mirror of
https://github.com/falcosecurity/falco.git
synced 2025-07-03 09:56:45 +00:00
minor changes
Signed-off-by: kaizhe <derek0405@gmail.com>
This commit is contained in:
parent
f16c744779
commit
cf8395c7ed
@ -2443,9 +2443,9 @@
|
|||||||
When the setuid or setgid bits are set for an application,
|
When the setuid or setgid bits are set for an application,
|
||||||
this means that the application will run with the privileges of the owning user or group respectively.
|
this means that the application will run with the privileges of the owning user or group respectively.
|
||||||
Detect setuid or setgid bits set via chmod
|
Detect setuid or setgid bits set via chmod
|
||||||
condition: consider_all_chmods and chmod and (evt.arg.mode contains "S_ISUID" or evt.arg.mode contains "S_ISGID") and not proc.cmdline in (user_known_chmod_applications)
|
condition: consider_all_chmods and chmod and (evt.arg.mode contains "S_ISUID" or evt.arg.mode contains "S_ISGID") and not proc.name in (user_known_chmod_applications)
|
||||||
output: >
|
output: >
|
||||||
Setuid or setgid bit is set via chmod (fd=%evt.arg.fd filename=%evt.arg.filename mode=%evt.arg.mode user=%user.name
|
Setuid or setgid bit is set via chmod (fd=%evt.arg.fd filename=%evt.arg.filename mode=%evt.arg.mode user=%user.name process=%proc.name
|
||||||
command=%proc.cmdline container_id=%container.id container_name=%container.name image=%container.image.repository:%container.image.tag)
|
command=%proc.cmdline container_id=%container.id container_name=%container.name image=%container.image.repository:%container.image.tag)
|
||||||
priority:
|
priority:
|
||||||
NOTICE
|
NOTICE
|
||||||
|
Loading…
Reference in New Issue
Block a user