Summary
- Total Checks: 98
- Positive Checks: 25
- Penalties: 72
- Maximum Possible Points: 100
Forensics Questions
Question 1
File Path: /home/benjamin/Desktop/Forensics Question 1.txt
Content:
What is the very first message that is displayed to clients
as soon as they connect to the FTP server (before logging in)?
( EXAMPLE: 220 Hello World )
ANSWER: <Type Answer Here>
Question 2
File Path: /home/benjamin/Desktop/Forensics Question 2.txt
Content:
The ftpusers file is a list of usernames not allowed to log in via FTP, even
if they're valid system users. Two users have reported issues logging into
the FTP server, and you suspect they were mistakenly added to ftpusers.
Which two users have been prevented from logging onto the FTP server?
( EXAMPLE: llitt )
ANSWER: <Type Answer Here>
ANSWER: <Type Answer Here>
Category: Account policy (F) (ACT)
✅ A minimum password length is required +4
Specific Conditions:
/etc/pam.d/common-passwordhas Exists equal totrue- Data of
/etc/pam.d/common-passwordmatches pattern(?i)^\s*password[^\n]*pam_unix.so[^\n]*minlen=0*[1-9]+[0-9]* -
OR
/etc/pam.d/common-passwordhas Exists equal totrue- Data of
/etc/pam.d/common-passwordmatches pattern(?i)^\s*password[^\n]*pam_unix.so - Data of
/etc/pam.d/common-passwordmatches pattern(?i)^\s*password[^\n]*pam_cracklib.so[^\n]*minlen=0*[1-9]+[0-9]* -
OR
/etc/pam.d/common-passwordhas Exists equal totrue- Data of
/etc/pam.d/common-passwordmatches pattern(?i)^\s*password[^\n]*pam_unix.so - Data of
/etc/pam.d/common-passwordmatches pattern(?i)^\s*password[^\n]*pam_pwquality.so[^\n]*minlen=0*[1-9]+[0-9]* -
OR
-
OR
/usr/lib/i386-linux-gnu/security/pam_cracklib.sohas Exists equal totrue-
OR
-
OR
-
OR
/usr/lib/x86_64-linux-gnu/security/pam_cracklib.sohas Exists equal totrue-
OR
-
OR
-
OR
-
OR
/usr/lib/i386-linux-gnu/security/pam_pwquality.sohas Exists equal totrue-
OR
-
OR
-
OR
/usr/lib/x86_64-linux-gnu/security/pam_pwquality.sohas Exists equal totrue
ID: PWMINL
Category: Application security (F) (APP)
✅ FTP users may log in with SSL +5
Specific Conditions:
/etc/vsftpd.confhas Exists equal totrue- Data of
/etc/vsftpd.confmatches pattern^\s*local_root\s*=\s*/srv/afa - Data of
/etc/vsftpd.confmatches pattern^\s*ssl_enable\s*=\s*(?i)(YES|TRUE|1)
ID: FTP_SSL
Category: Application update (F) (AUP)
✅ Chromium has been updated +4
Specific Conditions:
/usr/lib/chromium/chromiumhas Exists equal totrue/usr/lib/chromium/chromiumhas Signature equal to0:7f454c4602/usr/lib/chromium/chromiumhas BuildID not equal to6e1c92650f83897b300dc129c4069914dbccf83a
ID: CHRM
✅ Vsftpd has been updated +4
Specific Conditions:
/usr/sbin/vsftpdhas Exists equal totrue/usr/sbin/vsftpdhas Signature equal to0:7f454c4602/usr/sbin/vsftpdhas BuildID not equal tofc5dd07368a19c9258b75efa395e200b4b862e74
ID: VSFTP
Category: Defensive countermeasure (F) (DEF)
✅ Uncomplicated Firewall (UFW) protection has been enabled +5
Specific Conditions:
- Output of
nft-n list rulesetexists - Output of
nft-n list rulesetmatches pattern^\s*chain\s+INPUT - Output of
nft-n list rulesetmatches pattern^\s*chain\s+OUTPUT - Output of
nft-n list rulesetexists - Output of
nft-n list rulesetmatches pattern^\s*chain\s+INPUT - Output of
nft-n list rulesetmatches pattern^\s*chain\s+OUTPUT - Output of
nft-n list rulesetexists - Output of
nft-n list rulesetmatches pattern^\s*chain\s+INPUT - Output of
nft-n list rulesetmatches pattern^\s*chain\s+OUTPUT -
OR
/etc/ufw/ufw.confhas Exists equal totrue- Data of
/etc/ufw/ufw.confmatches pattern(?i)^\s*ENABLED="?yes"?
