Record Events that Modify the System's Mandatory Access Controls
Record Events that Modify the System's Mandatory Access Controls in usr/share
Ensure auditd Collects Information on Exporting to Media (successful)
Record Events that Modify the System's Network Environment
Record Attempts to Alter Process and Session Initiation Information
Ensure auditd Collects System Administrator Actions
Record Events that Modify User/Group Information
Record Events that Modify the System's Discretionary Access Controls - chmod
Record Events that Modify the System's Discretionary Access Controls - chown
Record Events that Modify the System's Discretionary Access Controls - fchmod
Record Events that Modify the System's Discretionary Access Controls - fchmodat
Record Events that Modify the System's Discretionary Access Controls - fchown
Record Events that Modify the System's Discretionary Access Controls - fchownat
Record Events that Modify the System's Discretionary Access Controls - fremovexattr
Record Events that Modify the System's Discretionary Access Controls - fsetxattr
Record Events that Modify the System's Discretionary Access Controls - lchown
Record Events that Modify the System's Discretionary Access Controls - lremovexattr
Record Events that Modify the System's Discretionary Access Controls - lsetxattr
Record Events that Modify the System's Discretionary Access Controls - removexattr
Record Events that Modify the System's Discretionary Access Controls - setxattr
Ensure auditd Collects File Deletion Events by User
Ensure auditd Collects File Deletion Events by User - rename
Ensure auditd Collects File Deletion Events by User - renameat
Ensure auditd Collects File Deletion Events by User - rmdir
Ensure auditd Collects File Deletion Events by User - unlink
Ensure auditd Collects File Deletion Events by User - unlinkat
Ensure auditd Collects Unauthorized Access Attempts to Files (unsuccessful)
Record Unsuccessful Access Attempts to Files - creat
Record Unsuccessful Access Attempts to Files - ftruncate
Record Unsuccessful Access Attempts to Files - open
Record Unsuccessful Access Attempts to Files - open_by_handle_at
Record Unsuccessful Access Attempts to Files - openat
Record Unsuccessful Access Attempts to Files - truncate
Ensure auditd Collects Information on Kernel Module Loading and Unloading
Ensure auditd Collects Information on Kernel Module Unloading - delete_module
Ensure auditd Collects Information on Kernel Module Loading and Unloading - finit_module
Ensure auditd Collects Information on Kernel Module Loading - init_module
Ensure auditd Collects Information on the Use of Privileged Commands - init
Ensure auditd Collects Information on the Use of Privileged Commands - poweroff
Ensure auditd Collects Information on the Use of Privileged Commands - reboot
Ensure auditd Collects Information on the Use of Privileged Commands - shutdown
Ensure auditd Collects Information on the Use of Privileged Commands
Record attempts to alter time through adjtimex
Record Attempts to Alter Time Through clock_settime
Record attempts to alter time through settimeofday
Record Attempts to Alter Time Through stime
Record Attempts to Alter the localtime File
Record Events that Modify User/Group Information via open syscall - /etc/group
Record Events that Modify User/Group Information via open_by_handle_at syscall - /etc/group
Record Events that Modify User/Group Information via openat syscall - /etc/group
Record Events that Modify User/Group Information via open syscall - /etc/gshadow
Record Events that Modify User/Group Information via open_by_handle_at syscall - /etc/gshadow
Record Events that Modify User/Group Information via openat syscall - /etc/gshadow
Record Events that Modify User/Group Information via open syscall - /etc/passwd
Record Events that Modify User/Group Information via open_by_handle_at syscall - /etc/passwd
Record Events that Modify User/Group Information via openat syscall - /etc/passwd
Record Events that Modify User/Group Information via open syscall - /etc/shadow
Record Events that Modify User/Group Information via open_by_handle_at syscall - /etc/shadow
Record Events that Modify User/Group Information via openat syscall - /etc/shadow
Record Events that Modify User/Group Information - /etc/group
Record Events that Modify User/Group Information - /etc/gshadow
Record Events that Modify User/Group Information - /etc/security/opasswd
Record Events that Modify User/Group Information - /etc/passwd
Record Events that Modify User/Group Information - /etc/shadow
Record Access Events to Audit Log Directory
Record Any Attempts to Run chcon
Record Any Attempts to Run restorecon
Record Any Attempts to Run semanage
Record Any Attempts to Run setfiles
Record Any Attempts to Run setsebool
Record Any Attempts to Run seunshare
Record Unsuccessful Permission Changes to Files - chmod
Record Unsuccessful Ownership Changes to Files - chown
Record Unsuccessful Permission Changes to Files - fchmod
