Add host posture checks (roadmap v0.8: posture check)
Add `enodia-sentinel posture check` — a config-hygiene audit that finds the conditions making a host easy to attack, complementing the live detectors. Checks: SSH root/password/empty-password login (Include-aware, first-wins sshd resolution), passwordless and group/world-writable sudoers, world-writable or non-root PATH directories, loose permissions on sensitive files (/etc/shadow, /etc/passwd, ...), and downgraded package-signature policy (reusing pkgdb.siglevel_alert). Findings reuse the Alert type, so they serialize through the existing JSON/triage pipeline (`posture check --json`). Each check is a pure evaluator over injected content/stat facts plus a thin system reader, so the 18 new tests need no root or live /etc. Posture is command-driven and never runs in the daemon loop, per the v0.8 exit criterion. SIDs 100040-100047 (classtype host-posture). Sample config and docs (COMMAND_REFERENCE, OPERATIONS, ROADMAP, SPECIFICATION) updated. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
parent
6ff2087329
commit
9ebc355936
9 changed files with 520 additions and 6 deletions
|
|
@ -26,10 +26,11 @@ work that is bigger than single alerts.
|
|||
alert time, process ancestry, sockets, persistence writes, FIM diffs, package
|
||||
transactions, and rootcheck findings.
|
||||
- Add `enodia-sentinel incident list/show/export`.
|
||||
- Add host posture checks:
|
||||
SSH password login, root SSH login, permissive sudoers entries, unexpected
|
||||
enabled services, world-writable PATH components, disabled package signatures,
|
||||
and unsafe systemd unit settings.
|
||||
- ✅ Add host posture checks (`enodia-sentinel posture check`):
|
||||
SSH root/password/empty-password login, passwordless and writable sudoers,
|
||||
world-writable PATH components, loose sensitive-file permissions, and disabled
|
||||
package signatures. Still to come: unexpected enabled services and unsafe
|
||||
systemd unit settings.
|
||||
- Add a machine-readable `status --json` command for automation.
|
||||
- Update the red-team harness so every current detection has a named drill and
|
||||
expected `sid`.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue