|
|
7629ac |
diff --git a/linux_os/guide/system/auditing/auditd_configure_rules/audit_rules_etc_group_open.rule b/linux_os/guide/system/auditing/auditd_configure_rules/audit_rules_etc_group_open.rule
|
|
|
7629ac |
new file mode 100644
|
|
|
7629ac |
index 0000000000..c69567f1c7
|
|
|
7629ac |
--- /dev/null
|
|
|
7629ac |
+++ b/linux_os/guide/system/auditing/auditd_configure_rules/audit_rules_etc_group_open.rule
|
|
|
7629ac |
@@ -0,0 +1,36 @@
|
|
|
7629ac |
+documentation_complete: true
|
|
|
7629ac |
+
|
|
|
7629ac |
+prodtype: rhel7,fedora
|
|
|
7629ac |
+
|
|
|
7629ac |
+title: 'Record Events that Modify User/Group Information via open syscall - /etc/group'
|
|
|
7629ac |
+
|
|
|
7629ac |
+description: |-
|
|
|
7629ac |
+ The audit system should collect write events to /etc/group file for all users and root.
|
|
|
7629ac |
+ If the <tt>auditd</tt> daemon is configured
|
|
|
7629ac |
+ to use the <tt>augenrules</tt> program to read audit rules during daemon
|
|
|
7629ac |
+ startup (the default), add the following lines to a file with suffix
|
|
|
7629ac |
+ <tt>.rules</tt> in the directory <tt>/etc/audit/rules.d</tt>:
|
|
|
7629ac |
+ -a always,exit -F arch=b32 -S open -F a2&03 -F path=/etc/group -F auid>=1000 -F auid!=unset -F key=group-modify
|
|
|
7629ac |
+ If the <tt>auditd</tt> daemon is configured to use the <tt>auditctl</tt>
|
|
|
7629ac |
+ utility to read audit rules during daemon startup, add the following lines to
|
|
|
7629ac |
+ <tt>/etc/audit/audit.rules</tt> file:
|
|
|
7629ac |
+ -a always,exit -F arch=b64 -S open -F a2&03 -F path=/etc/group -F auid>=1000 -F auid!=unset -F key=group-modify
|
|
|
7629ac |
+
|
|
|
7629ac |
+rationale: |-
|
|
|
7629ac |
+ Creation of groups through direct edition of /etc/group could be an indicator of malicious activity on a system.
|
|
|
7629ac |
+ Auditing these events could serve as evidence of potential system compromise.
|
|
|
7629ac |
+
|
|
|
7629ac |
+severity: medium
|
|
|
7629ac |
+
|
|
|
7629ac |
+references:
|
|
|
7629ac |
+ ospp@rhel7: FAU_GEN.1.1.c
|
|
|
7629ac |
+
|
|
|
7629ac |
+{{{ complete_ocil_entry_audit_syscall(syscall="open") }}}
|
|
|
7629ac |
+
|
|
|
7629ac |
+warnings:
|
|
|
7629ac |
+ - general: |-
|
|
|
7629ac |
+ Note that these rules can be configured in a
|
|
|
7629ac |
+ number of ways while still achieving the desired effect. Here the system calls
|
|
|
7629ac |
+ have been placed independent of other system calls. Grouping system calls related
|
|
|
7629ac |
+ to the same event is more efficient. See the following example:
|
|
|
7629ac |
+ -a always,exit -F arch=b32 -S open,openat,open_by_handle_at -F a2&03 -F path=/etc/group -F auid>=1000 -F auid!=unset -F key=group-modify
|
|
|
7629ac |
diff --git a/linux_os/guide/system/auditing/auditd_configure_rules/audit_rules_etc_group_open_by_handle_at.rule b/linux_os/guide/system/auditing/auditd_configure_rules/audit_rules_etc_group_open_by_handle_at.rule
|
|
|
7629ac |
new file mode 100644
|
|
|
7629ac |
index 0000000000..c33354b287
|
|
|
7629ac |
--- /dev/null
|
|
|
7629ac |
+++ b/linux_os/guide/system/auditing/auditd_configure_rules/audit_rules_etc_group_open_by_handle_at.rule
|
|
|
7629ac |
@@ -0,0 +1,36 @@
|
|
|
7629ac |
+documentation_complete: true
|
|
|
7629ac |
+
|
|
|
7629ac |
+prodtype: rhel7,fedora
|
|
|
7629ac |
+
|
|
|
7629ac |
+title: 'Record Events that Modify User/Group Information via open_by_handle_at syscall - /etc/group'
|
|
|
7629ac |
+
|
|
|
7629ac |
+description: |-
|
|
|
7629ac |
+ The audit system should collect write events to /etc/group file for all group and root.