Record Unsuccessful Permission Changes to Files - fchmodat
Record Unsuccessful Ownership Changes to Files - fchown
Record Unsuccessful Ownership Changes to Files - fchownat
Record Unsuccessful Permission Changes to Files - fremovexattr
Record Unsuccessful Permission Changes to Files - fsetxattr
Record Unsuccessful Ownership Changes to Files - lchown
Record Unsuccessful Permission Changes to Files - lremovexattr
Record Unsuccessful Permission Changes to Files - lsetxattr
Record Unsuccessful Creation Attempts to Files - open_by_handle_at O_CREAT
Record Unsuccessful Modification Attempts to Files - open_by_handle_at O_TRUNC_WRITE
Ensure auditd Unauthorized Access Attempts To open_by_handle_at Are Ordered Correctly
Record Unsuccessful Creation Attempts to Files - open O_CREAT
Record Unsuccessful Modification Attempts to Files - open O_TRUNC_WRITE
Ensure auditd Rules For Unauthorized Attempts To open Are Ordered Correctly
Record Unsuccessful Creation Attempts to Files - openat O_CREAT
Record Unsuccessful Modification Attempts to Files - openat O_TRUNC_WRITE
Ensure auditd Rules For Unauthorized Attempts To openat Are Ordered Correctly
Record Unsuccessful Permission Changes to Files - removexattr
Record Unsuccessful Delete Attempts to Files - rename
Record Unsuccessful Delete Attempts to Files - renameat
Record Unsuccessful Permission Changes to Files - setxattr
Record Unsuccessful Delete Attempts to Files - unlink
Record Unsuccessful Delete Attempts to Files - unlinkat
Record Attempts to Alter Logon and Logout Events
Record Attempts to Alter Logon and Logout Events - faillock
Record Attempts to Alter Logon and Logout Events - lastlog
Record Attempts to Alter Logon and Logout Events - tallylog
Ensure auditd Collects Information on the Use of Privileged Commands - at
Ensure auditd Collects Information on the Use of Privileged Commands - chage
Ensure auditd Collects Information on the Use of Privileged Commands - chsh
Ensure auditd Collects Information on the Use of Privileged Commands - crontab
Ensure auditd Collects Information on the Use of Privileged Commands - gpasswd
Ensure auditd Collects Information on the Use of Privileged Commands - insmod
Ensure auditd Collects Information on the Use of Privileged Commands - modprobe
Ensure auditd Collects Information on the Use of Privileged Commands - mount
Ensure auditd Collects Information on the Use of Privileged Commands - newgidmap
Ensure auditd Collects Information on the Use of Privileged Commands - newgrp
Ensure auditd Collects Information on the Use of Privileged Commands - newuidmap
Ensure auditd Collects Information on the Use of Privileged Commands - pam_timestamp_check
Ensure auditd Collects Information on the Use of Privileged Commands - passwd
Ensure auditd Collects Information on the Use of Privileged Commands - postdrop
Ensure auditd Collects Information on the Use of Privileged Commands - postqueue
Ensure auditd Collects Information on the Use of Privileged Commands - pt_chown
Ensure auditd Collects Information on the Use of Privileged Commands - ssh-keysign
Ensure auditd Collects Information on the Use of Privileged Commands - su
Ensure auditd Collects Information on the Use of Privileged Commands - sudo
Ensure auditd Collects Information on the Use of Privileged Commands - sudoedit
Ensure auditd Collects Information on the Use of Privileged Commands - umount
Ensure auditd Collects Information on the Use of Privileged Commands - unix_chkpwd
Ensure auditd Collects Information on the Use of Privileged Commands - userhelper
Ensure auditd Collects Information on the Use of Privileged Commands - usernetctl
Record Access Events to Kubernetes Audit Log Directory
Record Access Events to OAuth Audit Log Directory
Record Access Events to OpenShift Audit Log Directory
Ensure the libaudit1 package as a part of audit Subsystem is Installed
Ensure the audit Subsystem is Installed
Record Events that Modify the System's Discretionary Access Controls - umount
Record Events that Modify the System's Discretionary Access Controls - umount2
Record Any Attempts to Run chacl
Record Any Attempts to Run chmod
Record Any Attempts to Run setfacl
Record Any Attempts to Run rm
Record Attempts to Alter Logon and Logout Events - faillog
Ensure auditd Collects Information on the Use of Privileged Commands - chfn
Ensure auditd Collects Information on the Use of Privileged Commands - passmass
Record Any Attempts to Run ssh-agent
Ensure auditd Collects Information on the Use of Privileged Commands - usermod
Record Attempts to Alter Process and Session Initiation Information btmp
Record Attempts to Alter Process and Session Initiation Information utmp
Record Attempts to Alter Process and Session Initiation Information wtmp
Record Unsuccessful Delete Attempts to Files - renameat2
Ensure auditd Collects Information on the Use of Privileged Commands - rmmod
Ensure auditd Collects Information on the Use of Privileged Commands - unix2_chkpwd