inspec/test/unit/mock/cmd/auditctl
2015-09-21 14:12:11 +02:00

7 lines
359 B
Text

LIST_RULES: exit,always syscall=rmdir,unlink
LIST_RULES: exit,always auid=1001 (0x3e9) syscall=open
LIST_RULES: exit,always watch=/etc/group perm=wa
LIST_RULES: exit,always watch=/etc/passwd perm=wa
LIST_RULES: exit,always watch=/etc/shadow perm=wa
LIST_RULES: exit,always watch=/etc/sudoers perm=wa
LIST_RULES: exit,always watch=/etc/secret_directory perm=r