|
|
|
7629ac |
+ If the <tt>auditd</tt> daemon is configured
|
|
|
7629ac |
+ to use the <tt>augenrules</tt> program to read audit rules during daemon
|
|
|
7629ac |
+ startup (the default), add the following lines to a file with suffix
|
|
|
7629ac |
+ <tt>.rules</tt> in the directory <tt>/etc/audit/rules.d</tt>:
|
|
|
7629ac |
+ -a always,exit -F arch=b32 -S open_by_handle_at -F a2&03 -F path=/etc/group -F auid>=1000 -F auid!=unset -F key=group-modify
|
|
|
7629ac |
+ If the <tt>auditd</tt> daemon is configured to use the <tt>auditctl</tt>
|
|
|
7629ac |
+ utility to read audit rules during daemon startup, add the following lines to
|
|
|
7629ac |
+ <tt>/etc/audit/audit.rules</tt> file:
|
|
|
7629ac |
+ -a always,exit -F arch=b64 -S open_by_handle_at -F a2&03 -F path=/etc/group -F auid>=1000 -F auid!=unset -F key=group-modify
|
|
|
7629ac |
+
|
|
|
7629ac |
+rationale: |-
|
|
|
7629ac |
+ Creation of groups through direct edition of /etc/group could be an indicator of malicious activity on a system.
|
|
|
7629ac |
+ Auditing these events could serve as evidence of potential system compromise.
|
|
|
7629ac |
+
|
|
|
7629ac |
+severity: medium
|
|
|
7629ac |
+
|
|
|
7629ac |
+references:
|
|
|
7629ac |
+ ospp@rhel7: FAU_GEN.1.1.c
|
|
|
7629ac |
+
|
|
|
7629ac |
+{{{ complete_ocil_entry_audit_syscall(syscall="open_by_handle_at") }}}
|
|
|
7629ac |
+
|
|
|
7629ac |
+warnings:
|
|
|
7629ac |
+ - general: |-
|
|
|
7629ac |
+ Note that these rules can be configured in a
|
|
|
7629ac |
+ number of ways while still achieving the desired effect. Here the system calls
|
|
|
7629ac |
+ have been placed independent of other system calls. Grouping system calls related
|
|
|
7629ac |
+ to the same event is more efficient. See the following example:
|
|
|
7629ac |
+ -a always,exit -F arch=b32 -S open,openat,open_by_handle_at -F a2&03 -F path=/etc/group -F auid>=1000 -F auid!=unset -F key=group-modify
|
|
|
7629ac |
diff --git a/linux_os/guide/system/auditing/auditd_configure_rules/audit_rules_etc_group_openat.rule b/linux_os/guide/system/auditing/auditd_configure_rules/audit_rules_etc_group_openat.rule
|
|
|
7629ac |
new file mode 100644
|
|
|
7629ac |
index 0000000000..61bde4d6e9
|
|
|
7629ac |
--- /dev/null
|
|
|
7629ac |
+++ b/linux_os/guide/system/auditing/auditd_configure_rules/audit_rules_etc_group_openat.rule
|
|
|
7629ac |
@@ -0,0 +1,36 @@
|
|
|
7629ac |
+documentation_complete: true
|
|
|
7629ac |
+
|
|
|
7629ac |
+prodtype: rhel7,fedora
|
|
|
7629ac |
+
|
|
|
7629ac |
+title: 'Record Events that Modify User/Group Information via openat syscall - /etc/group'
|
|
|
7629ac |
+
|
|
|
7629ac |
+description: |-
|
|
|
7629ac |
+ The audit system should collect write events to /etc/group file for all users and root.
|
|
|
7629ac |
+ If the <tt>auditd</tt> daemon is configured
|
|
|
7629ac |
+ to use the <tt>augenrules</tt> program to read audit rules during daemon
|
|
|
7629ac |
+ startup (the default), add the following lines to a file with suffix
|
|
|
7629ac |
+ <tt>.rules</tt> in the directory <tt>/etc/audit/rules.d</tt>:
|
|
|
7629ac |
+ -a always,exit -F arch=b32 -S openat -F a2&03 -F path=/etc/group -F auid>=1000 -F auid!=unset -F key=group-modify
|
|
|
7629ac |
+ If the <tt>auditd</tt> daemon is configured to use the <tt>auditctl</tt>
|
|
|
7629ac |
+ utility to read audit rules during daemon startup, add the following lines to
|
|
|
7629ac |
+ <tt>/etc/audit/audit.rules</tt> file:
|
|
|
7629ac |
+ -a always,exit -F arch=b64 -S openat -F a2&03 -F path=/etc/group -F auid>=1000 -F auid!=unset -F key=group-modify
|
|
|
7629ac |
+
|
|
|
7629ac |
+rationale: |-
|
|
|
7629ac |
+ Creation of groups through direct edition of /etc/group could be an indicator of malicious activity on a system.
|
|
|
7629ac |
+ Auditing these events could serve as evidence of potential system compromise.
