✘✘ GRAYBYTE WORDPRESS FILE MANAGER ✘✘

​🇳​​🇦​​🇲​​🇪♯➤ server.blackpussy.asia ​🇻​♯➤ 5.14.0-611.20.1.el9_7.x86_64 #1 SMP 🇾​♯➤ 2026

𝗛𝗢𝗠𝗘 𝗜𝗗 ♯➤ 163.245.207.76 ♯➤ 𝗔𝗗𝗠𝗜𝗡 𝗜𝗗 216.73.216.243
𝗢𝗣𝗧𝗜𝗢𝗡𝗦 ♯ CRL ♯➤ 𝗢𝗞 ┃ WGT ♯➤ 𝗢𝗞 ┃ SDO ♯➤ 𝗢𝗞 ┃ PKEX ♯➤ 𝗢𝗙𝗙
𝗗𝗘𝗔𝗖𝗧𝗜𝗩𝗔𝗧𝗘𝗗 ♯➤ mail,mb_send_mail
𝗖𝗨𝗥𝗥𝗘𝗡𝗧 𝗙𝗜𝗟𝗘 : /usr/share/audit/sample-rules//30-stig.rules
## The purpose of these rules is to meet the stig auditing requirements
## These rules depends on having 10-base-config.rules & 99-finalize.rules
## installed.

## NOTE:
## 1) if this is being used on a 32 bit machine, comment out the b64 lines
## 2) These rules assume that login under the root account is not allowed.
## 3) It is also assumed that 1000 represents the first usable user account. To
##    be sure, look at UID_MIN in /etc/login.defs.
## 4) If these rules generate too much spurious data for your tastes, limit the
##    syscall file rules with a directory, like -F dir=/etc
## 5) You can search for the results on the key fields in the rules
##
##
## (GEN002880: CAT II) The IAO will ensure the auditing software can
## record the following for each audit event: 
##- Date and time of the event 
##- Userid that initiated the event 
##- Type of event 
##- Success or failure of the event 
##- For I&A events, the origin of the request (e.g., terminal ID) 
##- For events that introduce an object into a user’s address space, and
##  for object deletion events, the name of the object, and in MLS
##  systems, the object’s security level.
##
## Things that could affect time
-a always,exit -F arch=b32 -S adjtimex,settimeofday,stime -F key=time-change
-a always,exit -F arch=b64 -S adjtimex,settimeofday -F key=time-change
-a always,exit -F arch=b32 -S clock_settime -F a0=0x0 -F key=time-change
-a always,exit -F arch=b64 -S clock_settime -F a0=0x0 -F key=time-change
# Introduced in 2.6.39, commented out because it can make false positives
#-a always,exit -F arch=b32 -S clock_adjtime -F key=time-change
#-a always,exit -F arch=b64 -S clock_adjtime -F key=time-change
-a always,exit -F arch=b32 -F path=/etc/localtime -F perm=wa -F key=time-change
-a always,exit -F arch=b64 -F path=/etc/localtime -F perm=wa -F key=time-change

## Things that affect identity
-a always,exit -F arch=b32 -F path=/etc/group -F perm=wa -F key=identity
-a always,exit -F arch=b64 -F path=/etc/group -F perm=wa -F key=identity
-a always,exit -F arch=b32 -F path=/etc/passwd -F perm=wa -F key=identity
-a always,exit -F arch=b64 -F path=/etc/passwd -F perm=wa -F key=identity
-a always,exit -F arch=b32 -F path=/etc/gshadow -F perm=wa -F key=identity
-a always,exit -F arch=b64 -F path=/etc/gshadow -F perm=wa -F key=identity
-a always,exit -F arch=b32 -F path=/etc/shadow -F perm=wa -F key=identity
-a always,exit -F arch=b64 -F path=/etc/shadow -F perm=wa -F key=identity
-a always,exit -F arch=b32 -F path=/etc/security/opasswd -F perm=wa -F key=identity
-a always,exit -F arch=b64 -F path=/etc/security/opasswd -F perm=wa -F key=identity

## Things that could affect system locale
-a always,exit -F arch=b32 -S sethostname,setdomainname -F key=system-locale
-a always,exit -F arch=b64 -S sethostname,setdomainname -F key=system-locale
-a always,exit -F arch=b32 -F path=/etc/issue -F perm=wa -F key=system-locale
-a always,exit -F arch=b64 -F path=/etc/issue -F perm=wa -F key=system-locale
-a always,exit -F arch=b32 -F path=/etc/issue.net -F perm=wa -F key=system-locale
-a always,exit -F arch=b64 -F path=/etc/issue.net -F perm=wa -F key=system-locale
-a always,exit -F arch=b32 -F path=/etc/hosts -F perm=wa -F key=system-locale
-a always,exit -F arch=b64 -F path=/etc/hosts -F perm=wa -F key=system-locale
-a always,exit -F arch=b32 -F path=/etc/hostname -F perm=wa -F key=system-locale
-a always,exit -F arch=b64 -F path=/etc/hostname -F perm=wa -F key=system-locale
-a always,exit -F arch=b32 -F dir=/etc/NetworkManager/ -F perm=wa -F key=system-locale
-a always,exit -F arch=b64 -F dir=/etc/NetworkManager/ -F perm=wa -F key=system-locale

## Things that could affect MAC policy
-a always,exit -F arch=b32 -F dir=/etc/selinux/ -F perm=wa -F key=MAC-policy
-a always,exit -F arch=b64 -F dir=/etc/selinux/ -F perm=wa -F key=MAC-policy


## (GEN002900: CAT III) The IAO will ensure audit files are retained at
## least one year; systems containing SAMI will be retained for five years.
##
## Site action - no action in config files

## (GEN002920: CAT III) The IAO will ensure audit files are backed up
## no less than weekly onto a different system than the system being
## audited or backup media.  
##
## Can be done with cron script

## (GEN002700: CAT I) (Previously – G095) The SA will ensure audit data
## files have permissions of 640, or more restrictive.
##
## Done automatically by auditd

## (GEN002720-GEN002840: CAT II) (Previously – G100-G106) The SA will
## configure the auditing system to audit the following events for all
## users and root:
##
## - Logon (unsuccessful and successful) and logout (successful)
##
## Handled by pam, sshd, login, and gdm
## Might also want to watch these files if needing extra information
#-a always,exit -F arch=b32 -F path=/var/log/tallylog -F perm=wa -F key=logins
#-a always,exit -F arch=b64 -F path=/var/log/tallylog -F perm=wa -F key=logins
#-a always,exit -F arch=b32 -F path=/var/run/faillock -F perm=wa -F key=logins
#-a always,exit -F arch=b64 -F path=/var/run/faillock -F perm=wa -F key=logins
#-a always,exit -F arch=b32 -F path=/var/log/lastlog -F perm=wa -F key=logins
#-a always,exit -F arch=b64 -F path=/var/log/lastlog -F perm=wa -F key=logins


##- Process and session initiation (unsuccessful and successful)
##
## The session initiation is audited by pam without any rules needed.
## Might also want to watch this file if needing extra information
#-a always,exit -F arch=b32 -F path=/var/run/utmp -F perm=wa -F key=session
#-a always,exit -F arch=b64 -F path=/var/run/utmp -F perm=wa -F key=session
#-a always,exit -F arch=b32 -F path=/var/log/btmp -F perm=wa -F key=session
#-a always,exit -F arch=b64 -F path=/var/log/btmp -F perm=wa -F key=session
#-a always,exit -F arch=b32 -F path=/var/log/wtmp -F perm=wa -F key=session
#-a always,exit -F arch=b64 -F path=/var/log/wtmp -F perm=wa -F key=session

##- Discretionary access control permission modification (unsuccessful
## and successful use of chown/chmod)
-a always,exit -F arch=b32 -S chmod,fchmod,fchmodat -F auid>=1000 -F auid!=unset -F key=perm_mod
-a always,exit -F arch=b64 -S chmod,fchmod,fchmodat -F auid>=1000 -F auid!=unset -F key=perm_mod
-a always,exit -F arch=b32 -S lchown,fchown,chown,fchownat -F auid>=1000 -F auid!=unset -F key=perm_mod
-a always,exit -F arch=b64 -S chown,fchown,lchown,fchownat -F auid>=1000 -F auid!=unset -F key=perm_mod
-a always,exit -F arch=b32 -S setxattr,lsetxattr,fsetxattr,removexattr,lremovexattr,fremovexattr -F auid>=1000 -F auid!=unset -F key=perm_mod
-a always,exit -F arch=b64 -S setxattr,lsetxattr,fsetxattr,removexattr,lremovexattr,fremovexattr -F auid>=1000 -F auid!=unset -F key=perm_mod

##- Unauthorized access attempts to files (unsuccessful) 
-a always,exit -F arch=b32 -S open,creat,truncate,ftruncate,openat,openat2,open_by_handle_at -F exit=-EACCES -F auid>=1000 -F auid!=unset -F key=access
-a always,exit -F arch=b32 -S open,creat,truncate,ftruncate,openat,openat2,open_by_handle_at -F exit=-EPERM -F auid>=1000 -F auid!=unset -F key=access
-a always,exit -F arch=b64 -S open,truncate,ftruncate,creat,openat,openat2,open_by_handle_at -F exit=-EACCES -F auid>=1000 -F auid!=unset -F key=access
-a always,exit -F arch=b64 -S open,truncate,ftruncate,creat,openat,openat2,open_by_handle_at -F exit=-EPERM -F auid>=1000 -F auid!=unset -F key=access

##- Use of print command (unsuccessful and successful) 

##- Export to media (successful)
## You have to mount media before using it. You must disable all automounting
## so that its done manually in order to get the correct user requesting the
## export
-a always,exit -F arch=b32 -S mount -F auid>=1000 -F auid!=unset -F key=export
-a always,exit -F arch=b64 -S mount -F auid>=1000 -F auid!=unset -F key=export

##- System startup and shutdown (unsuccessful and successful)

##- Files and programs deleted by the user (successful and unsuccessful)
-a always,exit -F arch=b32 -S unlink,unlinkat,rename,renameat -F auid>=1000 -F auid!=unset -F key=delete
-a always,exit -F arch=b64 -S unlink,unlinkat,rename,renameat -F auid>=1000 -F auid!=unset -F key=delete

##- All system administration actions 
##- All security personnel actions
## 
## Look for pam_tty_audit and add it to your login entry point's pam configs.
## If that is not found, use sudo which should be patched to record its
## commands to the audit system. Do not allow unrestricted root shells or
## sudo cannot record the action.
-a always,exit -F arch=b32 -F path=/etc/sudoers -F perm=wa -F key=actions
-a always,exit -F arch=b64 -F path=/etc/sudoers -F perm=wa -F key=actions
-a always,exit -F arch=b32 -F dir=/etc/sudoers.d/ -F perm=wa -F key=actions
-a always,exit -F arch=b64 -F dir=/etc/sudoers.d/ -F perm=wa -F key=actions

## Special case for systemd-run. It is not audit aware, specifically watch it
-a always,exit -F arch=b32 -F path=/usr/bin/systemd-run -F perm=x -F auid!=unset -F key=maybe-escalation
-a always,exit -F arch=b64 -F path=/usr/bin/systemd-run -F perm=x -F auid!=unset -F key=maybe-escalation
## Special case for pkexec. It is not audit aware, specifically watch it
-a always,exit -F arch=b32 -F path=/usr/bin/pkexec -F perm=x -F key=maybe-escalation
-a always,exit -F arch=b64 -F path=/usr/bin/pkexec -F perm=x -F key=maybe-escalation

## (GEN002860: CAT II) (Previously – G674) The SA and/or IAO will
##ensure old audit logs are closed and new audit logs are started daily.
##
## Site action. Can be assisted by a cron job


Current_dir [ 𝗡𝗢𝗧 𝗪𝗥𝗜𝗧𝗘𝗔𝗕𝗟𝗘 ] Document_root [ 𝗪𝗥𝗜𝗧𝗘𝗔𝗕𝗟𝗘 ]

Current_dir [ 𝗡𝗢𝗧 𝗪𝗥𝗜𝗧𝗘𝗔𝗕𝗟𝗘 ] Document_root [ 𝗪𝗥𝗜𝗧𝗘𝗔𝗕𝗟𝗘 ]


