7f16b2fac1
Approved by: swills (mentor) MFH: 2015Q2 Security: c470db07-1098-11e5-b6a8-002590263bf5
170 lines
5.5 KiB
Text
170 lines
5.5 KiB
Text
%%PORTNAME%%/active-response/bin/disable-account.sh
|
|
%%PORTNAME%%/active-response/bin/firewall-drop.sh
|
|
%%PORTNAME%%/active-response/bin/host-deny.sh
|
|
%%PORTNAME%%/active-response/bin/ip-customblock.sh
|
|
%%PORTNAME%%/active-response/bin/ipfw_mac.sh
|
|
%%PORTNAME%%/active-response/bin/ipfw.sh
|
|
%%PORTNAME%%/active-response/bin/ossec-tweeter.sh
|
|
%%PORTNAME%%/active-response/bin/pf.sh
|
|
%%PORTNAME%%/active-response/bin/restart-ossec.sh
|
|
%%PORTNAME%%/active-response/bin/route-null.sh
|
|
%%PORTNAME%%/bin/agent_control
|
|
%%PORTNAME%%/bin/clear_stats
|
|
%%PORTNAME%%/bin/list_agents
|
|
%%PORTNAME%%/bin/manage_agents
|
|
%%PORTNAME%%/bin/ossec-agentlessd
|
|
%%PORTNAME%%/bin/ossec-analysisd
|
|
%%PORTNAME%%/bin/ossec-authd
|
|
%%PORTNAME%%/bin/ossec-control
|
|
%%PORTNAME%%/bin/ossec-csyslogd
|
|
%%PORTNAME%%/bin/ossec-dbd
|
|
%%PORTNAME%%/bin/ossec-execd
|
|
%%PORTNAME%%/bin/ossec-logcollector
|
|
%%PORTNAME%%/bin/ossec-logtest
|
|
%%PORTNAME%%/bin/ossec-lua
|
|
%%PORTNAME%%/bin/ossec-luac
|
|
%%PORTNAME%%/bin/ossec-maild
|
|
%%PORTNAME%%/bin/ossec-makelists
|
|
%%PORTNAME%%/bin/ossec-monitord
|
|
%%PORTNAME%%/bin/ossec-regex
|
|
%%PORTNAME%%/bin/ossec-remoted
|
|
%%PORTNAME%%/bin/ossec-reportd
|
|
%%PORTNAME%%/bin/ossec-syscheckd
|
|
%%PORTNAME%%/bin/rootcheck_control
|
|
%%PORTNAME%%/bin/syscheck_control
|
|
%%PORTNAME%%/bin/syscheck_update
|
|
%%PORTNAME%%/bin/util.sh
|
|
%%PORTNAME%%/bin/verify-agent-conf
|
|
@group ossec
|
|
%%PORTNAME%%/etc/decoder.xml
|
|
%%PORTNAME%%/etc/internal_options.conf
|
|
@sample %%PORTNAME%%/etc/ossec.conf.sample
|
|
%%PORTNAME%%/etc/shared/rootkit_files.txt
|
|
%%PORTNAME%%/etc/shared/rootkit_trojans.txt
|
|
%%PORTNAME%%/etc/shared/system_audit_rcl.txt
|
|
%%PORTNAME%%/etc/shared/win_applications_rcl.txt
|
|
%%PORTNAME%%/etc/shared/win_audit_rcl.txt
|
|
%%PORTNAME%%/etc/shared/win_malware_rcl.txt
|
|
%%PORTNAME%%/etc/shared/cis_debian_linux_rcl.txt
|
|
%%PORTNAME%%/etc/shared/cis_rhel_linux_rcl.txt
|
|
%%PORTNAME%%/etc/shared/cis_rhel5_linux_rcl.txt
|
|
@owner ossec
|
|
@mode 660
|
|
%%PORTNAME%%/logs/active-responses.log
|
|
%%PORTNAME%%/logs/ossec.log
|
|
@owner
|
|
@group
|
|
@mode
|
|
%%PORTNAME%%/rules/apache_rules.xml
|
|
%%PORTNAME%%/rules/arpwatch_rules.xml
|
|
%%PORTNAME%%/rules/asterisk_rules.xml
|
|
%%PORTNAME%%/rules/attack_rules.xml
|
|
%%PORTNAME%%/rules/cimserver_rules.xml
|
|
%%PORTNAME%%/rules/cisco-ios_rules.xml
|
|
%%PORTNAME%%/rules/clam_av_rules.xml
|
|
%%PORTNAME%%/rules/courier_rules.xml
|
|
%%PORTNAME%%/rules/dovecot_rules.xml
|
|
%%PORTNAME%%/rules/dropbear_rules.xml
|
|
%%PORTNAME%%/rules/firewall_rules.xml
|
|
%%PORTNAME%%/rules/ftpd_rules.xml
|
|
%%PORTNAME%%/rules/hordeimp_rules.xml
|
|
%%PORTNAME%%/rules/ids_rules.xml
|
|
%%PORTNAME%%/rules/imapd_rules.xml
|
|
%%PORTNAME%%/rules/local_rules.xml
|
|
%%PORTNAME%%/rules/mailscanner_rules.xml
|
|
%%PORTNAME%%/rules/mcafee_av_rules.xml
|
|
%%PORTNAME%%/rules/ms-exchange_rules.xml
|
|
%%PORTNAME%%/rules/ms-se_rules.xml
|
|
%%PORTNAME%%/rules/ms_dhcp_rules.xml
|
|