|
|
|
7629ac |
+
|
|
|
7629ac |
+severity: medium
|
|
|
7629ac |
+
|
|
|
7629ac |
+references:
|
|
|
7629ac |
+ ospp@rhel7: FAU_GEN.1.1.c
|
|
|
7629ac |
+
|
|
|
7629ac |
+{{{ complete_ocil_entry_audit_syscall(syscall="openat") }}}
|
|
|
7629ac |
+
|
|
|
7629ac |
+warnings:
|
|
|
7629ac |
+ - general: |-
|
|
|
7629ac |
+ Note that these rules can be configured in a
|
|
|
7629ac |
+ number of ways while still achieving the desired effect. Here the system calls
|
|
|
7629ac |
+ have been placed independent of other system calls. Grouping system calls related
|
|
|
7629ac |
+ to the same event is more efficient. See the following example:
|
|
|
7629ac |
+ -a always,exit -F arch=b32 -S open,openat,open_by_handle_at -F a2&03 -F path=/etc/group -F auid>=1000 -F auid!=unset -F key=group-modify
|
|
|
7629ac |
diff --git a/linux_os/guide/system/auditing/auditd_configure_rules/audit_rules_etc_passwd_open_by_handle_at.rule b/linux_os/guide/system/auditing/auditd_configure_rules/audit_rules_etc_passwd_open_by_handle_at.rule
|
|
|
7629ac |
new file mode 100644
|
|
|
7629ac |
index 0000000000..0f91bb7d58
|
|
|
7629ac |
--- /dev/null
|
|
|
7629ac |
+++ b/linux_os/guide/system/auditing/auditd_configure_rules/audit_rules_etc_passwd_open_by_handle_at.rule
|
|
|
7629ac |
@@ -0,0 +1,36 @@
|
|
|
7629ac |
+documentation_complete: true
|
|
|
7629ac |
+
|
|
|
7629ac |
+prodtype: rhel7,fedora
|
|
|
7629ac |
+
|
|
|
7629ac |
+title: 'Record Events that Modify User/Group Information via open_by_handle_at syscall - /etc/passwd'
|
|
|
7629ac |
+
|
|
|
7629ac |
+description: |-
|
|
|
7629ac |
+ The audit system should collect write events to /etc/passwd file for all users and root.
|
|
|
7629ac |
+ If the <tt>auditd</tt> daemon is configured
|
|
|
7629ac |
+ to use the <tt>augenrules</tt> program to read audit rules during daemon
|
|
|
7629ac |
+ startup (the default), add the following lines to a file with suffix
|
|
|
7629ac |
+ <tt>.rules</tt> in the directory <tt>/etc/audit/rules.d</tt>:
|
|
|
7629ac |
+ -a always,exit -F arch=b32 -S open_by_handle_at -F a2&03 -F path=/etc/passwd -F auid>=1000 -F auid!=unset -F key=user-modify
|
|
|
7629ac |
+ If the <tt>auditd</tt> daemon is configured to use the <tt>auditctl</tt>
|
|
|
7629ac |
+ utility to read audit rules during daemon startup, add the following lines to
|
|
|
7629ac |
+ <tt>/etc/audit/audit.rules</tt> file:
|
|
|
7629ac |
+ -a always,exit -F arch=b64 -S open_by_handle_at -F a2&03 -F path=/etc/passwd -F auid>=1000 -F auid!=unset -F key=user-modify
|
|
|
7629ac |
+
|
|
|
7629ac |
+rationale: |-
|
|
|
7629ac |
+ Creation of users through direct edition of /etc/passwd could be an indicator of malicious activity on a system.
|
|
|
7629ac |
+ Auditing these events could serve as evidence of potential system compromise.
|
|
|
7629ac |
+
|
|
|
7629ac |
+severity: medium
|
|
|
7629ac |
+
|
|
|
7629ac |
+references:
|
|
|
7629ac |
+ ospp@rhel7: FAU_GEN.1.1.c
|
|
|
7629ac |
+
|
|
|
7629ac |
+{{{ complete_ocil_entry_audit_syscall(syscall="open_by_handle_at") }}}
|
|
|
7629ac |
+
|
|
|
7629ac |
+warnings:
|
|
|
7629ac |
+ - general: |-
|
|
|
7629ac |
+ Note that these rules can be configured in a
|
|
|
7629ac |
+ number of ways while still achieving the desired effect. Here the system calls
|
|
|
7629ac |
+ have been placed independent of other system calls. Grouping system calls related
|
|
|
7629ac |
+ to the same event is more efficient. See the following example:
|
|
|
7629ac |
+ -a always,exit -F arch=b32 -S open,openat,open_by_handle_at -F a2&03 -F path=/etc/passwd -F auid>=1000 -F auid!=unset -F key=user-modify
|
|
|
7629ac |
diff --git a/linux_os/guide/system/auditing/auditd_configure_rules/audit_rules_etc_passwd_openat.rule b/linux_os/guide/system/auditing/auditd_configure_rules/audit_rules_etc_passwd_openat.rule
|
|
|
7629ac |
new file mode 100644
|
|
|
7629ac |
index 0000000000..f1fab2b945
|
|
|
7629ac |
--- /dev/null
|
|
|
7629ac |
+++ b/linux_os/guide/system/auditing/auditd_configure_rules/audit_rules_etc_passwd_openat.rule
|
|
|
7629ac |
@@ -0,0 +1,36 @@
|
|
|
7629ac |
+documentation_complete: true
|
|
|
7629ac |
+
|
|
|
7629ac |
+prodtype: rhel7,fedora
|
|
|
7629ac |
+
|
|
|
7629ac |
+title: 'Record Events that Modify User/Group Information via openat syscall - /etc/passwd'
|
|
|
7629ac |
+
|
|
|
7629ac |
+description: |-
|
|
|
7629ac |
+ The audit system should collect write events to /etc/passwd file for all users and root.
|
|
|
7629ac |
+ If the <tt>auditd</tt> daemon is configured
|
|
|
7629ac |
+ to use the <tt>augenrules</tt> program to read audit rules during daemon
|
|
|
7629ac |
+ startup (the default), add the following lines to a file with suffix
|
|
|
7629ac |
+ <tt>.rules</tt> in the directory <tt>/etc/audit/rules.d</tt>:
|
|
|
7629ac |
+ -a always,exit -F arch=b32 -S openat -F a2&03 -F path=/etc/passwd -F auid>=1000 -F auid!=unset -F key=user-modify
|
|
|
7629ac |
+ If the <tt>auditd</tt> daemon is configured to use the <tt>auditctl</tt>
|
|
|
7629ac |
+ utility to read audit rules during daemon startup, add the following lines to
|
|
|
7629ac |
+ <tt>/etc/audit/audit.rules</tt> file:
|
|
|
7629ac |
+ -a always,exit -F arch=b64 -S openat -F a2&03 -F path=/etc/passwd -F auid>=1000 -F auid!=unset -F key=user-modify
|
|
|
7629ac |
+
|
|
|
7629ac |
+rationale: |-
|
|
|
7629ac |
+ Creation of users through direct edition of /etc/passwd could be an indicator of malicious activity on a system.
|
|
|
7629ac |
+ Auditing these events could serve as evidence of potential system compromise.
|
|
|
7629ac |
+
|
|
|
7629ac |
+severity: medium
|
|
|
7629ac |
+
|
|
|
7629ac |
+references:
|
|
|
7629ac |
+ ospp@rhel7: FAU_GEN.1.1.c
|
|
|
7629ac |
+
|
|
|
7629ac |
+{{{ complete_ocil_entry_audit_syscall(syscall="openat") }}}
|
|
|
7629ac |
+
|
|
|
7629ac |
+warnings:
|
|
|
7629ac |
+ - general: |-
|
|
|
7629ac |
+ Note that these rules can be configured in a
|
|
|
7629ac |
+ number of ways while still achieving the desired effect. Here the system calls
|
|
|
7629ac |
+ have been placed independent of other system calls. Grouping system calls related
|
|
|
7629ac |
+ to the same event is more efficient. See the following example:
|
|
|
7629ac |
+ -a always,exit -F arch=b32 -S open,openat,open_by_handle_at -F a2&03 -F path=/etc/passwd -F auid>=1000 -F auid!=unset -F key=user-modify
|
|
|
7629ac |
diff --git a/rhel7/profiles/ospp42.profile b/rhel7/profiles/ospp42.profile
|
|
|
7629ac |
index 343ac9eb3c..68f4e38bc8 100644
|
|
|
7629ac |
--- a/rhel7/profiles/ospp42.profile
|
|
|
7629ac |
+++ b/rhel7/profiles/ospp42.profile
|
|
|
7629ac |
@@ -171,3 +171,8 @@ selections:
|
|
|
7629ac |
- audit_rules_kernel_module_loading_rmmod
|
|
|
7629ac |
- security_patches_up_to_date
|
|
|
7629ac |
- audit_rules_etc_passwd_open
|
|
|
7629ac |
+ - audit_rules_etc_passwd_openat
|
|
|
7629ac |
+ - audit_rules_etc_passwd_open_by_handle_at
|
|
|
7629ac |
+ - audit_rules_etc_group_open
|
|
|
7629ac |
+ - audit_rules_etc_group_openat
|
|
|
7629ac |
+ - audit_rules_etc_group_open_by_handle_at
|
|
|
7629ac |
diff --git a/shared/templates/create_audit_rules_path_syscall.py b/shared/templates/create_audit_rules_path_syscall.py
|
|
|
7629ac |
new file mode 100644
|
|
|
7629ac |
index 0000000000..0283bf439c
|
|
|
7629ac |
--- /dev/null
|
|
|
7629ac |
+++ b/shared/templates/create_audit_rules_path_syscall.py
|
|
|
7629ac |
@@ -0,0 +1,33 @@
|
|
|
7629ac |
+#!/usr/bin/python2
|
|
|
7629ac |
+
|
|
|
7629ac |
+#
|
|
|
7629ac |
+# create_audit_rules_path_syscall_detailed.py
|
|
|
7629ac |
+# generate template-based checks for changes to a path via syscalls
|
|
|
7629ac |
+
|
|
|
7629ac |
+
|
|
|
7629ac |
+from template_common import FilesGenerator, UnknownTargetError
|
|
|
7629ac |
+
|
|
|
7629ac |
+import re
|
|
|
7629ac |
+
|
|
|
7629ac |
+class AuditRulesPathSyscallGenerator(FilesGenerator):
