Skip to content

SLEM 5 must generate audit records for all uses of the "ssh-agent" command.

An XCCDF Rule

Description

Reconstruction of harmful events or forensic analysis is not possible if audit records do not contain enough information. At a minimum, the organization must audit the full-text recording of privileged commands. The organization must maintain audit trails in sufficient detail to reconstruct events to determine the cause and impact of compromise.

ID
SV-261442r996733_rule
Version
SLEM-05-654095
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Configure SLEM 5 to generate an audit record for all uses of the "ssh-agent" command.

Add or modify the following line in the "/etc/audit/rules.d/audit.rules" file:

-a always,exit -F path=/usr/bin/ssh-agent -F perm=x -F auid>=1000 -F auid!=unset -k privileged-ssh-agent