diff --git a/UDLs/nessus-compliance-checks_by_amurren.xml b/UDLs/nessus-compliance-checks_by_amurren.xml new file mode 100644 index 00000000..14f6b569 --- /dev/null +++ b/UDLs/nessus-compliance-checks_by_amurren.xml @@ -0,0 +1,64 @@ + + + + + + + + 00# 01 02 03 04 + + + + + + + + + + + + + + + + + + + <if> </if> <then> </then> <else> </else> + <access_acl <acl <condition '<condition type:"AND">' '<condition type:"OR">' '<condition auto:"FAILED"' <custom_item <file_acl <group_policy <item <launch_acl <launch2_acl <registry_acl '<report type' '<report type:"PASSED">' '<report type:"FAILED">' '<report type:"WARNING">' <service_acl <user + </acl> </condition> </custom_item> </file_acl> </group_policy> </item> </registry_acl> </report> </service_acl> </user> + 'account_type :' 'account_type:' 'acl_allow :' 'acl_allow:' 'acl_apply :' 'acl_apply:' 'acl_deny :' 'acl_deny:' 'acl_inheritance :' 'acl_inheritance:' 'acl_option :' 'acl_option:' 'allowActivityContinuation :' 'allowActivityContinuation:' 'allowAirDrop :' 'allowAirDrop:' 'allowApplePersonalizedAdvertising :' 'allowApplePersonalizedAdvertising:' 'allowAutoUnlock :' 'allowAutoUnlock:' 'allowCamera :' 'allowCamera:' 'allowCloudAddressBook :' 'allowCloudAddressBook:' 'allowCloudBookmarks :' 'allowCloudBookmarks:' 'allowCloudCalendar :' 'allowCloudCalendar:' 'allowCloudDesktopAndDocuments :' 'allowCloudDesktopAndDocuments:' 'allowCloudDocumentSync :' 'allowCloudDocumentSync:' 'allowCloudKeychainSync :' 'allowCloudKeychainSync:' 'allowCloudMail :' 'allowCloudMail:' 'allowCloudNotes :' 'allowCloudNotes:' 'allowCloudPhotoLibrary :' 'allowCloudPhotoLibrary:' 'allowCloudPrivateRelay :' 'allowCloudPrivateRelay:' 'allowCloudReminders :' 'allowCloudReminders:' 'allowConnectionsWithoutCertificates :' 'allowConnectionsWithoutCertificates:' 'allowContentCaching :' 'allowContentCaching:' 'allowDiagnosticSubmission :' 'allowDiagnosticSubmission:' 'allowFindMyDevice :' 'allowFindMyDevice:' 'allowFindMyFriends :' 'allowFindMyFriends:' 'allowFingerprintForUnlock :' 'allowFingerprintForUnlock:' 'AllowGuestAccess :' 'AllowGuestAccess:' 'AllowIdentifiedDevelopers :' 'AllowIdentifiedDevelopers:' 'allowInvalidCertificates :' 'allowInvalidCertificates:' 'allowPasswordAutoFill :' 'allowPasswordAutoFill:' 'allowPasswordProximityRequests :' 'allowPasswordProximityRequests:' 'allowPasswordSharing :' 'allowPasswordSharing:' 'allowSimple :' 'allowSimple:' 'allowSmartCard :' 'allowSmartCard:' 'any_region :' 'any_region:' 'api_request_type :' 'api_request_type:' 'apiVersion :' 'apiVersion:' 'appcmd_args :' 'appcmd_args:' 'appcmd_filter :' 'appcmd_filter:' 'appcmd_filter_value :' 'appcmd_filter_value:' 'appcmd_list :' 'appcmd_list:' 'askForPassword :' 'askForPassword:' 'askForPasswordDelay :' 'askForPasswordDelay:' 'attr :' 'attr:' 'audit_policy :' 'audit_policy:' 