Code Review
/
ta
/
infra-ansible.git
/ blob
commit
grep
author
committer
pickaxe
?
search:
re
9e028358417774381b1a80a983721182bacb1f79
[ta/infra-ansible.git]
/
32-power-abuse.rules.j2
1
## The purpose of this rule is to detect when an admin may be abusing power
2
## by looking in user's home dir.
3
-a always,exit -F dir=/home -F uid=0 -C auid!=obj_uid -F key=admin-abuse