ooknet/modules/nixos/base/security/auditing.nix

9 lines
181 B
Nix

{pkgs, ...}: {
security = {
audit = {
enable = true;
rules = ["-a exit, always -F arch=b64 -s execve"];
};
};
environment.systemPackages = [pkgs.lynis];
}