Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add CIS policy "Ensure XD/NX support is enabled" back for SCA #7314

Closed
vikman90 opened this issue Jan 29, 2021 · 0 comments · Fixed by #7316
Closed

Add CIS policy "Ensure XD/NX support is enabled" back for SCA #7314

vikman90 opened this issue Jan 29, 2021 · 0 comments · Fixed by #7316
Assignees
Labels
feed module/sca Security Configuration Assessment module type/enhancement New feature or request

Comments

@vikman90
Copy link
Member

Issue #6997 stated that SCA was consuming more memory than acceptable when running command that produced a very large output. So we temporarily removed the policy involved "Ensure XD/NX support is enabled" (wazuh/wazuh-ruleset#822).

After issue #3340 (PR #7307) is closed, shell commands will be allowed in SCA via sh -c "...". Then we will add that policy back, using shell commands.

For instance:

- 'sh -c "c:journalctl | grep \"protection: active\"" -> r:^kernel:\s+NX \(Execute Disable\) protection: active'
@vikman90 vikman90 added type/enhancement New feature or request module/sca Security Configuration Assessment module labels Jan 29, 2021
@vikman90 vikman90 self-assigned this Jan 29, 2021
@vikman90 vikman90 added the feed label Jan 29, 2021
@vikman90 vikman90 linked a pull request Jan 29, 2021 that will close this issue
3 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
feed module/sca Security Configuration Assessment module type/enhancement New feature or request
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant