mirror of
https://github.com/falcosecurity/falco.git
synced 2025-08-28 19:00:48 +00:00
rule(Mkdir binary dirs): Exclude exe_running_docker_save
Signed-off-by: James Barlow <james.barlow@finbourne.com>
This commit is contained in:
parent
581d67fa08
commit
c2a05b3e64
@ -1601,7 +1601,12 @@
|
|||||||
|
|
||||||
- rule: Mkdir binary dirs
|
- rule: Mkdir binary dirs
|
||||||
desc: an attempt to create a directory below a set of binary directories.
|
desc: an attempt to create a directory below a set of binary directories.
|
||||||
condition: mkdir and bin_dir_mkdir and not package_mgmt_procs and not user_known_mkdir_bin_dir_activities
|
condition: >
|
||||||
|
mkdir
|
||||||
|
and bin_dir_mkdir
|
||||||
|
and not package_mgmt_procs
|
||||||
|
and not user_known_mkdir_bin_dir_activities
|
||||||
|
and not exe_running_docker_save
|
||||||
output: >
|
output: >
|
||||||
Directory below known binary directory created (user=%user.name user_loginuid=%user.loginuid
|
Directory below known binary directory created (user=%user.name user_loginuid=%user.loginuid
|
||||||
command=%proc.cmdline directory=%evt.arg.path container_id=%container.id image=%container.image.repository)
|
command=%proc.cmdline directory=%evt.arg.path container_id=%container.id image=%container.image.repository)
|
||||||
|
Loading…
Reference in New Issue
Block a user