Closed juresaht2 closed 7 months ago
Please try for your situation
-a always,exit -F arch=b32 -F path=/etc/default/virtualbox -F perm=wa -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks -a always,exit -F arch=b64 -F path=/etc/default/virtualbox -F perm=wa -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks
-a always,exit -F arch=b32 -F path=/etc/init.d/vboxdrv -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks -a always,exit -F arch=b64 -F path=/etc/init.d/vboxdrv -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks
-a always,exit -F arch=b32 -F path=/etc/init.d/virtualbox -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks -a always,exit -F arch=b64 -F path=/etc/init.d/virtualbox -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks
-a always,exit -F arch=b32 -F path=/usr/bin/virtualbox -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks -a always,exit -F arch=b64 -F path=/usr/bin/virtualbox -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks
-a always,exit -F arch=b32 -F path=/usr/sbin/virtualbox -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks -a always,exit -F arch=b64 -F path=/usr/sbin/virtualbox -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks
-a always,exit -F arch=b32 -F path=/usr/bin/virt-manager -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks -a always,exit -F arch=b64 -F path=/usr/bin/virt-manager -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks
-a always,exit -F arch=b32 -F path=/usr/sbin/virt-manager -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks -a always,exit -F arch=b64 -F path=/usr/sbin/virt-manager -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks
-a always,exit -F arch=b32 -F path=/lib/udev/VBoxCreateUSBNode.sh -F perm=wax -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks -a always,exit -F arch=b64 -F path=/lib/udev/VBoxCreateUSBNode.sh -F perm=wax -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks
-a always,exit -F arch=b32 -F path=/usr/lib/udev/VBoxCreateUSBNode.sh -F perm=wax -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks -a always,exit -F arch=b64 -F path=/usr/lib/udev/VBoxCreateUSBNode.sh -F perm=wax -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks
-a always,exit -F arch=b32 -F path=/lib/udev/rules.d/60-virtualbox.rules -F perm=wa -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks -a always,exit -F arch=b64 -F path=/lib/udev/rules.d/60-virtualbox.rules -F perm=wa -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks
-a always,exit -F arch=b32 -F path=/usr/lib/udev/rules.d/60-virtualbox.rules -F perm=wa -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks -a always,exit -F arch=b64 -F path=/usr/lib/udev/rules.d/60-virtualbox.rules -F perm=wa -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks
-a always,exit -F arch=b32 -F path=/usr/bin/VBoxBalloonCtrl -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks -a always,exit -F arch=b64 -F path=/usr/bin/VBoxBalloonCtrl -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks
-a always,exit -F arch=b32 -F path=/usr/sbin/VBoxBalloonCtrl -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks -a always,exit -F arch=b64 -F path=/usr/sbin/VBoxBalloonCtrl -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks
-a always,exit -F arch=b32 -F path=/usr/bin/VBoxHeadless -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks -a always,exit -F arch=b64 -F path=/usr/bin/VBoxHeadless -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks
-a always,exit -F arch=b32 -F path=/usr/sbin/VBoxHeadless -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks -a always,exit -F arch=b64 -F path=/usr/sbin/VBoxHeadless -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks
-a always,exit -F arch=b32 -F path=/usr/bin/VBoxManage -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks -a always,exit -F arch=b64 -F path=/usr/bin/VBoxManage -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks
-a always,exit -F arch=b32 -F path=/usr/sbin/VBoxManage -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks -a always,exit -F arch=b64 -F path=/usr/sbin/VBoxManage -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks
-a always,exit -F arch=b32 -F path=/usr/bin/VBoxSDL -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks -a always,exit -F arch=b64 -F path=/usr/bin/VBoxSDL -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks
-a always,exit -F arch=b32 -F path=/usr/sbin/VBoxSDL -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks -a always,exit -F arch=b64 -F path=/usr/sbin/VBoxSDL -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks
-a always,exit -F arch=b32 -F path=/usr/bin/vbox-img -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks -a always,exit -F arch=b64 -F path=/usr/bin/vbox-img -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks
-a always,exit -F arch=b32 -F path=/usr/sbin/vbox-img -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks -a always,exit -F arch=b64 -F path=/usr/sbin/vbox-img -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks
-a always,exit -F arch=b32 -F path=/usr/bin/vboxballoonctrl -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks -a always,exit -F arch=b64 -F path=/usr/bin/vboxballoonctrl -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks
-a always,exit -F arch=b32 -F path=/usr/sbin/vboxballoonctrl -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks -a always,exit -F arch=b64 -F path=/usr/sbin/vboxballoonctrl -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks
-a always,exit -F arch=b32 -F path=/usr/bin/vboxheadless -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks -a always,exit -F arch=b64 -F path=/usr/bin/vboxheadless -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks
-a always,exit -F arch=b32 -F path=/usr/sbin/vboxheadless -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks -a always,exit -F arch=b64 -F path=/usr/sbin/vboxheadless -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks
-a always,exit -F arch=b32 -F path=/usr/bin/vboximg-mount -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks -a always,exit -F arch=b64 -F path=/usr/bin/vboximg-mount -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks
-a always,exit -F arch=b32 -F path=/usr/sbin/vboximg-mount -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks -a always,exit -F arch=b64 -F path=/usr/sbin/vboximg-mount -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks
-a always,exit -F arch=b32 -F path=/usr/bin/vboxmanage -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks -a always,exit -F arch=b64 -F path=/usr/bin/vboxmanage -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks
-a always,exit -F arch=b32 -F path=/usr/sbin/vboxmanage -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks -a always,exit -F arch=b64 -F path=/usr/sbin/vboxmanage -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks
-a always,exit -F arch=b32 -F path=/usr/bin/vboxsdl -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks -a always,exit -F arch=b64 -F path=/usr/bin/vboxsdl -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks
-a always,exit -F arch=b32 -F path=/usr/sbin/vboxsdl -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks -a always,exit -F arch=b64 -F path=/usr/sbin/vboxsdl -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks
-a always,exit -F arch=b32 -F path=/usr/bin/vboxwebsrv -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks -a always,exit -F arch=b64 -F path=/usr/bin/vboxwebsrv -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks
-a always,exit -F arch=b32 -F path=/usr/sbin/vboxwebsrv -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks -a always,exit -F arch=b64 -F path=/usr/sbin/vboxwebsrv -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks
-a always,exit -F arch=b32 -F path=/etc/init.d/vboxadd-service -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks -a always,exit -F arch=b64 -F path=/etc/init.d/vboxadd-service -F perm=x -F key=T1497_Virtualization_Sandbox_Evasion_System_Checks
Someone else will have to test this as I have solved my issue by removing the rules.
I removed everything related to macOS. I don't want to support it with my config.
The following lines are yielding a "parameter passed without an option given" error on my CentOS machine.
https://github.com/Neo23x0/auditd/blob/master/audit.rules#L649
As these lines are intended to be for macOS anyway, I will just remove them, so I don't know if escaping the whitespace with
\
is the solution or if this is even a bug that affects auditd on macOS.