[ Back ]
𝗡𝗔𝗠𝗘
𝗦𝗜𝗭𝗘
𝗟𝗔𝗦𝗧 𝗧𝗢𝗨𝗖𝗛
𝗨𝗦𝗘𝗥
𝗦𝗧𝗔𝗧𝗨𝗦
𝗙𝗨𝗡𝗖𝗧𝗜𝗢𝗡𝗦
..
--
4 Apr 2026 8.12 PM
root / root
0755
10-base-config.rules
0.238 KB
4 Apr 2026 8.12 PM
root / root
0644
10-no-audit.rules
0.277 KB
4 Apr 2026 8.12 PM
root / root
0644
11-loginuid.rules
0.091 KB
4 Apr 2026 8.12 PM
root / root
0644
12-cont-fail.rules
0.325 KB
4 Apr 2026 8.12 PM
root / root
0644
12-ignore-error.rules
0.319 KB
4 Apr 2026 8.12 PM
root / root
0644
20-dont-audit.rules
0.504 KB
4 Apr 2026 8.12 PM
root / root
0644
21-no32bit.rules
0.267 KB
4 Apr 2026 8.12 PM
root / root
0644
22-ignore-chrony.rules
0.248 KB
4 Apr 2026 8.12 PM
root / root
0644
23-ignore-filesystems.rules
0.495 KB
4 Apr 2026 8.12 PM
root / root
0644
30-nispom.rules
4.827 KB
4 Apr 2026 8.12 PM
root / root
0644
30-ospp-v42-1-create-failed.rules
1.465 KB
4 Apr 2026 8.12 PM
root / root
0644
30-ospp-v42-1-create-success.rules
0.729 KB
4 Apr 2026 8.12 PM
root / root
0644
30-ospp-v42-2-modify-failed.rules
1.607 KB
4 Apr 2026 8.12 PM
root / root
0644
30-ospp-v42-2-modify-success.rules
0.807 KB
4 Apr 2026 8.12 PM
root / root
0644
30-ospp-v42-3-access-failed.rules
0.61 KB
4 Apr 2026 8.12 PM
root / root
0644
30-ospp-v42-3-access-success.rules
0.39 KB
4 Apr 2026 8.12 PM
root / root
0644
30-ospp-v42-4-delete-failed.rules
0.549 KB
4 Apr 2026 8.12 PM
root / root
0644
30-ospp-v42-4-delete-success.rules
0.277 KB
4 Apr 2026 8.12 PM
root / root
0644
30-ospp-v42-5-perm-change-failed.rules
0.797 KB
4 Apr 2026 8.12 PM
root / root
0644
30-ospp-v42-5-perm-change-success.rules
0.404 KB
4 Apr 2026 8.12 PM
root / root
0644
30-ospp-v42-6-owner-change-failed.rules
0.565 KB
4 Apr 2026 8.12 PM
root / root
0644
30-ospp-v42-6-owner-change-success.rules
0.288 KB
4 Apr 2026 8.12 PM
root / root
0644
30-ospp-v42.rules
9.099 KB
4 Apr 2026 8.12 PM
root / root
0644
30-pci-dss-v31.rules
8.184 KB
4 Apr 2026 8.12 PM
root / root
0644
30-stig.rules
9.251 KB
4 Apr 2026 8.12 PM
root / root
0644
31-privileged.rules
1.562 KB
4 Apr 2026 8.12 PM
root / root
0644
32-power-abuse.rules
0.208 KB
4 Apr 2026 8.12 PM
root / root
0644
40-local.rules
0.176 KB
4 Apr 2026 8.12 PM
root / root
0644
41-containers.rules
0.429 KB
4 Apr 2026 8.12 PM
root / root
0644
42-injection.rules
0.656 KB
4 Apr 2026 8.12 PM
root / root
0644
43-module-load.rules
0.389 KB
4 Apr 2026 8.12 PM
root / root
0644
44-installers.rules
1.234 KB
4 Apr 2026 8.12 PM
root / root
0644
70-einval.rules
0.318 KB
4 Apr 2026 8.12 PM
root / root
0644
71-networking.rules
0.147 KB
4 Apr 2026 8.12 PM
root / root
0644
99-finalize.rules
0.084 KB
4 Apr 2026 8.12 PM
root / root
0644
README-rules
1.388 KB
4 Apr 2026 8.12 PM
root / root
0644

✘✘ GRAYBYTE WORDPRESS FILE MANAGER @ 2026 CONTACT ME ✘✘
Static GIF Static GIF