From 23a7203e50e9a460ed56ea76b95a88d7ff2a07ba Mon Sep 17 00:00:00 2001 From: Hiroki Suezawa Date: Fri, 13 Dec 2019 22:28:21 +0900 Subject: [PATCH] rule(list network_tool_binaries): add network tool names Signed-off-by: Hiroki Suezawa --- rules/falco_rules.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/rules/falco_rules.yaml b/rules/falco_rules.yaml index 3dac609f..2a09254c 100644 --- a/rules/falco_rules.yaml +++ b/rules/falco_rules.yaml @@ -2281,7 +2281,7 @@ tags: [network, k8s, container, mitre_port_knocking] - list: network_tool_binaries - items: [nc, ncat, nmap, dig, tcpdump, tshark, ngrep] + items: [nc, ncat, nmap, dig, tcpdump, tshark, ngrep, telnet, ssh, mitmproxy, socat] - macro: network_tool_procs condition: (proc.name in (network_tool_binaries))