STIGUI
V-288839CAT II — Medium severitySV-288839r1262232_rule

SLEM 5 must generate audit records for all uses of the "useradd" command.

Rule version SLEM-05-654126 · STIG v1 · 2026-08-20

Discussion

Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one.

Audit records can be generated from various components within the information system (e.g., module or policy filter).

Check

Verify SLEM 5 generates an audit record for any use of the "useradd" command with the following command:

     > sudo auditctl -l | grep -w '/usr/sbin/useradd'
     -a always,exit -S all -F path=/usr/sbin/useradd -F perm=x -F auid>=1000 -F auid!=-1 -F key=privileged-useradd

If the command does not return any output, this is a finding.

Note: The "key=" value is arbitrary and can be different from the example output above.

Fix

Configure SLEM 5 to generate an audit record for all uses of the "useradd" command.

Add or modify the following line in the "/etc/audit/rules.d/audit.rules" file:

-a always,exit -F path=/usr/sbin/useradd -F perm=x -F auid>=1000 -F auid!=unset -k privileged-useradd

To reload the rules file, restart the audit daemon:

     > sudo systemctl restart auditd.service

or issue the following command:

     > sudo augenrules --load

Identifiers

Group ID
V-288839
Group title
SRG-OS-000037-GPOS-00015
Rule ID
SV-288839r1262232_rule
Check ID
C-93528r1262230_chk
Fix ID
F-93433r1262231_fix