Add host posture checks (roadmap v0.8: posture check)
Add `enodia-sentinel posture check` — a config-hygiene audit that finds the conditions making a host easy to attack, complementing the live detectors. Checks: SSH root/password/empty-password login (Include-aware, first-wins sshd resolution), passwordless and group/world-writable sudoers, world-writable or non-root PATH directories, loose permissions on sensitive files (/etc/shadow, /etc/passwd, ...), and downgraded package-signature policy (reusing pkgdb.siglevel_alert). Findings reuse the Alert type, so they serialize through the existing JSON/triage pipeline (`posture check --json`). Each check is a pure evaluator over injected content/stat facts plus a thin system reader, so the 18 new tests need no root or live /etc. Posture is command-driven and never runs in the daemon loop, per the v0.8 exit criterion. SIDs 100040-100047 (classtype host-posture). Sample config and docs (COMMAND_REFERENCE, OPERATIONS, ROADMAP, SPECIFICATION) updated. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
parent
6ff2087329
commit
9ebc355936
9 changed files with 520 additions and 6 deletions
|
|
@ -155,6 +155,31 @@ Exit code:
|
|||
- `0`: sampled files match and signature policy is not downgraded.
|
||||
- `1`: a signed-package mismatch or insecure signature setting was found.
|
||||
|
||||
### `posture check`
|
||||
|
||||
```bash
|
||||
enodia-sentinel posture check
|
||||
enodia-sentinel posture check --json
|
||||
```
|
||||
|
||||
Audits host configuration hygiene — the conditions that make a host *easy* to
|
||||
attack, as opposed to an attack in progress:
|
||||
|
||||
- SSH: root login, password authentication, and empty-password logins.
|
||||
- sudo: passwordless (`NOPASSWD`) rules, disabled authentication, and
|
||||
group/world-writable sudoers files.
|
||||
- World-writable or non-root-owned `PATH` directories (binary-hijack vectors).
|
||||
- Loose permissions on sensitive files (`/etc/shadow`, `/etc/passwd`, ...).
|
||||
- Downgraded package-signature policy (`SigLevel`).
|
||||
|
||||
Findings are advisory and reuse the standard alert JSON shape (`--json`). This
|
||||
command does not run inside the daemon and never blocks startup.
|
||||
|
||||
Exit code:
|
||||
|
||||
- `0`: no posture findings.
|
||||
- `1`: one or more findings.
|
||||
|
||||
## Evidence and Operator Commands
|
||||
|
||||
### `web`
|
||||
|
|
@ -217,7 +242,6 @@ enodia-sentinel status --json
|
|||
enodia-sentinel incident list
|
||||
enodia-sentinel incident show <incident-id>
|
||||
enodia-sentinel incident export <incident-id>
|
||||
enodia-sentinel posture check
|
||||
enodia-sentinel respond plan <incident-id>
|
||||
enodia-sentinel respond apply <plan-id>
|
||||
```
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue