Skip to content

SLEM 5 must generate audit records for a uses of the "chsh" command.

An XCCDF Rule

Description

Reconstruction of harmful events or forensic analysis is not possible if audit records do not contain enough information. At a minimum, the organization must audit the full-text recording of privileged commands. The organization must maintain audit trails in sufficient detail to reconstruct events to determine the cause and impact of compromise.

ID
SV-261430r996697_rule
Version
SLEM-05-654035
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Configure SLEM 5 to generate an audit record for all uses of the "chsh" command.

Add or modify the following line in the "/etc/audit/rules.d/audit.rules" file:

-a always,exit -F path=/usr/bin/chsh -F perm=x -F auid>=1000 -F auid!=unset -k privileged-chsh