Ensure discretionary access control permission modification events are collected – b64 setxattr Details Monitor changes to file permissions, attributes, ownership and group. The parameters in this section track changes for system calls...
Ensure DNS Server is not enabled Details The Domain Name System (DNS) is a hierarchical naming system that maps names to IP addresses for computers, services...
Ensure echo services are not enabled Details Disabling this service will reduce the remote attack surface of the system. Solution Comment out or remove any lines...
Ensure /etc/hosts.allow is configured Details The /etc/hosts.allow file supports access control by IP and helps ensure that only authorized systems can connect to the...
Ensure /etc/hosts.deny is configured Details The /etc/hosts.deny file serves as a failsafe so that any host not specified in /etc/hosts.allow is denied access to...
Ensure events that modify date and time information are collected – auditctl b32 adjtimex Details Capture events where the system date and/or time has been modified. The parameters in this section are set to...
Ensure events that modify date and time information are collected – auditctl b32 clock_settime Details Capture events where the system date and/or time has been modified. The parameters in this section are set to...
Ensure events that modify date and time information are collected – auditctl b64 adjtimex Details Capture events where the system date and/or time has been modified. The parameters in this section are set to...
Ensure events that modify date and time information are collected – auditctl b64 clock_settime Details Capture events where the system date and/or time has been modified. The parameters in this section are set to...
Ensure events that modify date and time information are collected – auditctl time-change Details Capture events where the system date and/or time has been modified. The parameters in this section are set to...