Tag: audit
sudo install auditd
## First rule - delete all -D ## Increase the buffers to survive stress events. ## Make this bigger for busy systems -b 8192 ## This determine how long to wait in burst of events --backlog_wait_time 0 ## Set failure mode to syslog -f 1 -a always,exit -F dir=/var/lib/mysql -S unlink -S unlinkat -S rename -S renameat -S rmdir -k delete_mysql -a always,exit -F arch=b32 -F uid=33 -S execve -k www -a always,exit -F arch=b64 -F uid=33 -S execve -k www -a always,exit -F arch=b32 -C auid!=uid -S execve -k su_prog -a always,exit -F arch=b64 -C auid!=uid -S execve -k su_prog -a exit,always -S unlink -S rmdir -k delete_file -w /var/www -p wa -k change_file -w /etc/group -p wa -k change_file -w /etc/passwd -p wa -k change_file -w /etc/shadow -p wa -k change_file -w /etc/sudoers -p -k change_file
-a always,exit -F dir=/var/lib/mysql -S unlink -S unlinkat -S rename -S renameat -S rmdir -k delete_mysql
-a always,exit -F arch=b32 -F uid=33 -S execve -k www -a always,exit -F arch=b64 -F uid=33 -S execve -k www
-a always,exit -F arch=b32 -C auid!=uid -S execve -k su_prog -a always,exit -F arch=b64 -C auid!=uid -S execve -k su_prog
-a exit,always -S unlink -S rmdir -k delete_file
-w /var/www -p wa -k change_file -w /etc/group -p wa -k change_file -w /etc/passwd -p wa -k change_file -w /etc/shadow -p wa -k change_file -w /etc/sudoers -p -k change_file