|
|
|
7629ac |
+ def generate(self, target, args):
|
|
|
7629ac |
+ path,syscall = args[0:2]
|
|
|
7629ac |
+ pathid = re.sub('[-\./]', '_', path)
|
|
|
7629ac |
+ # remove root slash made into '_'
|
|
|
7629ac |
+ pathid = pathid[1:]
|
|
|
7629ac |
+ if target == "oval":
|
|
|
7629ac |
+ self.file_from_template(
|
|
|
7629ac |
+ "./template_OVAL_audit_rules_path_syscall",
|
|
|
7629ac |
+ {
|
|
|
7629ac |
+ "PATH": path,
|
|
|
7629ac |
+ "PATHID": pathid,
|
|
|
7629ac |
+ "SYSCALL": syscall
|
|
|
7629ac |
+ },
|
|
|
7629ac |
+ "./oval/audit_rules_{0}_{1}.xml", pathid, syscall
|
|
|
7629ac |
+ )
|
|
|
7629ac |
+ else:
|
|
|
7629ac |
+ raise UnknownTargetError(target)
|
|
|
7629ac |
+
|
|
|
7629ac |
+ def csv_format(self):
|
|
|
7629ac |
+ return("CSV should contains lines of the format: " +
|
|
|
7629ac |
+ "PATH,SYSCALL")
|
|
|
7629ac |
diff --git a/shared/templates/csv/audit_rules_path_syscall.csv b/shared/templates/csv/audit_rules_path_syscall.csv
|
|
|
7629ac |
new file mode 100644
|
|
|
7629ac |
index 0000000000..015f02f58d
|
|
|
7629ac |
--- /dev/null
|
|
|
7629ac |
+++ b/shared/templates/csv/audit_rules_path_syscall.csv
|
|
|
7629ac |
@@ -0,0 +1,11 @@
|
|
|
7629ac |
+# format:
|
|
|
7629ac |
+# <path>,<syscall>
|
|
|
7629ac |
+# - path is the absolute path to watch
|
|
|
7629ac |
+# - syscall is the syscall to wath the path for
|
|
|
7629ac |
+
|
|
|
7629ac |
+/etc/passwd,open
|
|
|
7629ac |
+/etc/passwd,openat
|
|
|
7629ac |
+/etc/passwd,open_by_handle_at
|
|
|
7629ac |
+/etc/group,open
|
|
|
7629ac |
+/etc/group,openat
|
|
|
7629ac |
+/etc/group,open_by_handle_at
|
|
|
7629ac |
diff --git a/shared/checks/oval/audit_rules_etc_passwd_open.xml b/shared/templates/template_OVAL_audit_rules_path_syscall
|
|
|
7629ac |
similarity index 52%
|
|
|
7629ac |
rename from shared/checks/oval/audit_rules_etc_passwd_open.xml
|
|
|
7629ac |
rename to shared/templates/template_OVAL_audit_rules_path_syscall
|
|
|
7629ac |
index fd5c3efb28..dcc1d7b0a2 100644
|
|
|
7629ac |
--- a/shared/checks/oval/audit_rules_etc_passwd_open.xml
|
|
|
7629ac |
+++ b/shared/templates/template_OVAL_audit_rules_path_syscall
|
|
|
7629ac |
@@ -1,12 +1,12 @@
|
|
|
7629ac |
<def-group>
|
|
|
7629ac |
- <definition class="compliance" id="audit_rules_etc_passwd_open" version="1">
|
|
|
7629ac |
+ <definition class="compliance" id="audit_rules_{{{ PATHID }}}_{{{ SYSCALL }}}" version="1">
|
|
|
7629ac |
<metadata>
|
|
|
7629ac |
- <title>Ensure auditd Collects Write Events to /etc/passwd</title>
|
|
|
7629ac |
+ <title>Ensure auditd Collects Write Events to {{{ PATH }}}</title>
|
|
|
7629ac |
<affected family="unix">
|
|
|
7629ac |
<platform>Red Hat Enterprise Linux 7</platform>
|
|
|
7629ac |
<platform>multi_platform_fedora</platform>
|
|
|
7629ac |
</affected>
|
|
|
7629ac |
- <description>Audit rules about the write events to /etc/passwd</description>
|
|
|
7629ac |
+ <description>Audit rules about the write events to {{{ PATH }}}</description>
|
|
|
7629ac |
</metadata>
|
|
|
7629ac |
|
|
|
7629ac |
<criteria operator="OR">
|
|
|
7629ac |
@@ -14,26 +14,26 @@
|
|
|
7629ac |
|
|
|
7629ac |
<criteria operator="AND">
|
|
|
7629ac |
<extend_definition comment="audit augenrules" definition_ref="audit_rules_augenrules" />
|
|
|
7629ac |
- <criterion comment="audit rule to record write events to /etc/passwd" test_ref="test_audit_rules_etc_passwd_open_32bit_augenrules" />