ID: FWALL
Category: Prohibited file (F) (FIL)
✅ Prohibited MP3 files are removed +4
Specific Conditions:
/srv/afa/01-01- Ocean Motion.mp3has Exists equal tofalse-
OR
/srv/afa/01-04- Tinker Bells Dream.mp3has Exists equal tofalse-
OR
/srv/afa/01-07- Last Thoughts.mp3has Exists equal tofalse-
OR
/srv/afa/has Exists equal totrue
ID: MP3
Category: Forensic Question (F) (FOR)
✅ Forensics Question 1 correct +6
Specific Conditions:
- Data of
/home/benjamin/Desktop/Forensics Question 1.txtmatches pattern(?i)^\s*[A-Z]{6}:\s*(?:220\s+)?Welcome\sto\sAFA(?:\s|$)
ID: Q1
✅ Forensics Question 2 correct +6
Specific Conditions:
- Data of
/home/benjamin/Desktop/Forensics Question 2.txtmatches pattern(?i)^\s*[A-Z]{6}:\s*rzane(?:\s|$) - Data of
/home/benjamin/Desktop/Forensics Question 2.txtmatches pattern(?i)^\s*[A-Z]{6}:\s*shuntley(?:\s|$)
ID: Q2
Category: Operating system update (F) (OUP)
✅ The system refreshes the list of updates automatically +4
Specific Conditions:
- Output of
/usr/bin/su-l -s /bin/bash -c /usr/bin/dconf dump /com/linuxmint/ benjaminmatches patternrefresh-schedule-enabled=true
ID: DAILY_MNT
✅ The update manager installs updates automatically +4
Specific Conditions:
/var/lib/linuxmint/mintupdate-automatic-upgrades-enabledhas Exists equal totrue
ID: AUTO_MNT
✅ Install updates from important security updates +4
Specific Conditions:
/etc/apt/sources.listhas Exists equal totrue- Data of
/etc/apt/sources.listmatches pattern^\s*deb\s+https?://[^/]+.ubuntu.com/ubuntu/?\s+[^\s]+-security\s+(?:[^\n]+\s+)?main
ID: SEC_UBU
✅ Systemd has been updated +4
Specific Conditions:
/usr/lib/systemd/systemdhas Exists equal totrue/usr/lib/systemd/systemdhas Signature equal to0:7f454c4602/usr/lib/systemd/systemdhas BuildID not equal toef2b0a29855b95866e8343e4af5edbcd2b7fc6c6
ID: SYSD
Category: Penalty (F) (PEN)
➖ WARNING: VirtualBox is unsupported 0
Specific Conditions:
- Data of
/proc/bus/input/devicesmatches patternVirtualBox -
OR
- Data of
/sys/devices/virtual/dmi/id/product_namematches patternVirtualBox -
OR
- Data of
/sys/devices/virtual/dmi/id/bios_versionmatches patternVirtualBox -
OR
- Data of
/sys/devices/virtual/dmi/id/board_namematches patternVirtualBox
ID: VBX
❌ VSFTP service has been stopped or removed -5
Specific Conditions:
- Process
/vsftpddoes not exists -
OR
-
OR
-
OR
/usr/sbin/vsftpdhas Exists equal tofalse
ID: SRV_VSFTPD
❌ Chromium has been removed -5
Specific Conditions:
/usr/lib/chromium/chromiumhas Exists not equal totrue
ID: SFT_CHRM
❌ Missing or corrupt FTP configuration -5
Specific Conditions:
/etc/vsftpd.confhas Exists equal totrue- Data of
/etc/vsftpd.confdoes not match pattern^\s*local_root\s*=\s*/srv/afa -
OR
/etc/vsftpd.confhas Exists equal totrue- Data of
/etc/vsftpd.confmatches pattern^\s*anonymous_enable\s*=\s*YES - Data of
/etc/vsftpd.confdoes not match pattern^\s*local_enable\s*=\s* -
OR
/etc/vsftpd.confhas Exists equal totrue- Data of
/etc/vsftpd.confmatches pattern^\s*anonymous_enable\s*=\s*YES - Data of
/etc/vsftpd.confmatches pattern^\s*local_enable\s*=\s*NO
ID: CFG_VSFTPD
❌ Removed one or more authorized administrators -5
Specific Conditions:
- Data of
/etc/groupdoes not match pattern(?i)^(?:sudo|wheel):[^\n]*[:,]benjamin(?:,|$) -
OR
-
OR
-
OR
benjaminhas Exists equal tofalse-
OR
-
OR
jpearsonhas Exists equal tofalse-
OR
-
OR
hspecterhas Exists equal tofalse-
OR
-
OR
llitthas Exists equal tofalse
ID: USRA
❌ Removed one or more authorized users -5
Specific Conditions:
dscotthas Exists equal tofalse-
OR
nnesbitthas Exists equal tofalse-
OR
pporterhas Exists equal tofalse-
OR
kbennetthas Exists equal tofalse-
OR
mrosshas Exists equal tofalse-
OR
rzanehas Exists equal tofalse-
OR
dpaulsenhas Exists equal tofalse-
OR
shuntleyhas Exists equal tofalse-
OR
jpomavillehas Exists equal tofalse-
OR
sbandaruhas Exists equal tofalse-
OR
sthomashas Exists equal tofalse
ID: USRS
❌ Removed one or more authorized user directories -5
Specific Conditions:
/home/benjaminhas Exists equal tofalse-
OR
/home/jpearsonhas Exists equal tofalse-
OR
/home/hspecterhas Exists equal tofalse-
OR
/home/llitthas Exists equal tofalse-
OR
/home/dscotthas Exists equal tofalse-
OR
/home/nnesbitthas Exists equal tofalse-
OR
/home/pporterhas Exists equal tofalse-
OR
/home/kbennetthas Exists equal tofalse-
OR
/home/mrosshas Exists equal tofalse-
