1.185 RHEL-10-500300

Information

RHEL 10 must generate audit records for successful and unsuccessful uses of the "execve" system call.

GROUP ID: V-281116RULE ID: SV-281116r1166300

Misuse of privileged functions, either intentionally or unintentionally by authorized users, or by unauthorized external entities that have compromised information system accounts, is a serious and ongoing concern and can have significant adverse impacts on organizations.

Auditing the use of privileged functions is one way to detect such misuse and identify the risk from insider threats and the advanced persistent threat.

Satisfies: SRG-OS-000326-GPOS-00126, SRG-OS-000327-GPOS-00127, SRG-OS-000755-GPOS-00220

Solution

Configure RHEL 10 to generate audit records upon successful and unsuccessful attempts to use the "execve" system call.

Add or update the following file system rules to "/etc/audit/rules.d/audit.rules":

-a always,exit -F arch=b32 -S execve -C uid!=euid -F euid=0 -k execpriv-a always,exit -F arch=b64 -S execve -C uid!=euid -F euid=0 -k execpriv-a always,exit -F arch=b32 -S execve -C gid!=egid -F egid=0 -k execpriv-a always,exit -F arch=b64 -S execve -C gid!=egid -F egid=0 -k execpriv

Restart the audit daemon with the following command for the changes to take effect:

$ sudo service auditd restart

See Also

https://workbench.cisecurity.org/benchmarks/26403