From 5cde0e0520c72804b6eac8f08d976db777d7ba04 Mon Sep 17 00:00:00 2001 From: Dominik Lisiak Date: Fri, 26 Oct 2018 18:45:19 +0200 Subject: Added CIS benchmarks. Improved profiles. --- .../files/template-logs-default.xml.in | 68 ---------------------- .../files/template-logs-system.xml.in | 68 ++++++++++++++++++++++ .../files/template-rootcheck-basic.xml.in | 22 +++++++ .../files/template-rootcheck-cis-l1.xml.in | 9 +++ .../files/template-rootcheck-cis-l2.xml.in | 9 +++ .../files/template-rootcheck-cis.xml.in | 9 +++ .../files/template-rootcheck-default.xml.in | 23 -------- .../files/template-syscheck-basic.xml.in | 18 ++++++ .../files/template-syscheck-default.xml.in | 18 ------ .../files/template-syscheck-hostdeny.xml.in | 4 +- .../files/template-syscheck-newfiles.xml.in | 4 +- .../files/template-syscheck-noauto.xml.in | 4 +- .../files/template-syscheck-ossec.xml.in | 4 +- 13 files changed, 143 insertions(+), 117 deletions(-) delete mode 100644 security/ossec-hids-local-config/files/template-logs-default.xml.in create mode 100644 security/ossec-hids-local-config/files/template-logs-system.xml.in create mode 100644 security/ossec-hids-local-config/files/template-rootcheck-basic.xml.in create mode 100644 security/ossec-hids-local-config/files/template-rootcheck-cis-l1.xml.in create mode 100644 security/ossec-hids-local-config/files/template-rootcheck-cis-l2.xml.in create mode 100644 security/ossec-hids-local-config/files/template-rootcheck-cis.xml.in delete mode 100644 security/ossec-hids-local-config/files/template-rootcheck-default.xml.in create mode 100644 security/ossec-hids-local-config/files/template-syscheck-basic.xml.in delete mode 100644 security/ossec-hids-local-config/files/template-syscheck-default.xml.in (limited to 'security/ossec-hids-local-config/files') diff --git a/security/ossec-hids-local-config/files/template-logs-default.xml.in b/security/ossec-hids-local-config/files/template-logs-default.xml.in deleted file mode 100644 index 47b9a77..0000000 --- a/security/ossec-hids-local-config/files/template-logs-default.xml.in +++ /dev/null @@ -1,68 +0,0 @@ - - - - - syslog - /var/log/auth.log - - - - syslog - /var/log/maillog - - - - syslog - /var/log/messages - - - - syslog - /var/log/security - - - - syslog - /var/log/userlog - - - - syslog - /var/log/xferlog - - - - - - - - syslog - /var/log/auth.log - - - - syslog - /var/log/dpkg.log - - - - syslog - /var/log/kern.log - - - - syslog - /var/log/mail.log - - - - syslog - /var/log/messages - - - - syslog - /var/log/syslog - - - diff --git a/security/ossec-hids-local-config/files/template-logs-system.xml.in b/security/ossec-hids-local-config/files/template-logs-system.xml.in new file mode 100644 index 0000000..eee09aa --- /dev/null +++ b/security/ossec-hids-local-config/files/template-logs-system.xml.in @@ -0,0 +1,68 @@ + + + + + syslog + /var/log/auth.log + + + + syslog + /var/log/maillog + + + + syslog + /var/log/messages + + + + syslog + /var/log/security + + + + syslog + /var/log/userlog + + + + syslog + /var/log/xferlog + + + + + + + + syslog + /var/log/auth.log + + + + syslog + /var/log/dpkg.log + + + + syslog + /var/log/kern.log + + + + syslog + /var/log/mail.log + + + + syslog + /var/log/messages + + + + syslog + /var/log/syslog + + + diff --git a/security/ossec-hids-local-config/files/template-rootcheck-basic.xml.in b/security/ossec-hids-local-config/files/template-rootcheck-basic.xml.in new file mode 100644 index 0000000..37c2166 --- /dev/null +++ b/security/ossec-hids-local-config/files/template-rootcheck-basic.xml.in @@ -0,0 +1,22 @@ + + + + + %%OSSEC_HOME%%/etc/shared/rootkit_files.txt + %%OSSEC_HOME%%/etc/shared/rootkit_trojans.txt + %%OSSEC_HOME%%/etc/shared/system_audit_rcl.txt + %%OSSEC_HOME%%/etc/shared/system_audit_ssh.txt + + + + + + + + /var/ossec/etc/shared/rootkit_files.txt + /var/ossec/etc/shared/rootkit_trojans.txt + /var/ossec/etc/shared/system_audit_rcl.txt + /var/ossec/etc/shared/system_audit_ssh.txt + + + diff --git a/security/ossec-hids-local-config/files/template-rootcheck-cis-l1.xml.in b/security/ossec-hids-local-config/files/template-rootcheck-cis-l1.xml.in new file mode 100644 index 0000000..1b2f20c --- /dev/null +++ b/security/ossec-hids-local-config/files/template-rootcheck-cis-l1.xml.in @@ -0,0 +1,9 @@ + + + + + + /var/ossec/etc/shared/cis_debianlinux7-8_L1_rcl.txt + + + diff --git a/security/ossec-hids-local-config/files/template-rootcheck-cis-l2.xml.in b/security/ossec-hids-local-config/files/template-rootcheck-cis-l2.xml.in new file mode 100644 index 0000000..d156887 --- /dev/null +++ b/security/ossec-hids-local-config/files/template-rootcheck-cis-l2.xml.in @@ -0,0 +1,9 @@ + + + + + + /var/ossec/etc/shared/cis_debianlinux7-8_L2_rcl.txt + + + diff --git a/security/ossec-hids-local-config/files/template-rootcheck-cis.xml.in b/security/ossec-hids-local-config/files/template-rootcheck-cis.xml.in new file mode 100644 index 0000000..0640be7 --- /dev/null +++ b/security/ossec-hids-local-config/files/template-rootcheck-cis.xml.in @@ -0,0 +1,9 @@ + + + + + + /var/ossec/etc/shared/cis_debian_linux_rcl.txt + + + diff --git a/security/ossec-hids-local-config/files/template-rootcheck-default.xml.in b/security/ossec-hids-local-config/files/template-rootcheck-default.xml.in deleted file mode 100644 index 63e5f1e..0000000 --- a/security/ossec-hids-local-config/files/template-rootcheck-default.xml.in +++ /dev/null @@ -1,23 +0,0 @@ - - - - - %%OSSEC_HOME%%/etc/shared/rootkit_files.txt - %%OSSEC_HOME%%/etc/shared/rootkit_trojans.txt - %%OSSEC_HOME%%/etc/shared/system_audit_rcl.txt - %%OSSEC_HOME%%/etc/shared/system_audit_ssh.txt - - - - - - - - /var/ossec/etc/shared/rootkit_files.txt - /var/ossec/etc/shared/rootkit_trojans.txt - /var/ossec/etc/shared/system_audit_rcl.txt - /var/ossec/etc/shared/system_audit_ssh.txt - /var/ossec/etc/shared/cis_debian_linux_rcl.txt - - - diff --git a/security/ossec-hids-local-config/files/template-syscheck-basic.xml.in b/security/ossec-hids-local-config/files/template-syscheck-basic.xml.in new file mode 100644 index 0000000..516b921 --- /dev/null +++ b/security/ossec-hids-local-config/files/template-syscheck-basic.xml.in @@ -0,0 +1,18 @@ + + + + + /bin,/sbin,/usr/bin,/usr/sbin,%%PREFIX%%/bin,%%PREFIX%%/sbin + /etc,%%PREFIX%%/etc + + + + + + + + /bin,/sbin,/usr/bin,/usr/sbin,/usr/local/bin,/usr/local/sbin + /etc,/usr/local/etc + + + diff --git a/security/ossec-hids-local-config/files/template-syscheck-default.xml.in b/security/ossec-hids-local-config/files/template-syscheck-default.xml.in deleted file mode 100644 index 78ae8f8..0000000 --- a/security/ossec-hids-local-config/files/template-syscheck-default.xml.in +++ /dev/null @@ -1,18 +0,0 @@ - - - - - /bin,/sbin,/usr/bin,/usr/sbin,%%PREFIX%%/bin,%%PREFIX%%/sbin - /etc,%%PREFIX%%/etc - - - - - - - - /bin,/sbin,/usr/bin,/usr/sbin,/usr/local/bin,/usr/local/sbin - /etc,/usr/local/etc - - - diff --git a/security/ossec-hids-local-config/files/template-syscheck-hostdeny.xml.in b/security/ossec-hids-local-config/files/template-syscheck-hostdeny.xml.in index f35f4d5..07f278d 100644 --- a/security/ossec-hids-local-config/files/template-syscheck-hostdeny.xml.in +++ b/security/ossec-hids-local-config/files/template-syscheck-hostdeny.xml.in @@ -1,5 +1,5 @@ - + /etc/hosts.allow @@ -7,7 +7,7 @@ - + /etc/hosts.deny diff --git a/security/ossec-hids-local-config/files/template-syscheck-newfiles.xml.in b/security/ossec-hids-local-config/files/template-syscheck-newfiles.xml.in index 7a303e5..eee5915 100644 --- a/security/ossec-hids-local-config/files/template-syscheck-newfiles.xml.in +++ b/security/ossec-hids-local-config/files/template-syscheck-newfiles.xml.in @@ -1,5 +1,5 @@ - + yes @@ -7,7 +7,7 @@ - + yes diff --git a/security/ossec-hids-local-config/files/template-syscheck-noauto.xml.in b/security/ossec-hids-local-config/files/template-syscheck-noauto.xml.in index 03f5943..b71e1ae 100644 --- a/security/ossec-hids-local-config/files/template-syscheck-noauto.xml.in +++ b/security/ossec-hids-local-config/files/template-syscheck-noauto.xml.in @@ -1,5 +1,5 @@ - + no @@ -7,7 +7,7 @@ - + no diff --git a/security/ossec-hids-local-config/files/template-syscheck-ossec.xml.in b/security/ossec-hids-local-config/files/template-syscheck-ossec.xml.in index 8342f63..42911ef 100644 --- a/security/ossec-hids-local-config/files/template-syscheck-ossec.xml.in +++ b/security/ossec-hids-local-config/files/template-syscheck-ossec.xml.in @@ -1,5 +1,5 @@ - + %%OSSEC_SYSCHECK_BIN_DIRS%% @@ -8,7 +8,7 @@ - + /var/ossec/bin,/var/ossec/active-response,/var/ossec/agentless -- cgit v1.2.3