Mondoo Docs

auditd (Linux Audit Daemon) rule

auditd.rule MQL resource for querying Operating System infrastructure with cnquery and cnspec.

Operating SystemPrivate Resource

auditd (Linux Audit Daemon) rule

Min version: 9.0.0

Relationships

Mini Map
Operating System
5 resources · 4 relationshipsClick to select, expand fields to see properties.

Fields (3)

FieldTypeDescription
controlprivate
auditd.rule.controlauditd (Linux Audit Daemon) rule for a control
fileprivate
auditd.rule.fileauditd (Linux Audit Daemon) rule for a file
syscallprivate
auditd.rule.syscallauditd (Linux Audit Daemon) rule for a syscall

Field Details

controlauditd.rule.control

We translate these into simple key-value pairs consisting of a flag and a value eg: --backlog_wait_time 60000 => {flag: "--backlog_wait_time", value: "60000"} eg: -b 8192 => {flag: "-b", value: "8192"} eg: -D => {flag: "-D", value: nil}

fileauditd.rule.file

eg: -w /etc/shadow -p rw -k shadow_access => {path: "/etc/shadow", permissions: "rw", keyname: "shadow_access"}

syscallauditd.rule.syscall

eg: -a always,exit -F arch=b32 -F auid>=1000 -F auid!=unset => { action: "always", list: "exit", syscalls: [], field_entries: [ key="arch" op="=" value="b32" key="auid" op=">=" value="1000" key="auid" op="!=" value="unset" ], keyname: nil, }