# McAfee Enterprise Enterprise Security triggers on Auditbeat in /etc/passwd.xx

**URL:** https://discuss.elastic.co/t/mcafee-enterprise-enterprise-security-triggers-on-auditbeat-in-etc-passwd-xx/294846
**Category:** Beats
**Tags:** auditbeat
**Created:** [January 19, 2022, 3:51pm UTC](https://discuss.elastic.co/t/mcafee-enterprise-enterprise-security-triggers-on-auditbeat-in-etc-passwd-xx/294846 "2022-01-19T15:51:40Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![odehen](https://avatars.discourse-cdn.com/v4/letter/o/6a8cbe/32.png) [@odehen](https://discuss.elastic.co/u/odehen)
#### Post date: [January 19, 2022, 3:51pm UTC](https://discuss.elastic.co/t/mcafee-enterprise-enterprise-security-triggers-on-auditbeat-in-etc-passwd-xx/294846/1 "2022-01-19T15:51:40Z")

</div>

We are using Elasticsearch 7.16.2 on RHEL with McAfee Enterprise. Apparently an alarm has gone off, namely the PREVENT\_MODIFICATION\_PASSWORDFILES\_LINUX rule because of Auditbeat supposedly attempting to modify /etc/passwd and a few derivatives, /etc/passwd.xx .

Searches here and on Google have returned nothing, so we're concerned whether this is a false positive with McAfee or if we have a serious issue with Auditbeat actually attempting to modify the files. We're currently waiting to see if McAfe can give us any more detailed information on why the block happened.

---

<div class="post-metadata">

### Author: ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)
#### Post date: [January 20, 2022, 2:02am UTC](https://discuss.elastic.co/t/mcafee-enterprise-enterprise-security-triggers-on-auditbeat-in-etc-passwd-xx/294846/2 "2022-01-20T02:02:19Z")

</div>

There's nothing in Auditbeat's modules that would be writing. There are parts of Auditbeat that monitor /etc/passwd and /etc/shadow. So there can be some read activity (like with the system/user module).

---

<div class="post-metadata">

### Author: ![odehen](https://avatars.discourse-cdn.com/v4/letter/o/6a8cbe/32.png) [@odehen](https://discuss.elastic.co/u/odehen)
#### Post date: [January 20, 2022, 7:46am UTC](https://discuss.elastic.co/t/mcafee-enterprise-enterprise-security-triggers-on-auditbeat-in-etc-passwd-xx/294846/3 "2022-01-20T07:46:54Z")

</div>

Yes, I know that Auditbeat shouldn't be writing to any files like that, so I just want to clarify that this is a false positive so that we as a community can know about it! At least this has just happened in one of our environments with a total of 9 machines overall, so we're inclined to think it's something specific to how something might be set up on this specific system.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [February 17, 2022, 9:47am UTC](https://discuss.elastic.co/t/mcafee-enterprise-enterprise-security-triggers-on-auditbeat-in-etc-passwd-xx/294846/4 "2022-02-17T09:47:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
