Got rkhunter working for HIDS; operational fixes for Sharingan
This commit is contained in:
		
							
								
								
									
										55
									
								
								roles/Sharingan/tasks/scans.yml
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										55
									
								
								roles/Sharingan/tasks/scans.yml
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,55 @@
 | 
			
		||||
---
 | 
			
		||||
 | 
			
		||||
 - name: Install lynis
 | 
			
		||||
   register: lynis_pkg
 | 
			
		||||
   become: yes
 | 
			
		||||
   package:
 | 
			
		||||
     name:
 | 
			
		||||
       - lynis
 | 
			
		||||
       - arch-audit
 | 
			
		||||
       - clamav
 | 
			
		||||
     state: present
 | 
			
		||||
 | 
			
		||||
 - name: lynis config
 | 
			
		||||
   register: lynis_conf
 | 
			
		||||
   become: yes
 | 
			
		||||
   copy:
 | 
			
		||||
     src: lynis/custom.prf
 | 
			
		||||
     dest: /etc/lynis/custom.prf
 | 
			
		||||
     owner: root
 | 
			
		||||
     group: root
 | 
			
		||||
     mode: 0600
 | 
			
		||||
 | 
			
		||||
 - name: Scanning services
 | 
			
		||||
   become: yes
 | 
			
		||||
   copy:
 | 
			
		||||
     src: "lynis/{{ item }}" 
 | 
			
		||||
     dest: /usr/lib/systemd/system/
 | 
			
		||||
     owner: root
 | 
			
		||||
     group: root
 | 
			
		||||
     mode: 0664
 | 
			
		||||
   loop:
 | 
			
		||||
     - sharingan-scan.service
 | 
			
		||||
     - sharingan-scan.timer
 | 
			
		||||
 | 
			
		||||
 - name: Scanning services
 | 
			
		||||
   become: yes
 | 
			
		||||
   copy:
 | 
			
		||||
     src: "clamav/{{ item }}" 
 | 
			
		||||
     dest: /usr/lib/systemd/system/
 | 
			
		||||
     owner: root
 | 
			
		||||
     group: root
 | 
			
		||||
     mode: 0664
 | 
			
		||||
   loop:
 | 
			
		||||
     - freshclam.service
 | 
			
		||||
     - freshclam.timer
 | 
			
		||||
 | 
			
		||||
 - name: Enable timers
 | 
			
		||||
   become: yes
 | 
			
		||||
   loop:
 | 
			
		||||
     - freshclam.timer
 | 
			
		||||
     - sharingan-scan.timer
 | 
			
		||||
   service:
 | 
			
		||||
     name: "{{ item }}"
 | 
			
		||||
     state: restarted
 | 
			
		||||
     enabled: yes
 | 
			
		||||
		Reference in New Issue
	
	Block a user