diff options
| author | Fuwn <[email protected]> | 2024-09-20 05:36:20 -0700 |
|---|---|---|
| committer | Fuwn <[email protected]> | 2024-09-20 05:36:20 -0700 |
| commit | d9747c64b038943253eaafdc59a49d5face46dab (patch) | |
| tree | b452d15a7f20e9f4bb70ec9f9040137bec1072f8 /modules/core/security/audit.nix | |
| parent | himeji: move containers over from seti (diff) | |
| download | nixos-config-d9747c64b038943253eaafdc59a49d5face46dab.tar.xz nixos-config-d9747c64b038943253eaafdc59a49d5face46dab.zip | |
modules: server and core modules
Diffstat (limited to 'modules/core/security/audit.nix')
| -rw-r--r-- | modules/core/security/audit.nix | 17 |
1 files changed, 17 insertions, 0 deletions
diff --git a/modules/core/security/audit.nix b/modules/core/security/audit.nix new file mode 100644 index 0000000..9922213 --- /dev/null +++ b/modules/core/security/audit.nix @@ -0,0 +1,17 @@ +let + enable = false; +in +{ + security = { + auditd.enable = enable; + + audit = { + inherit enable; + + rules = [ + "-a exit,always -F arch=b64 -S execve" + "-a exit,always -F arch=b32 -S execve" + ]; + }; + }; +} |