:
stigid@ol8: OL08-00-030490
stigid@sle12: SLES-12-020460
stigid@sle15: SLES-15-030290
stigid@ubuntu2404: UBTU-24-900150

{{{ complete_ocil_entry_audit_syscall(syscall="fchmod") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -56,6 +56,7 @@ references:
stigid@ol8: OL08-00-030490
stigid@sle12: SLES-12-020460
stigid@sle15: SLES-15-030290
stigid@ubuntu2404: UBTU-24-900150

{{{ complete_ocil_entry_audit_syscall(syscall="fchmodat") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -59,6 +59,7 @@ references:
stigid@ol8: OL08-00-030480
stigid@sle12: SLES-12-020420
stigid@sle15: SLES-15-030250
stigid@ubuntu2404: UBTU-24-900140

{{{ complete_ocil_entry_audit_syscall(syscall="fchown") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -56,6 +56,7 @@ references:
stigid@ol8: OL08-00-030480
stigid@sle12: SLES-12-020420
stigid@sle15: SLES-15-030250
stigid@ubuntu2404: UBTU-24-900140

{{{ complete_ocil_entry_audit_syscall(syscall="fchownat") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -74,6 +74,7 @@ references:
stigid@ol8: OL08-00-030200
stigid@sle12: SLES-12-020370
stigid@sle15: SLES-15-030190
stigid@ubuntu2404: UBTU-24-900130

{{{ complete_ocil_entry_audit_syscall(syscall="fremovexattr") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -68,6 +68,7 @@ references:
stigid@ol8: OL08-00-030200
stigid@sle12: SLES-12-020370
stigid@sle15: SLES-15-030190
stigid@ubuntu2404: UBTU-24-900130

{{{ complete_ocil_entry_audit_syscall(syscall="fsetxattr") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -60,6 +60,7 @@ references:
stigid@ol8: OL08-00-030480
stigid@sle12: SLES-12-020420
stigid@sle15: SLES-15-030250
stigid@ubuntu2404: UBTU-24-900140

{{{ complete_ocil_entry_audit_syscall(syscall="lchown") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -73,6 +73,7 @@ references:
stigid@ol8: OL08-00-030200
stigid@sle12: SLES-12-020370
stigid@sle15: SLES-15-030190
stigid@ubuntu2404: UBTU-24-900130

{{{ complete_ocil_entry_audit_syscall(syscall="lremovexattr") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -68,6 +68,7 @@ references:
stigid@ol8: OL08-00-030200
stigid@sle12: SLES-12-020370
stigid@sle15: SLES-15-030190
stigid@ubuntu2404: UBTU-24-900130

{{{ complete_ocil_entry_audit_syscall(syscall="lsetxattr") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -72,6 +72,7 @@ references:
stigid@ol8: OL08-00-030200
stigid@sle12: SLES-12-020370
stigid@sle15: SLES-15-030190
stigid@ubuntu2404: UBTU-24-900130

{{{ complete_ocil_entry_audit_syscall(syscall="removexattr") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -68,6 +68,7 @@ references:
stigid@ol8: OL08-00-030200
stigid@sle12: SLES-12-020370
stigid@sle15: SLES-15-030190
stigid@ubuntu2404: UBTU-24-900130

{{{ complete_ocil_entry_audit_syscall(syscall="setxattr") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -31,6 +31,7 @@ references:
stigid@ol8: OL08-00-030570
stigid@sle12: SLES-12-020620
stigid@sle15: SLES-15-030440
stigid@ubuntu2404: UBTU-24-900240

{{{ ocil_fix_srg_privileged_command("chacl", "/usr/bin/", "perm_mod") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -30,6 +30,7 @@ references:
stigid@ol8: OL08-00-030330
stigid@sle12: SLES-12-020610
stigid@sle15: SLES-15-030430
stigid@ubuntu2404: UBTU-24-900230

{{{ ocil_fix_srg_privileged_command("setfacl", "/usr/bin/", "perm_mod") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -47,6 +47,7 @@ references:
stigid@ol8: OL08-00-030260
stigid@sle12: SLES-12-020630
stigid@sle15: SLES-15-030450
stigid@ubuntu2404: UBTU-24-900210

{{{ ocil_fix_srg_privileged_command("chcon", "/usr/bin/", "perm_mod") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -52,6 +52,7 @@ references:
srg: SRG-OS-000037-GPOS-00015,SRG-OS-000042-GPOS-00020,SRG-OS-000062-GPOS-00031,SRG-OS-000392-GPOS-00172,SRG-OS-000462-GPOS-00206,SRG-OS-000471-GPOS-00215,SRG-OS-000466-GPOS-00210,SRG-OS-000467-GPOS-00211,SRG-OS-000468-GPOS-00212,SRG-APP-000495-CTR-001235,SRG-APP-000499-CTR-001255,SRG-APP-000501-CTR-001265,SRG-APP-000502-CTR-001270
stigid@ol7: OL07-00-030910
stigid@ol8: OL08-00-030361
stigid@ubuntu2404: UBTU-24-900540

{{{ complete_ocil_entry_audit_syscall(syscall="rename") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -49,6 +49,7 @@ references:
srg: SRG-OS-000037-GPOS-00015,SRG-OS-000042-GPOS-00020,SRG-OS-000062-GPOS-00031,SRG-OS-000392-GPOS-00172,SRG-OS-000462-GPOS-00206,SRG-OS-000471-GPOS-00215,SRG-OS-000466-GPOS-00210,SRG-OS-000467-GPOS-00211,SRG-OS-000468-GPOS-00212,SRG-APP-000495-CTR-001235,SRG-APP-000499-CTR-001255,SRG-APP-000501-CTR-001265,SRG-APP-000502-CTR-001270
stigid@ol7: OL07-00-030910
stigid@ol8: OL08-00-030361
stigid@ubuntu2404: UBTU-24-900540

{{{ complete_ocil_entry_audit_syscall(syscall="renameat") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -49,6 +49,7 @@ references:
srg: SRG-OS-000037-GPOS-00015,SRG-OS-000042-GPOS-00020,SRG-OS-000062-GPOS-00031,SRG-OS-000392-GPOS-00172,SRG-OS-000462-GPOS-00206,SRG-OS-000471-GPOS-00215,SRG-OS-000466-GPOS-00210,SRG-OS-000467-GPOS-00211,SRG-OS-000468-GPOS-00212,SRG-APP-000495-CTR-001235,SRG-APP-000499-CTR-001255,SRG-APP-000501-CTR-001265,SRG-APP-000502-CTR-001270
stigid@ol7: OL07-00-030910
stigid@ol8: OL08-00-030361
stigid@ubuntu2404: UBTU-24-900540

{{{ complete_ocil_entry_audit_syscall(syscall="rmdir") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -52,6 +52,7 @@ references:
srg: SRG-OS-000037-GPOS-00015,SRG-OS-000042-GPOS-00020,SRG-OS-000062-GPOS-00031,SRG-OS-000392-GPOS-00172,SRG-OS-000462-GPOS-00206,SRG-OS-000471-GPOS-00215,SRG-OS-000466-GPOS-00210,SRG-OS-000467-GPOS-00211,SRG-OS-000468-GPOS-00212,SRG-APP-000495-CTR-001235,SRG-APP-000499-CTR-001255,SRG-APP-000501-CTR-001265,SRG-APP-000502-CTR-001270
stigid@ol7: OL07-00-030910
stigid@ol8: OL08-00-030361
stigid@ubuntu2404: UBTU-24-900540

{{{ complete_ocil_entry_audit_syscall(syscall="unlink") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -49,6 +49,7 @@ references:
srg: SRG-OS-000037-GPOS-00015,SRG-OS-000042-GPOS-00020,SRG-OS-000062-GPOS-00031,SRG-OS-000392-GPOS-00172,SRG-OS-000462-GPOS-00206,SRG-OS-000471-GPOS-00215,SRG-OS-000466-GPOS-00210,SRG-OS-000467-GPOS-00211,SRG-OS-000468-GPOS-00212,SRG-APP-000495-CTR-001235,SRG-APP-000499-CTR-001255,SRG-APP-000501-CTR-001265,SRG-APP-000502-CTR-001270
stigid@ol7: OL07-00-030910
stigid@ol8: OL08-00-030361
stigid@ubuntu2404: UBTU-24-900540

{{{ complete_ocil_entry_audit_syscall(syscall="unlinkat") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -63,6 +63,7 @@ references:
stigid@ol8: OL08-00-030420
stigid@sle12: SLES-12-020490
stigid@sle15: SLES-15-030150
stigid@ubuntu2404: UBTU-24-900160

ocil: |-
{{{ ocil_audit_rules_unsuccessful_file_modification("creat", "access") | indent(4) }}}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -63,6 +63,7 @@ references:
stigid@ol8: OL08-00-030420
stigid@sle12: SLES-12-020490
stigid@sle15: SLES-15-030150
stigid@ubuntu2404: UBTU-24-900160

ocil: |-
{{{ ocil_audit_rules_unsuccessful_file_modification("ftruncate", "access") | indent(4) }}}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -67,6 +67,7 @@ references:
stigid@ol8: OL08-00-030420
stigid@sle12: SLES-12-020490
stigid@sle15: SLES-15-030150
stigid@ubuntu2404: UBTU-24-900160

ocil: |-
{{{ ocil_audit_rules_unsuccessful_file_modification("open", "access") | indent(4) }}}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -57,6 +57,7 @@ references:
stigid@ol8: OL08-00-030420
stigid@sle12: SLES-12-020490
stigid@sle15: SLES-15-030150
stigid@ubuntu2404: UBTU-24-900160

ocil: |-
{{{ ocil_audit_rules_unsuccessful_file_modification("open_by_handle_at", "access") | indent(4) }}}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -63,6 +63,7 @@ references:
stigid@ol8: OL08-00-030420
stigid@sle12: SLES-12-020490
stigid@sle15: SLES-15-030150
stigid@ubuntu2404: UBTU-24-900160

ocil: |-
{{{ ocil_audit_rules_unsuccessful_file_modification("openat", "access") | indent(4) }}}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -62,6 +62,7 @@ references:
stigid@ol8: OL08-00-030420
stigid@sle12: SLES-12-020490
stigid@sle15: SLES-15-030150
stigid@ubuntu2404: UBTU-24-900160

ocil: |-
{{{ ocil_audit_rules_unsuccessful_file_modification("truncate", "access") | indent(4) }}}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,7 @@ references:
stigid@ol8: OL08-00-030390
stigid@sle12: SLES-12-020730
stigid@sle15: SLES-15-030520
stigid@ubuntu2404: UBTU-24-900350

{{{ complete_ocil_entry_audit_syscall(syscall="delete_module") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -41,6 +41,7 @@ references:
stigid@ol8: OL08-00-030360
stigid@sle12: SLES-12-020740
stigid@sle15: SLES-15-030530
stigid@ubuntu2404: UBTU-24-900340

{{{ complete_ocil_entry_audit_syscall(syscall="finit_module") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -42,6 +42,7 @@ references:
stigid@ol8: OL08-00-030360
stigid@sle12: SLES-12-020740
stigid@sle15: SLES-15-030530
stigid@ubuntu2404: UBTU-24-900340

{{{ complete_ocil_entry_audit_syscall(syscall="init_module") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,7 @@ references:
nist@sle12: AU-3,AU-12(a),AU-12(c),MA-4(1)(a)
srg: SRG-OS-000037-GPOS-00015
stigid@sle12: SLES-12-020760
stigid@ubuntu2404: UBTU-24-900250

ocil_clause: 'there is no output'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,7 @@ references:
stigid@ol8: OL08-00-030600
stigid@sle12: SLES-12-020660
stigid@sle15: SLES-15-030480
stigid@ubuntu2404: UBTU-24-900260

ocil_clause: 'the command does not return a line, or the line is commented out'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@ severity: medium

references:
srg: SRG-OS-000064-GPOS-00033
stigid@ubuntu2404: UBTU-24-900220

ocil: |-
To verify that execution of the command is being audited, run the following command:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -46,6 +46,7 @@ references:
stigid@ol8: OL08-00-030250
stigid@sle12: SLES-12-020690
stigid@sle15: SLES-15-030120
stigid@ubuntu2404: UBTU-24-900300

{{{ ocil_fix_srg_privileged_command("chage") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -27,6 +27,7 @@ references:
nist: AU-3,AU-12(a),AU-12(c),MA-4(1)(a)
stigid@sle12: SLES-12-020280
stigid@sle15: SLES-15-030340
stigid@ubuntu2404: UBTU-24-900080

ocil_clause: '{{{ ocil_clause_audit() }}}'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -46,6 +46,7 @@ references:
stigid@ol8: OL08-00-030410
stigid@sle12: SLES-12-020580
stigid@sle15: SLES-15-030100
stigid@ubuntu2404: UBTU-24-900190

{{{ ocil_fix_srg_privileged_command("chsh") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -44,6 +44,7 @@ references:
stigid@ol8: OL08-00-030400
stigid@sle12: SLES-12-020710
stigid@sle15: SLES-15-030130
stigid@ubuntu2404: UBTU-24-900320

