mirror of
https://github.com/falcosecurity/falco.git
synced 2025-08-11 02:52:54 +00:00
Let cilium-cni change namespaces
Sample Falco alert: ``` Namespace change (setns) by unexpected program (user=root command=cilium-cni parent=cilium-cni host CID2 CID1 image=<NA>) ``` Signed-off-by: Mark Stemm <mark.stemm@gmail.com>
This commit is contained in:
parent
01c9d8ba31
commit
48a0f512fb
@ -1546,7 +1546,7 @@
|
|||||||
condition: >
|
condition: >
|
||||||
evt.type = setns
|
evt.type = setns
|
||||||
and not proc.name in (docker_binaries, k8s_binaries, lxd_binaries, sysdigcloud_binaries,
|
and not proc.name in (docker_binaries, k8s_binaries, lxd_binaries, sysdigcloud_binaries,
|
||||||
sysdig, nsenter, calico, oci-umount, network_plugin_binaries)
|
sysdig, nsenter, calico, oci-umount, cilium-cni, network_plugin_binaries)
|
||||||
and not proc.name in (user_known_change_thread_namespace_binaries)
|
and not proc.name in (user_known_change_thread_namespace_binaries)
|
||||||
and not proc.name startswith "runc"
|
and not proc.name startswith "runc"
|
||||||
and not proc.cmdline startswith "containerd"
|
and not proc.cmdline startswith "containerd"
|
||||||
|
Loading…
Reference in New Issue
Block a user