--- {{ if .Vars.ubtu24cis_level_2 }} {{ if .Vars.ubtu24cis_rule_6_2_3_2 }} command: auditd_sudo_actions: title: 6.2.3.2 | Ensure actions as another user are always logged | Config exec: grep user_emulation /etc/audit/rules.d/*.rules exit-status: 0 stdout: - '/.*:-a always,exit -F arch=b64 -C euid!=uid -F auid!=(unset|4294967295|-1) -S execve -k user_emulation/' - '/.*:-a always,exit -F arch=b32 -C euid!=uid -F auid!=(unset|4294967295|-1) -S execve -k user_emulation/' meta: server: 2 workstation: 2 CIS_ID: - 6.2.3.2 CISv8: - 8.5 CISv8_IG1: true CISv8_IG2: true CISv8_IG3: true NIST800-53R5: - AU-3 auditd_sudo_actions_live: title: 6.2.3.2 | Ensure actions as another user are always logged | Live exec: auditctl -l | grep user_emulation exit-status: 0 stdout: - '/-a always,exit -F arch=b64 -S execve -C uid!=euid -F auid!=(unset|4294967295|-1) -F key=user_emulation/' - '/-a always,exit -F arch=b32 -S execve -C uid!=euid -F auid!=(unset|4294967295|-1) -F key=user_emulation/' meta: server: 2 workstation: 2 CIS_ID: - 6.2.3.2 CISv8: - 8.5 CISv8_IG1: true CISv8_IG2: true CISv8_IG3: true NIST800-53R5: - AU-3 {{ end }} {{ end }}