adding chipsec and ossec

This commit is contained in:
2025-12-13 16:06:50 +01:00
parent e38b442bb4
commit bd4a9e8429

View File

@@ -55,15 +55,10 @@ EOL
# [MALW-3276] Ensure rkhunter is installed
sudo pacman -S --noconfirm --needed rkhunter
sudo rkhunter --propupd
sudo tee /etc/rkhunter.conf > /dev/null <<EOL
# rkhunter configuration file
# Whitelist to avoid false positive
SCRIPTWHITELIST=/usr/bin/egrep
SCRIPTWHITELIST=/usr/bin/fgrep
SCRIPTWHITELIST=/usr/bin/ldd
SCRIPTWHITELIST=/usr/bin/vendor_perl/GET
EOL
sudo echo 'SCRIPTWHITELIST=/usr/bin/egrep' | sudo tee -a /etc/rkhunter.conf > /dev/null
sudo echo 'SCRIPTWHITELIST=/usr/bin/fgrep' | sudo tee -a /etc/rkhunter.conf > /dev/null
sudo echo 'SCRIPTWHITELIST=/usr/bin/ldd' | sudo tee -a /etc/rkhunter.conf > /dev/null
sudo echo 'SCRIPTWHITELIST=/usr/bin/rkhunter' | sudo tee -a /etc/rkhunter.conf > /dev/null
# [MALW-3282] Ensure ClamAV is installed
sudo pacman -S --noconfirm --needed clamav