diff --git a/rules/falco_rules.yaml b/rules/falco_rules.yaml index df8c12ae..67b964f3 100644 --- a/rules/falco_rules.yaml +++ b/rules/falco_rules.yaml @@ -111,7 +111,7 @@ items: [add-shell, remove-shell] - macro: shell_procs - condition: (proc.name in (shell_binaries)) + condition: proc.name in (shell_binaries) - list: coreutils_binaries items: [