mirror of
https://github.com/falcosecurity/falco.git
synced 2025-09-19 17:14:26 +00:00
Add more logging on process ancestors.
Try to find the root process that might be spawning shells/reading sensitive files.
This commit is contained in:
@@ -451,7 +451,7 @@
|
||||
and not proc.cmdline contains /usr/bin/mandb
|
||||
output: >
|
||||
Sensitive file opened for reading by non-trusted program (user=%user.name name=%proc.name
|
||||
command=%proc.cmdline file=%fd.name)
|
||||
command=%proc.cmdline file=%fd.name parent=%proc.pname gparent=%proc.aname[2])
|
||||
priority: WARNING
|
||||
tags: [filesystem]
|
||||
|
||||
@@ -763,7 +763,7 @@
|
||||
not proc.cmdline startswith "passwd -S"
|
||||
output: >
|
||||
User management binary command run outside of container
|
||||
(user=%user.name command=%proc.cmdline parent=%proc.pname gparent=%proc.aname[2])
|
||||
(user=%user.name command=%proc.cmdline parent=%proc.pname gparent=%proc.aname[2] ggparent=%proc.aname[3])
|
||||
priority: NOTICE
|
||||
tags: [host, users]
|
||||
|
||||
|
Reference in New Issue
Block a user