diff --git a/rules/falco_rules.yaml b/rules/falco_rules.yaml index d962c539..56e7974f 100644 --- a/rules/falco_rules.yaml +++ b/rules/falco_rules.yaml @@ -638,7 +638,7 @@ evt.type=setuid and evt.dir=> and not user.name=root and not somebody_becoming_themself and not proc.name in (userexec_binaries, mail_binaries, docker_binaries, - sshd, dbus-daemon-lau, ping, ping6, critical-stack-) + sshd, dbus-daemon-lau, ping, ping6, critical-stack-, Xvfb) and not java_running_sdjagent output: > Unexpected setuid call by non-sudo, non-root program (user=%user.name parent=%proc.pname