用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-ubuntu2004-v300-6-3-2-4命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
基于 SOC 职业分类
正在显示 SKILL.md
| name | cis-ubuntu2004-v300-6-3-2-4 |
| description | Ensure system warns when audit logs are low on space |
| category | cis-logging |
| version | 3.0.0 |
| author | cyberstrike-official |
| tags | ["cis","ubuntu","linux","ubuntu-20.04","auditing","auditd"] |
| cis_id | 6.3.2.4 |
| cis_benchmark | CIS Ubuntu Linux 20.04 LTS Benchmark v3.0.0 |
| tech_stack | ["ubuntu","linux"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
The auditd daemon can be configured to halt the system, put the system in single user mode or send a warning message, if the partition that holds the audit log files is low on space.
The space_left_action parameter tells the system what action to take when the system has detected that it is starting to get low on disk space. Valid values are ignore, syslog, rotate, email, exec, suspend, single, and halt.
The admin_space_left_action parameter tells the system what action to take when the system has detected that it is low on disk space. Valid values are ignore, syslog, rotate, email, exec, suspend, single, and halt.
In high security contexts, the risk of detecting unauthorized access or nonrepudiation exceeds the benefit of the system's availability.
If the admin_space_left_action is set to single the audit daemon will put the computer system in single user mode.
Run the following command and verify the space_left_action is set to email, exec, single, or halt:
grep -P -- '^\h*space_left_action\h*=\h*(email|exec|single|halt)\b' /etc/audit/auditd.conf
Verify the output is email, exec, single, or halt.
Example output:
space_left_action = email
Run the following command and verify the admin_space_left_action is set to single - OR - halt:
grep -P -- '^\h*admin_space_left_action\h*=\h*(single|halt)\b' /etc/audit/auditd.conf
Verify the output is single or halt.
Example output:
admin_space_left_action = single
Note: A Mail Transfer Agent (MTA) must be installed and configured properly to set space_left_action = email
space_left_action should be set to email, exec, single, or halt. admin_space_left_action should be set to single or halt.
Set the space_left_action parameter in /etc/audit/auditd.conf to email, exec, single, or halt:
Example:
space_left_action = email
Set the admin_space_left_action parameter in /etc/audit/auditd.conf to single or halt:
Example:
admin_space_left_action = single
Note: A Mail Transfer Agent (MTA) must be installed and configured properly to set space_left_action = email
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
|---|---|---|---|---|
| v8 | 8.2 Collect Audit Logs | X | X | X |
| v8 | 8.3 Ensure Adequate Audit Log Storage | X | X | X |
| v7 | 6.2 Activate audit logging | X | X | X |
MITRE ATT&CK Mappings: T1562, T1562.006 / TA0005