|
|
|
7629ac |
+ <criterion comment="audit rule to record write events to {{{ PATH }}}" test_ref="test_audit_rules_{{{ PATHID }}}_{{{ SYSCALL }}}_32bit_augenrules" />
|
|
|
7629ac |
|
|
|
7629ac |
<criteria operator="OR">
|
|
|
7629ac |
|
|
|
7629ac |
<extend_definition comment="64-bit system" definition_ref="system_info_architecture_64bit" negate="true" />
|
|
|
7629ac |
|
|
|
7629ac |
- <criterion comment="audit rule to record write events to /etc/passwd" test_ref="test_audit_rules_etc_passwd_open_64bit_augenrules" />
|
|
|
7629ac |
+ <criterion comment="audit rule to record write events to {{{ PATH }}}" test_ref="test_audit_rules_{{{ PATHID }}}_{{{ SYSCALL }}}_64bit_augenrules" />
|
|
|
7629ac |
</criteria>
|
|
|
7629ac |
</criteria>
|
|
|
7629ac |
|
|
|
7629ac |
|
|
|
7629ac |
<criteria operator="AND">
|
|
|
7629ac |
<extend_definition comment="audit auditctl" definition_ref="audit_rules_auditctl" />
|
|
|
7629ac |
- <criterion comment="audit rule to record write events to /etc/passwd" test_ref="test_audit_rules_etc_passwd_open_32bit_auditctl" />
|
|
|
7629ac |
+ <criterion comment="audit rule to record write events to {{{ PATH }}}" test_ref="test_audit_rules_{{{ PATHID }}}_{{{ SYSCALL }}}_32bit_auditctl" />
|
|
|
7629ac |
|
|
|
7629ac |
<criteria operator="OR">
|
|
|
7629ac |
|
|
|
7629ac |
<extend_definition comment="64-bit_system" definition_ref="system_info_architecture_64bit" negate="true" />
|
|
|
7629ac |
|
|
|
7629ac |
- <criterion comment="audit rule to record write events to /etc/passwd" test_ref="test_audit_rules_etc_passwd_open_64bit_auditctl" />
|
|
|
7629ac |
+ <criterion comment="audit rule to record write events to {{{ PATH }}}" test_ref="test_audit_rules_{{{ PATHID }}}_{{{ SYSCALL }}}_64bit_auditctl" />
|
|
|
7629ac |
</criteria>
|
|
|
7629ac |
</criteria>
|
|
|
7629ac |
|
|
|
7629ac |
@@ -41,55 +41,55 @@
|
|
|
7629ac |
</definition>
|
|
|
7629ac |
|
|
|
7629ac |
|
|
|
7629ac |
- <constant_variable id="var_audit_rule_32bit_open_write_etc_passwd_regex" version="1" datatype="string" comment="audit rule arch and syscal">
|
|
|
7629ac |
- <value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:-S(?:[\s]+open[\s]+|(?:[\s]+|[,])open(?:[\s]+|[,])))[\S]*[\s]*(?:-F[\s]+a2&03)[\s]+(?:-F[\s]+path=/etc/passwd)[\s]+(?:-F\s+auid>={{{ auid }}}[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</value>
|
|
|
7629ac |
+ <constant_variable id="var_audit_rule_32bit_{{{ SYSCALL }}}_write_{{{ PATHID }}}_regex" version="1" datatype="string" comment="audit rule arch and syscal">
|
|
|
7629ac |
+ <value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:-S(?:[\s]+{{{ SYSCALL }}}[\s]+|(?:[\s]+|[,]){{{ SYSCALL }}}(?:[\s]+|[,])))[\S]*[\s]*(?:-F[\s]+a2&03)[\s]+(?:-F[\s]+path={{{ PATH }}})[\s]+(?:-F\s+auid>={{{ auid }}}[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</value>
|
|
|
7629ac |
</constant_variable>
|
|
|
7629ac |
|
|
|
7629ac |
- <constant_variable id="var_audit_rule_64bit_open_write_etc_passwd_regex" version="1" datatype="string" comment="audit rule arch and syscal">
|
|
|
7629ac |
- <value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:-S(?:[\s]+open[\s]+|(?:[\s]+|[,])open(?:[\s]+|[,])))[\S]*[\s]*(?:-F[\s]+a2&03)[\s]+(?:-F[\s]+path=/etc/passwd)[\s]+(?:-F\s+auid>={{{ auid }}}[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</value>
|
|
|
7629ac |