%%PORTNAME%%/rules/ms_ftpd_rules.xml
|
|
%%PORTNAME%%/rules/msauth_rules.xml
|
|
%%PORTNAME%%/rules/mysql_rules.xml
|
|
%%PORTNAME%%/rules/named_rules.xml
|
|
%%PORTNAME%%/rules/netscreenfw_rules.xml
|
|
%%PORTNAME%%/rules/nginx_rules.xml
|
|
%%PORTNAME%%/rules/openbsd_rules.xml
|
|
%%PORTNAME%%/rules/ossec_rules.xml
|
|
%%PORTNAME%%/rules/pam_rules.xml
|
|
%%PORTNAME%%/rules/php_rules.xml
|
|
%%PORTNAME%%/rules/pix_rules.xml
|
|
%%PORTNAME%%/rules/policy_rules.xml
|
|
%%PORTNAME%%/rules/postfix_rules.xml
|
|
%%PORTNAME%%/rules/postgresql_rules.xml
|
|
%%PORTNAME%%/rules/proftpd_rules.xml
|
|
%%PORTNAME%%/rules/pure-ftpd_rules.xml
|
|
%%PORTNAME%%/rules/racoon_rules.xml
|
|
%%PORTNAME%%/rules/roundcube_rules.xml
|
|
%%PORTNAME%%/rules/rules_config.xml
|
|
%%PORTNAME%%/rules/sendmail_rules.xml
|
|
%%PORTNAME%%/rules/smbd_rules.xml
|
|
%%PORTNAME%%/rules/solaris_bsm_rules.xml
|
|
%%PORTNAME%%/rules/sonicwall_rules.xml
|
|
%%PORTNAME%%/rules/spamd_rules.xml
|
|
%%PORTNAME%%/rules/squid_rules.xml
|
|
%%PORTNAME%%/rules/sshd_rules.xml
|
|
%%PORTNAME%%/rules/symantec-av_rules.xml
|
|
%%PORTNAME%%/rules/symantec-ws_rules.xml
|
|
%%PORTNAME%%/rules/syslog_rules.xml
|
|
%%PORTNAME%%/rules/telnetd_rules.xml
|
|
%%PORTNAME%%/rules/trend-osce_rules.xml
|
|
%%PORTNAME%%/rules/vmpop3d_rules.xml
|
|
%%PORTNAME%%/rules/vmware_rules.xml
|
|
%%PORTNAME%%/rules/vpn_concentrator_rules.xml
|
|
%%PORTNAME%%/rules/vpopmail_rules.xml
|
|
%%PORTNAME%%/rules/vsftpd_rules.xml
|
|
%%PORTNAME%%/rules/web_appsec_rules.xml
|
|
%%PORTNAME%%/rules/web_rules.xml
|
|
%%PORTNAME%%/rules/wordpress_rules.xml
|
|
%%PORTNAME%%/rules/zeus_rules.xml
|
|
%%PORTNAME%%/agentless/main.exp
|
|
%%PORTNAME%%/agentless/register_host.sh
|
|
%%PORTNAME%%/agentless/ssh.exp
|
|
%%PORTNAME%%/agentless/ssh_asa-fwsmconfig_diff
|
|
%%PORTNAME%%/agentless/ssh_foundry_diff
|
|
%%PORTNAME%%/agentless/ssh_generic_diff
|
|
%%PORTNAME%%/agentless/ssh_integrity_check_bsd
|
|
%%PORTNAME%%/agentless/ssh_integrity_check_linux
|
|
%%PORTNAME%%/agentless/ssh_nopass.exp
|
|
%%PORTNAME%%/agentless/ssh_pixconfig_diff
|
|
%%PORTNAME%%/agentless/sshlogin.exp
|
|
%%PORTNAME%%/agentless/su.exp
|
|
@owner root
|
|
@group ossec
|
|
@mode 550
|
|
@dir %%PORTNAME%%/.ssh
|
|
@dir %%PORTNAME%%/active-response/bin
|
|
@dir %%PORTNAME%%/active-response
|
|
@dir %%PORTNAME%%/agentless
|
|
@dir %%PORTNAME%%/bin
|
|
@dir %%PORTNAME%%/etc/shared
|
|
@dir %%PORTNAME%%/etc
|
|
@dir %%PORTNAME%%/queue/rootcheck
|
|
@dir %%PORTNAME%%/rules
|
|
@dir %%PORTNAME%%/tmp
|
|
@mode 770
|
|
@dir %%PORTNAME%%/var/run
|
|
@mode 550
|
|
@dir %%PORTNAME%%/var
|
|
@owner ossec
|
|
@mode 770
|
|
@dir %%PORTNAME%%/queue/alerts
|
|
@dir %%PORTNAME%%/queue/ossec
|
|
@mode 750
|
|
@dir %%PORTNAME%%/queue/fts
|
|
@dir %%PORTNAME%%/queue/syscheck
|
|
@dir %%PORTNAME%%/queue/diff
|
|
@dir %%PORTNAME%%/queue/agentless
|
|
@dir %%PORTNAME%%/stats
|
|
@dir %%PORTNAME%%/logs/alerts
|
|
@dir %%PORTNAME%%/logs/archives
|
|
@dir %%PORTNAME%%/logs/firewall
|
|
@dir %%PORTNAME%%/logs
|
|
@owner ossecr
|
|
@dir %%PORTNAME%%/queue/agent-info
|
|
@dir %%PORTNAME%%/queue/rids
|
|
@owner ossec
|
|
@mode 550
|
|
@dir %%PORTNAME%%/queue
|
|
@owner root
|
|
@mode 550
|
|
@dir %%PORTNAME%%
|