OR
/home/rzanehas Exists equal tofalse-
OR
/home/dpaulsenhas Exists equal tofalse-
OR
/home/shuntleyhas Exists equal tofalse-
OR
/home/jpomavillehas Exists equal tofalse-
OR
/home/sbandaruhas Exists equal tofalse-
OR
/home/sthomashas Exists equal tofalse
ID: USRD
Category: Local policy (F) (POL)
✅ IPv4 TCP SYN cookies have been enabled +4
Specific Conditions:
/proc/sys/net/ipv4/tcp_syncookieshas Exists equal totrue- Data of
/proc/sys/net/ipv4/tcp_syncookiesmatches pattern1
ID: PRC_SYNC
Category: Penalty (F) (SCR)
❌ Removed multiple authorized user directories -2
Specific Conditions:
/home/benjaminhas Exists equal tofalse-
OR
/home/jpearsonhas Exists equal tofalse-
OR
/home/hspecterhas Exists equal tofalse-
OR
/home/llitthas Exists equal tofalse-
OR
/home/dscotthas Exists equal tofalse-
OR
/home/nnesbitthas Exists equal tofalse-
OR
/home/pporterhas Exists equal tofalse-
OR
/home/kbennetthas Exists equal tofalse-
OR
/home/mrosshas Exists equal tofalse-
OR
/home/rzanehas Exists equal tofalse-
OR
/home/dpaulsenhas Exists equal tofalse-
OR
/home/shuntleyhas Exists equal tofalse-
OR
/home/jpomavillehas Exists equal tofalse-
OR
/home/sbandaruhas Exists equal tofalse-
OR
/home/sthomashas Exists equal tofalse
ID: SCRD
❌ Removed multiple authorized users -6
Specific Conditions:
dscotthas Exists equal tofalse-
OR
nnesbitthas Exists equal tofalse-
OR
pporterhas Exists equal tofalse-
OR
kbennetthas Exists equal tofalse-
OR
mrosshas Exists equal tofalse-
OR
rzanehas Exists equal tofalse-
OR
dpaulsenhas Exists equal tofalse-
OR
shuntleyhas Exists equal tofalse-
OR
jpomavillehas Exists equal tofalse-
OR
sbandaruhas Exists equal tofalse-
OR
sthomashas Exists equal tofalse-
OR
benjaminhas Exists equal tofalse-
OR
jpearsonhas Exists equal tofalse-
OR
hspecterhas Exists equal tofalse-
OR
llitthas Exists equal tofalse
ID: SCRU
Category: Unwanted software (F) (SFT)
✅ Prohibited software aMule removed +4
Specific Conditions:
/usr/bin/amulehas Exists equal tofalse-
OR
/usr/has Exists equal totrue
ID: AMUL
✅ Prohibited software Wireshark removed +4
Specific Conditions:
/usr/bin/wiresharkhas Exists equal tofalse-
OR
/usr/bin/has Exists equal totrue
ID: WIRE
✅ Prohibited software Zangband removed +4
Specific Conditions:
/usr/games/zangbandhas Exists equal tofalse-
OR
/usr/has Exists equal totrue
ID: ZANG
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
/usr/sbin/lvmsadchas Exists equal totrue-
OR
/usr/sbinhas Exists equal tofalse
ID: CMWS
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
/usr/bin/xscreensaver-getimagehas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: USSV
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
/usr/bin/ppmtorgb3has Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: JCRZ
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
/bin/pinentryhas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: FMJZ
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
/bin/foomatic-riphas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: YXWW
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
/usr/bin/hcitoolhas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: FJBQ
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
/sbin/deluserhas Exists equal totrue-
OR
/sbinhas Exists equal tofalse
ID: SMVG
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
/usr/bin/grub-script-checkhas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: DGKV
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
/sbin/ebtables-nfthas Exists equal totrue-
OR
/sbinhas Exists equal tofalse
ID: RWDZ
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
/bin/ranlibhas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: XXBJ
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
/usr/sbin/zvol_waithas Exists equal totrue-
OR
/usr/sbinhas Exists equal tofalse
ID: JVFH
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
/usr/bin/spa-inspecthas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: BHGF
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
/usr/bin/sensible-pagerhas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: NNIJ
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
/bin/udevadmhas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: JBIH
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
