inspec/test/unit/mock/cmd/auditctl-legacy

8 lines
359 B
Text
Raw Normal View History

2016-01-28 16:08:41 +00:00
LIST_RULES: exit,always syscall=rmdir,unlink
LIST_RULES: exit,always auid=1001 (0x3e9) syscall=open
LIST_RULES: exit,always watch=/etc/group perm=wa
LIST_RULES: exit,always watch=/etc/passwd perm=wa
LIST_RULES: exit,always watch=/etc/shadow perm=wa
LIST_RULES: exit,always watch=/etc/sudoers perm=wa
LIST_RULES: exit,always watch=/etc/secret_directory perm=r