+ <constant_variable id="var_audit_rule_64bit_{{{ SYSCALL }}}_write_{{{ PATHID }}}_regex" version="1" datatype="string" comment="audit rule arch and syscal">
|
|
|
7629ac |
+ <value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:-S(?:[\s]+{{{ SYSCALL }}}[\s]+|(?:[\s]+|[,]){{{ SYSCALL }}}(?:[\s]+|[,])))[\S]*[\s]*(?:-F[\s]+a2&03)[\s]+(?:-F[\s]+path={{{ PATH }}})[\s]+(?:-F\s+auid>={{{ auid }}}[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</value>
|
|
|
7629ac |
</constant_variable>
|
|
|
7629ac |
|
|
|
7629ac |
-
|
|
|
7629ac |
+
|
|
|
7629ac |
|
|
|
7629ac |
- comment="defined audit rule must exist" id="test_audit_rules_etc_passwd_open_32bit_augenrules" version="1">
|
|
|
7629ac |
- <ind:object object_ref="object_audit_rules_etc_passwd_open_32bit_augenrules" />
|
|
|
7629ac |
+ comment="defined audit rule must exist" id="test_audit_rules_{{{ PATHID }}}_{{{ SYSCALL }}}_32bit_augenrules" version="1">
|
|
|
7629ac |
+ <ind:object object_ref="object_audit_rules_{{{ PATHID }}}_{{{ SYSCALL }}}_32bit_augenrules" />
|
|
|
7629ac |
</ind:textfilecontent54_test>
|
|
|
7629ac |
- <ind:textfilecontent54_object id="object_audit_rules_etc_passwd_open_32bit_augenrules" version="1">
|
|
|
7629ac |
+ <ind:textfilecontent54_object id="object_audit_rules_{{{ PATHID }}}_{{{ SYSCALL }}}_32bit_augenrules" version="1">
|
|
|
7629ac |
<ind:filepath operation="pattern match">/etc/audit/rules\.d/.*\.rules</ind:filepath>
|
|
|
7629ac |
- <ind:pattern operation="pattern match" var_ref="var_audit_rule_32bit_open_write_etc_passwd_regex" />
|
|
|
7629ac |
+ <ind:pattern operation="pattern match" var_ref="var_audit_rule_32bit_{{{ SYSCALL }}}_write_{{{ PATHID }}}_regex" />
|
|
|
7629ac |
<ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
|
|
|
7629ac |
</ind:textfilecontent54_object>
|
|
|
7629ac |
|
|
|
7629ac |
|
|
|
7629ac |
- comment="defined audit rule must exist" id="test_audit_rules_etc_passwd_open_64bit_augenrules" version="1">
|
|
|
7629ac |
- <ind:object object_ref="object_audit_rules_etc_passwd_open_64bit_augenrules" />
|
|
|
7629ac |
+ comment="defined audit rule must exist" id="test_audit_rules_{{{ PATHID }}}_{{{ SYSCALL }}}_64bit_augenrules" version="1">
|
|
|
7629ac |
+ <ind:object object_ref="object_audit_rules_{{{ PATHID }}}_{{{ SYSCALL }}}_64bit_augenrules" />
|
|
|
7629ac |
</ind:textfilecontent54_test>
|
|
|
7629ac |
- <ind:textfilecontent54_object id="object_audit_rules_etc_passwd_open_64bit_augenrules" version="1">
|
|
|
7629ac |
+ <ind:textfilecontent54_object id="object_audit_rules_{{{ PATHID }}}_{{{ SYSCALL }}}_64bit_augenrules" version="1">
|
|
|
7629ac |
<ind:filepath operation="pattern match">/etc/audit/rules\.d/.*\.rules</ind:filepath>
|
|
|
7629ac |
- <ind:pattern operation="pattern match" var_ref="var_audit_rule_64bit_open_write_etc_passwd_regex" />
|
|
|
7629ac |
+ <ind:pattern operation="pattern match" var_ref="var_audit_rule_64bit_{{{ SYSCALL }}}_write_{{{ PATHID }}}_regex" />
|
|
|
7629ac |
<ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
|
|
|
7629ac |
</ind:textfilecontent54_object>
|
|
|
7629ac |
|
|
|
7629ac |
|
|
|
7629ac |
|
|
|
7629ac |
-
|
|
|
7629ac |
+
|
|
|
7629ac |
|
|
|
7629ac |
- comment="defined audit rule must exist" id="test_audit_rules_etc_passwd_open_32bit_auditctl" version="1">
|
|
|
7629ac |
- <ind:object object_ref="object_audit_rules_etc_passwd_open_32bit_auditctl" />
|
|
|
7629ac |
+ comment="defined audit rule must exist" id="test_audit_rules_{{{ PATHID }}}_{{{ SYSCALL }}}_32bit_auditctl" version="1">
|
|
|
7629ac |
+ <ind:object object_ref="object_audit_rules_{{{ PATHID }}}_{{{ SYSCALL }}}_32bit_auditctl" />
|
|
|
7629ac |
</ind:textfilecontent54_test>
|
|
|
7629ac |
- <ind:textfilecontent54_object id="object_audit_rules_etc_passwd_open_32bit_auditctl" version="1">
|
|
|
7629ac |
+ <ind:textfilecontent54_object id="object_audit_rules_{{{ PATHID }}}_{{{ SYSCALL }}}_32bit_auditctl" version="1">
|
|
|
7629ac |
<ind:filepath>/etc/audit/audit.rules</ind:filepath>
|
|
|
7629ac |
- <ind:pattern operation="pattern match" var_ref="var_audit_rule_32bit_open_write_etc_passwd_regex" />
|
|
|
7629ac |
+ <ind:pattern operation="pattern match" var_ref="var_audit_rule_32bit_{{{ SYSCALL }}}_write_{{{ PATHID }}}_regex" />
|
|
|
7629ac |
<ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
|
|
|
7629ac |
</ind:textfilecontent54_object>
|
|
|
7629ac |
|
|
|
7629ac |
|
|
|
7629ac |
- comment="defined audit rule must exist" id="test_audit_rules_etc_passwd_open_64bit_auditctl" version="1">
|
|
|
7629ac |
- <ind:object object_ref="object_audit_rules_etc_passwd_open_64bit_auditctl" />
|
|
|
7629ac |
+ comment="defined audit rule must exist" id="test_audit_rules_{{{ PATHID }}}_{{{ SYSCALL }}}_64bit_auditctl" version="1">
|
|
|
7629ac |
+ <ind:object object_ref="object_audit_rules_{{{ PATHID }}}_{{{ SYSCALL }}}_64bit_auditctl" />
|
|
|
7629ac |
</ind:textfilecontent54_test>
|
|
|
7629ac |
- <ind:textfilecontent54_object id="object_audit_rules_etc_passwd_open_64bit_auditctl" version="1">
|
|
|
7629ac |
+ <ind:textfilecontent54_object id="object_audit_rules_{{{ PATHID }}}_{{{ SYSCALL }}}_64bit_auditctl" version="1">
|
|
|
7629ac |
<ind:filepath>/etc/audit/audit.rules</ind:filepath>
|
|
|
7629ac |
- <ind:pattern operation="pattern match" var_ref="var_audit_rule_64bit_open_write_etc_passwd_regex" />
|
|
|
7629ac |
+ <ind:pattern operation="pattern match" var_ref="var_audit_rule_64bit_{{{ SYSCALL }}}_write_{{{ PATHID }}}_regex" />
|
|
|
7629ac |
<ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
|
|
|
7629ac |
</ind:textfilecontent54_object>
|
|
|
7629ac |
|
|
|
7629ac |
diff --git a/shared/templates/template_common.py b/shared/templates/template_common.py
|
|
|
7629ac |
index b0fdf5fcc9..c8930ee05c 100644
|
|
|
7629ac |
--- a/shared/templates/template_common.py
|
|
|
7629ac |
+++ b/shared/templates/template_common.py
|
|
|
7629ac |
@@ -78,14 +78,15 @@ def get_template_filename(self, filename):
|
|
|
7629ac |
raise TemplateNotFoundError(filename, paths)
|
|
|
7629ac |
|
|
|
7629ac |
def file_from_template(self, template_filename, constants,
|
|
|
7629ac |
- filename_format, filename_value):
|
|
|
7629ac |
+ filename_format, filename_value, *extra_filename_args):
|
|
|
7629ac |
"""
|
|
|
7629ac |
Load template, fill constant and create new file
|
|
|
7629ac |
"""
|
|
|
7629ac |
|
|
|
7629ac |
template_filepath = self.get_template_filename(template_filename)
|
|
|
7629ac |
+ format_args = (filename_value,) + extra_filename_args
|
|
|
7629ac |
output_filepath = os.path.join(
|
|
|
7629ac |
- self.output_dir, filename_format.format(filename_value)
|
|
|
7629ac |
+ self.output_dir, filename_format.format(*format_args)
|
|
|
7629ac |
)
|
|
|
7629ac |
|
|
|
7629ac |
if self.action == ActionType.INPUT:
|