/usr/bin/grub-mkimagehas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: FTKQ
❌ Performed an unspecified action on the filesystem -3
Specific Conditions:
/bin/cmuwmtopbmhas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: MTEW
❌ Performed an unspecified action on the filesystem -3
Specific Conditions:
/bin/aptitudehas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: PUYR
❌ Performed an unspecified action on the filesystem -3
Specific Conditions:
/bin/commhas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: WJUO
❌ Performed an unspecified action on the filesystem -3
Specific Conditions:
/usr/sbin/vgremovehas Exists equal totrue-
OR
/usr/sbinhas Exists equal tofalse
ID: CEYO
❌ Performed an unspecified action on the filesystem -3
Specific Conditions:
/bin/Xhas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: IGAG
❌ Performed an unspecified action on the filesystem -3
Specific Conditions:
/usr/bin/vmware-rpctoolhas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: UQVL
❌ Performed an unspecified action on the filesystem -3
Specific Conditions:
/sbin/jfs_debugfshas Exists equal totrue-
OR
/sbinhas Exists equal tofalse
ID: DOZN
❌ Performed an unspecified action on the filesystem -3
Specific Conditions:
/usr/bin/picohas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: KKDH
❌ Performed an unspecified action on the filesystem -3
Specific Conditions:
/usr/bin/pdffontshas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: GLNL
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
/usr/bin/xvminitoppmhas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: YMSQ
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
/usr/bin/lphas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: FFTJ
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
/bin/aa-features-abihas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: RJCB
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
/bin/ld.bfdhas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: ZHRW
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
/usr/sbin/mount.ntfs-3ghas Exists equal totrue-
OR
/usr/sbinhas Exists equal tofalse
ID: RSYM
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
/bin/bzfgrephas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: PZBJ
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
/usr/sbin/ebtables-nfthas Exists equal totrue-
OR
/usr/sbinhas Exists equal tofalse
ID: YENW
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
/bin/t1asciihas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: FERB
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
/usr/bin/scanimagehas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: VLPF
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
/usr/sbin/vpddecodehas Exists equal totrue-
OR
/usr/sbinhas Exists equal tofalse
ID: QFCA
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
/usr/sbin/ModemManagerhas Exists equal totrue-
OR
/usr/sbinhas Exists equal tofalse
ID: HOSA
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
/usr/bin/rvimhas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: EOMI
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
/bin/ppmtopi1has Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: ITCM
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
/usr/bin/foo2lavahas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: DNIN
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
/bin/sdptoolhas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: XLLV
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
/usr/bin/mdeltreehas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: KXJO
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
/bin/lziphas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: USXC
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
/bin/gemtopbmhas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: ATCY
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
/usr/bin/factorhas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: HATB
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
/bin/xfdhas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: XDRB
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
/bin/morehas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: KJMR