'audit_policy_subcategory :' 'audit_policy_subcategory:' 'AutoSubmit :' 'AutoSubmit:' 'aws_action :' 'aws_action:' 'basedir :' 'basedir:' 'byhost :' 'byhost:' 'check_option :' 'check_option:' 'check_type :' 'check_type:' 'check_uneveness :' 'check_uneveness:' 'checkCertificateTrust :' 'checkCertificateTrust:' 'cmd :' 'cmd:' 'collection :' 'collection:' 'ConfigDataInstall :' 'ConfigDataInstall:' 'configuration :' 'configuration:' 'content :' 'content:' 'context :' 'context:' 'defaults :' 'defaults:' 'description :' 'description:' 'destination :' 'destination:' 'DeviceEnabled :' 'DeviceEnabled:' 'DisableBluetooth :' 'DisableBluetooth:' 'DisabledPreferencePanes :' 'DisabledPreferencePanes:' 'DisableFDEAutoLogin :' 'DisableFDEAutoLogin:' 'DisableFMMiCloudSetting :' 'DisableFMMiCloudSetting:' 'DisableGuestAccount :' 'DisableGuestAccount:' 'DisableOverride :' 'DisableOverride:' 'distribution_id :' 'distribution_id:' 'dont_echo_cmd :' 'dont_echo_cmd:' 'EnableAssessment :' 'EnableAssessment :' 'EnableAssessment:' 'EnableAssessment:' 'enforce :' 'enforce-version :' 'enforce-version:' 'enforce:' 'enforceSmartCard :' 'enforceSmartCard:' 'except :' 'except:' 'exclude_paths :' 'exclude_paths:' 'exec :' 'exec:' 'exemptions :' 'exemptions:' 'expect :' 'expect:' 'f5_command :' 'f5_command:' 'familyControlsEnabled :' 'familyControlsEnabled:' 'feature_set :' 'feature_set:' 'fieldsSelector :' 'fieldsSelector:' 'file :' 'file-db :' 'file-db:' 'file:' 'file_extension :' 'file_extension:' 'file_name :' 'file_name:' 'file_option :' 'file_option:' 'file_required :' 'file_required:' 'file_supersedence :' 'file_supersedence:' 'file_type :' 'file_type:' 'filter :' 'filter:' 'find :' 'find:' 'find_acl :' 'find_acl:' 'find_name :' 'find_name:' 'find_option :' 'find_option:' 'find_type :' 'find_type:' 'forceInternetSharingOff :' 'forceInternetSharingOff:' 'forceLimitAdTracking :' 'forceLimitAdTracking:' 'format :' 'format:' 'gid :' 'gid:' 'GKAutoRearm :' 'GKAutoRearm:' 'group :' 'group:' 'group_name :' 'group_name:' 'group_type :' 'group_type:' 'guestAccess :' 'guestAccess:' 'guid_reg_key :' 'guid_reg_key:' 'hash_algorithm :' 'hash_algorithm:' 'hierarchy :' 'hierarchy:' 'homeSharingUIStatus :' 'homeSharingUIStatus:' 'hosted_zone_id :' 'hosted_zone_id:' 'idleTime :' 'idleTime:' 'ignore :' 'ignore:' 'ignore_shell :' 'ignore_shell:' 'ignore_user :' 'ignore_user:' 'ignore_users :' 'ignore_users:' 'include_paths :' 'include_paths:' 'info :' 'info:' 'interfaces :' 'interfaces:' 'ios_version :' 'ios_version:' 'Ironwood Allowed :' 'Ironwood Allowed:' 'is_substring :' 'is_substring:' 'item :' 'item:' 'javascriptEnabled :' 'javascriptEnabled:' 'journal :' 'journal:' 'json_transform :' 'json_transform:' 'kb_path :' 'kb_path:' 'kb_path_required :' 'kb_path_required:' 'kerberos_policy :' 'kerberos_policy:' 'key_item :' 'key_item:' 'keys :' 'keys:' 'kind :' 'kind:' 'known_good :' 'known_good:' 'label :' 'label:' 'legacySharingUIStatus :' 'legacySharingUIStatus:' 'levels :' 'levels:' 'lockout_policy :' 'lockout_policy:' 'logAppend :' 'logAppend:' 'loginWindowModulePath :' 'loginWindowModulePath:' 'ls :' 'ls:' 'luhn :' 'luhn:' 'managed_path :' 'managed_path:' 'mask :' 'mask:' 'masked :' 'masked:' 'match :' 'match:' 'match_all :' 'match_all:' 'match_case :' 'match_case:' 'max_occurrences :' 'max_occurrences:' 'max_size :' 'max_size:' 'maxFailedAttempts :' 'maxFailedAttempts:' 'maxIncomingConnections :' 'maxIncomingConnections:' 'maxPINAgeInDays :' 'maxPINAgeInDays:' 'md5 :' 'md5:' 'mediaSharingUIStatus :' 'mediaSharingUIStatus:' 'min_occurrences :' 'min_occurrences:' 'minComplexChars :' 'minComplexChars:' 'mindepth :' 'mindepth:' 'minLength :' 'minLength:' 'minutesUntilFailedLoginReset :' 'minutesUntilFailedLoginReset:' 'mkstore-wrlc :' 'mkstore-wrlc:' 'mode :' 'mode:' 'modulePath :' 'modulePath:' 'Monitoronlymode :' 'Monitoronlymode:' 'mount-controls :' 'mount-controls:' 'name :' 'name:' 'namespaces :' 'namespaces:' 'natIP :' 'natIP:' 'net :' 'net:' 'nogroup :' 'nogroup:' 'NoMulticastAdvertisements :' 'NoMulticastAdvertisements:' 'not_expect :' 'not_expect:' 'not_group :' 'not_group:' 'not_perm :' 'not_perm:' 'not_regex :' 'not_regex:' 'not_user :' 'not_user:' 'nouser :' 'nouser:' 'num_rows :' 'num_rows:' 'number_of_lines :' 'number_of_lines:' 'only_show :' 'only_show:' 'only_show_cmd_output :' 'only_show_cmd_output:' 'operator :' 'operator:' 'output :' 'output:' 'output_all_lines :' 'output_all_lines:' 'owner :' 'owner:' 'pam_umaskmodule :' 'pam_umaskmodule:' 'parameters :' 'parameters:' 'password_policy :' 'password_policy:' 'pathBlackList :' 'pathBlackList:' 'payload_key :' 'payload_key:' 'payload_type :' 'payload_type:' 'perm :' 'perm:' 'pinHistory :' 'pinHistory:' 'pkg :' 'pkg:' 'plist_item :' 'plist_item:' 'plist_name :' 'plist_name:' 'plist_option :' 'plist_option:' 'plist_user :' 'plist_user:' 'policy_arn :' 'policy_arn:' 'policy_name :' 'policy_name:' 'port :' 'port:' 'port_no :' 'port_no:' 'port_option :' 'port_option:' 'port_type :' 'port_type:' 'ports :' 'ports:' 'powershell_args :' 'powershell_args:' 'powershell_console_file :' 'powershell_console_file:' 'powershell_option :' 'powershell_option:' 'print :' 'print:' 'privileges :' 'privileges:' 'property :' 'property:' 'providers :' 'providers:' 'ps_encoded_args :' 'ps_encoded_args:' 'pwd :' 'pwd:' 'query :' 'query:' 'quiet :' 'quiet:' 'reference :' 'reference:' 'reg_enum :' 'reg_enum:' 'reg_ignore_hku_users :' 'reg_ignore_hku_users:' 'reg_include_hku_users :' 'reg_include_hku_users:' 'reg_item :' 'reg_item:' 'reg_key :' 'reg_key:' 'reg_option :' 'reg_option:' 'reg_type :' 'reg_type:' 'regex :' 'regex:' 'regex_replace :' 'regex_replace:' 'request :' 'request:' 'requireAlphanumeric :' 'requireAlphanumeric:' 'required :' 'required:' 'resources :' 'resources:' 'RetriesUntilHint :' 'RetriesUntilHint:' 'revokePrivilegesFromRole :' 'revokePrivilegesFromRole:' 'right_type :' 'right_type:' 'role :' 'role:' 'role_name :' 'role_name:' 'roles :' 'roles:' 'rpm :' 'rpm:' 'rules :' 'rules:' 'runtimeClasses :' 'runtimeClasses:' 'script :' 'script:' 'search_locations :' 'search_locations:' 'seccompProfile :' 'seccompProfile:' 'secret :' 'secret:' 'section :' 'section:' 'secure_string :' 'secure_string:' 'security :' 'security:' 'securityContext :' 'securityContext:' 'see_also :' 'see_also:' 'service :' 'service:' 'service_name :' 'service_name:' 'settings_name :' 'settings_name:' 'severity :' 'severity:' 'show_output :' 'show_output:' 'SHOWFULLNAME :' 'SHOWFULLNAME:' 'Siri Data Sharing Opt-In Status :' 'Siri Data Sharing Opt-In Status:' 'SkipCloudSetup :' 'SkipCloudSetup:' 'SkipiCloudStorageSetup :' 'SkipiCloudStorageSetup:' 'SkipSiriSetup :' 'SkipSiriSetup:' 'SkipTouchIDSetup :' 'SkipTouchIDSetup:' 'solution :' 'solution:' 'sql_expect :' 'sql_expect:' 'sql_request :' 'sql_request:' 'sql_types :' 'sql_types:' 'ssl :' 'ssl:' 'status :' 'status:' 'storage :' 'storage:' 'string_required :' 'string_required:' 'subscriptions :' 'subscriptions:' 'svc_option :' 'svc_option:' 'svcprop_option :' 'svcprop_option:' 'switch :' 'switch:' 'system :' 'system-db :' 'system-db:' 'system:' 'systemvalue :' 'systemvalue:' 'target :' 'target:' 'timeout :' 'timeout:' 'timeServer :' 'timeServer:' 'timestamp :' 'timestamp:' 'tls :' 'tls:' 'TMAutomaticTimeOnlyEnabled :' 'TMAutomaticTimeOnlyEnabled:' 'tokenRemovalAction :' 'tokenRemovalAction:' 'tolooklikethelinesbelow :' 'tolooklikethelinesbelow:' 'tomcat_admin :' 'tomcat_admin:' 'trust :' 'trust:' 'type :' 'type:' 'uid :' 'uid:' 'uid_ge :' 'uid_ge:' 'uid_lt :' 'uid_lt:' 'use_domain :' 'use_domain:' 'use_valid_shells :' 'use_valid_shells:' 'user :' 'user-db :' 'user-db:' 'user:' 'user_name :' 'user_name:' 'usernames :' 'usernames:' 'value :' 'value:' 'value_data :' 'value_data:' 'value_type :' 'value_type:' 'verbose :' 'verbose:' 'warn :' 'warn-version :' 'warn-version:' 'warn:' 'warning :' 'warning:' 'wmi_attribute :' 'wmi_attribute:' 'wmi_exclude_result :' 'wmi_exclude_result:' 'wmi_key :' 'wmi_key:' 'wmi_namespace :' 'wmi_namespace:' 'wmi_option :' 'wmi_option:' 'wmi_request :' 'wmi_request:' 'writeConcern :' 'writeConcern:' 'xattr :' 'xattr:' 'xsl_stmt :' 'xsl_stmt:' + <variable> </variable> + ACCESS_ANALYZER ANONYMOUS_SID_SETTING APP_INFO_BY_DEVICE AUDIT_ESX AUDIT_EXCHANGE AUDIT_IIS_APPCMD AUDIT_POLICY_SUBCATEGORY AUDIT_POWERSHELL AUDIT_SYSTEMVAL AUDIT_USER_TIMESTAMPS AUDIT_VCENTER AUDIT_VM AUDIT_XML AUDIT_XML_VPM AUTOSCALING BANNER_CHECK CHECK_ACCOUNT CHKCONFIG CLOUDFRONT CLOUDTRAIL CLOUDWATCH CLUSTERROLEBINDINGSUBJECTSA-NAMESPACE CMD_EXEC CONFIG CONFIG_CHECK CONFIG_CHECK_NOT CONFIGURATION_INFO DEVICE_INFO EC2 EFS ELB FILE_CHECK FILE_CHECK_NOT FILE_CONTENT_CHECK FILE_CONTENT_CHECK_NOT FILE_PERMISSIONS FILE_VERSION FIND_CMD FULL_PROFILE_INFO GRAMMAR_CHECK GROUP_MEMBERS_POLICY GUID_REGISTRY_SETTING IAM KERBEROS_POLICY KMS LOCKOUT_POLICY LOGS MACOSX_DEFAULTS_READ MACOSX_OSASCRIPT PASSWORD_POLICY PKG_CHECK POLICY PROCESS_CHECK RANDOMNESS_CHECK RDS REG_CHECK REG_CHECK_SUBKEYS REGISTRY_PERMISSIONS REGISTRY_SETTING REST_API ROUTE53 RPM_CHECK S3 SECURITYHUB SERVICE_POLICY SHOW_CONFIG_CHECK SNS SQL_POLICY SVC_PROP USER_GROUPS_POLICY USER_RIGHTS_POLICY WMI_POLICY XINETD_SVC + </check_type> '<check_type:"Adtran">' '<check_type:"Alcatel">' '<check_type:"amazon_aws">' '<check_type:"Arista">' '<check_type:"ArubaOS">' '<check_type:"AS/400">' '<check_type:"BlueCoat">' '<check_type:"Brocade">' '<check_type:"CheckPoint">' '<check_type:"Cisco">' '<check_type:"Cisco_ACI">' '<check_type:"Cisco_Firepower">' '<check_type:"Cisco_Viptela">' '<check_type:"Citrix_Application_Delivery">' '<check_type:"Database"' '<check_type:"Extreme_ExtremeXOS">' '<check_type:"F5">' '<check_type:"FileContent">' '<check_type:"FireEye">' '<check_type:"FortiGate">' '<check_type:"GCP">' '<check_type:"HPProCurve">' '<check_type:"Huawei">' '<check_type:"IBM_DB2DB">' '<check_type:"Juniper">' '<check_type:"MDM"' '<check_type:"microsoft_azure">' '<check_type:"MongoDB">' '<check_type:"MS_SQLDB">' '<check_type:"MySQLDB">' '<check_type:"NetApp">' '<check_type:"Netapp_API">' '<check_type:"OpenShift">' '<check_type:"OpenStack">' '<check_type:"OracleDB">' '<check_type:"Palo_Alto">' '<check_type:"PostgreSQLDB">' '<check_type:"Rackspace">' '<check_type:"RHEV">' '<check_type:"Salesforce.com">' '<check_type:"Snowflake">' '<check_type:"SonicWALL">' '<check_type:"Splunk">' '<check_type:"SybaseDB">' '<check_type:"Unix"' '<check_type:"VMware">' '<check_type:"WatchGuard">' '<check_type:"Windows"' '<check_type:"Zoom">' '<check_type:"ZTE_ROSNG">' 'com.apple.' + 'Default Value:' 'Default Value :' 'a query:' 'mobileconfig profile info:' 'mobileconfig profile info :' + 00 01 02 03 04 05 06 07 08 09 10 11 12 13 14 15 16 17 18 19 20 21 22 23 + + + + + + + + + + + + + + + + + + + + + + + + + + + + + diff --git a/udl-list.json b/udl-list.json index fac0f00f..db0bbc87 100644 --- a/udl-list.json +++ b/udl-list.json @@ -3164,6 +3164,15 @@ "description": "twinBASIC syntax highlighting (dark version)", "author": "sokinkeso", "homepage": "https://twinbasic.com/" - } + }, + { + "id-name": "nessus-compliance-checks_by_amurren", + "display-name": "nessus-compliance-checks", + "version": "2025-May-28", + "repository": "", + "description": "Nessus Audit File Compliance Checks", + "author": "amurren", + "homepage": "https://github.com/amurren/nessus-compliance-checks-UDL" + } ] }