{{{ ocil_fix_srg_privileged_command("crontab") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,7 @@ severity: medium

references:
srg: SRG-OS-000477-GPOS-00222
stigid@ubuntu2404: UBTU-24-900750

ocil_clause: '{{{ ocil_clause_audit() }}}'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -46,6 +46,7 @@ references:
stigid@ol8: OL08-00-030370
stigid@sle12: SLES-12-020560
stigid@sle15: SLES-15-030080
stigid@ubuntu2404: UBTU-24-900290

{{{ ocil_fix_srg_privileged_command("gpasswd") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -33,6 +33,7 @@ references:
stigid@ol8: OL08-00-030580
stigid@sle12: SLES-12-020360
stigid@sle15: SLES-15-030410
stigid@ubuntu2404: UBTU-24-900740

{{{ ocil_fix_srg_privileged_command("kmod") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -44,6 +44,7 @@ references:
nist: AU-12(a),AU-12.1(ii),AU-3,AU-3.1,AU-12(c),AU-12.1(iv),MA-4(1)(a)
srg: SRG-OS-000037-GPOS-00015,SRG-OS-000062-GPOS-00031,SRG-OS-000392-GPOS-00172,SRG-OS-000462-GPOS-00206,SRG-OS-000471-GPOS-00215
stigid@sle15: SLES-15-030400
stigid@ubuntu2404: UBTU-24-900730

ocil_clause: '{{{ ocil_clause_audit() }}}'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -32,6 +32,7 @@ references:
stigid@ol7: OL07-00-030740
stigid@ol8: OL08-00-030300
stigid@sle12: SLES-12-020290
stigid@ubuntu2404: UBTU-24-900090

{{{ ocil_fix_srg_privileged_command("mount") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -46,6 +46,7 @@ references:
stigid@ol8: OL08-00-030350
stigid@sle12: SLES-12-020570
stigid@sle15: SLES-15-030090
stigid@ubuntu2404: UBTU-24-900200

{{{ ocil_fix_srg_privileged_command("newgrp") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -51,6 +51,7 @@ references:
stigid@ol8: OL08-00-030340
stigid@sle12: SLES-12-020720
stigid@sle15: SLES-15-030510
stigid@ubuntu2404: UBTU-24-900330

{{% if product not in ["sle12", "sle15", "slmicro5", "slmicro6"] %}}
{{{ ocil_fix_srg_privileged_command("pam_timestamp_check", "/usr/sbin/") }}}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -46,6 +46,7 @@ references:
stigid@ol8: OL08-00-030290
stigid@sle12: SLES-12-020550
stigid@sle15: SLES-15-030070
stigid@ubuntu2404: UBTU-24-900270

{{{ ocil_fix_srg_privileged_command("passwd") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -32,6 +32,7 @@ references:
stigid@ol8: OL08-00-030280
stigid@sle12: SLES-12-020310
stigid@sle15: SLES-15-030370
stigid@ubuntu2404: UBTU-24-900110

{{{ ocil_fix_srg_privileged_command("ssh-agent") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -56,6 +56,7 @@ references:
stigid@ol8: OL08-00-030320
stigid@sle12: SLES-12-020320
stigid@sle15: SLES-15-030060
stigid@ubuntu2404: UBTU-24-900120

{{{ ocil_fix_srg_privileged_command("ssh-keysign", ssh_keysign_path) }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -45,6 +45,7 @@ references:
stigid@ol8: OL08-00-030190
stigid@sle12: SLES-12-020250
stigid@sle15: SLES-15-030550
stigid@ubuntu2404: UBTU-24-900070

{{{ ocil_fix_srg_privileged_command("su") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -45,6 +45,7 @@ references:
stigid@ol8: OL08-00-030550
stigid@sle12: SLES-12-020260
stigid@sle15: SLES-15-030560
stigid@ubuntu2404: UBTU-24-900170

{{{ ocil_fix_srg_privileged_command("sudo") }}}
template:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -42,6 +42,7 @@ references:
nist@sle15: AU-3,AU-3.1,AU-12(a),AU-12.1(ii),AU-12.1(iv)
srg: SRG-OS-000037-GPOS-00015,SRG-OS-000042-GPOS-00020,SRG-OS-000062-GPOS-00031,SRG-OS-000392-GPOS-00172,SRG-OS-000462-GPOS-00206,SRG-OS-000471-GPOS-00215,SRG-APP-000495-CTR-001235,SRG-OS-000755-GPOS-00220
stigid@sle15: SLES-15-030330
stigid@ubuntu2404: UBTU-24-900180

{{{ ocil_fix_srg_privileged_command("sudoedit") }}}

Expand Down
Loading
Loading