[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Audit Kernel Module Loading and Unloading

ID: oval:org.secpod.oval:def:44056Date: (C)2018-02-20   (M)2023-07-04
Class: COMPLIANCEFamily: macos




Kernel modules, called kernel extensions in Mac OS X, are compiled segments of code that are dynamically loaded into the kernel as required to support specific pieces of hardware or functionality. Privileged users are permitted to load or unload kernel extensions manually. An attacker might attempt to load a kernel extension that is known to be insecure to increase the attack surface of the system, or a user might plug in an unauthorized device that then triggers a kernel extension to be loaded. Auditing administrative actions, which include the loading or unloading of kernel extensions, mitigates this risk.

Platform:
Apple Mac OS X 10.11
Reference:
CCE-91361-6
CCE    1
CCE-91361-6
XCCDF    1
xccdf_org.secpod_benchmark_general_Mac_OS_X_10_11

© SecPod Technologies