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
/usr/bin/sbigtopgmhas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: VQYF
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
/bin/luithas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: DOCW
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
/bin/apthas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: ANMI
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
/bin/ntfslshas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: FKFW
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
/usr/bin/es2gears_waylandhas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: XWAK
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
/bin/libnetcfghas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: PUUB
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
/bin/pngtopnmhas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: EZYC
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
/usr/bin/gemtopnmhas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: KONS
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
/usr/bin/ppmbrightenhas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: PYAO
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
/usr/bin/oakdecodehas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: IMWB
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
/bin/pnmcathas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: CBHX
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
/etc/nftables.confhas Exists equal totrue-
OR
/etchas Exists equal tofalse
ID: ZHMV
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
/bin/capinfoshas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: ZJUU
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
/usr/bin/mint-refresh-cachehas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: ORCB
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
/usr/bin/rnanohas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: QXUC
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
/bin/gcc-arhas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: ZGOQ
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
/sbin/killall5has Exists equal totrue-
OR
/sbinhas Exists equal tofalse
ID: SENA
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
/usr/bin/dfhas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: QYZE
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
/bin/glxdemohas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: XJQL
Category: Service auditing (F) (SRV)
✅ OpenSSH service is disabled or removed +4
Specific Conditions:
- Process
/sshddoes not exists -
OR
-
OR
-
OR
/usr/sbin/sshdhas Exists equal tofalse
ID: SSHD
Category: Uncategorized operating system setting (F) (SYS)
✅ Insecure permissions on FTP root directory fixed +5
Specific Conditions:
/srv/afa/has Exists equal totrue/srv/afa/has others_write equal tofalse
ID: FTP_PERM
Category: User auditing (F) (USR)
✅ Guest account is disabled +3
Specific Conditions:
/etc/lightdm/lightdm.confhas Exists equal totrue- Data of
/etc/lightdm/lightdm.confmatches pattern(?i)^\s*\[Seat(Defaults|:\*)\] - Data of
/etc/lightdm/lightdm.confmatches pattern(?i)^\s*allow-guest\s*=\s*false -
OR
-
OR
ID: GST
✅ Removed unauthorized user tgianopolous +3
Specific Conditions:
tgianopoloushas Exists equal tofalse
ID: TGIA
✅ Removed unauthorized user jquelling +3
Specific Conditions:
jquellinghas Exists equal tofalse
ID: JQUE
✅ User dscott is not an administrator +3
Specific Conditions:
dscotthas Exists equal totrue-
OR
/etc/grouphas Exists equal totrue- Data of
/etc/groupmatches patternsudo: - Data of
/etc/groupdoes not match pattern(?i)^sudo:[^\n]*[:,]dscott
ID: DSCO
✅ Changed insecure password for user llitt +3
Specific Conditions:
llitthas Exists equal totruellitthas Password not equal tougotlittup
ID: LLIT
✅ Created new administrator account for edarby +3
Specific Conditions:
edarbyhas Exists equal totrue-
OR
/etc/grouphas Exists equal totrue- Data of
/etc/groupmatches patternsudo: - Data of
/etc/groupmatches pattern(?i)^sudo:([^\n]*,)?edarby
ID: EDAR
✅ User edarby must change password at next login +3
Specific Conditions:
edarbyhas Exists equal totrue-
OR
/etc/shadowhas Exists equal totrue- Data of
/etc/shadowmatches pattern(?i)^edarby:[^\n:]+:0: