mirror of
https://github.com/falcosecurity/falco.git
synced 2025-06-28 15:47:25 +00:00
rule(Read sensitive file untrusted): let salt-call read sensitive files
Signed-off-by: vin01 <vinc.i@protonmail.ch>
This commit is contained in:
parent
3697d1fae2
commit
d03826379b
@ -1441,7 +1441,7 @@
|
|||||||
and not proc.name in (user_mgmt_binaries, userexec_binaries, package_mgmt_binaries,
|
and not proc.name in (user_mgmt_binaries, userexec_binaries, package_mgmt_binaries,
|
||||||
cron_binaries, read_sensitive_file_binaries, shell_binaries, hids_binaries,
|
cron_binaries, read_sensitive_file_binaries, shell_binaries, hids_binaries,
|
||||||
vpn_binaries, mail_config_binaries, nomachine_binaries, sshkit_script_binaries,
|
vpn_binaries, mail_config_binaries, nomachine_binaries, sshkit_script_binaries,
|
||||||
in.proftpd, mandb, salt-minion, postgres_mgmt_binaries,
|
in.proftpd, mandb, salt-call, salt-minion, postgres_mgmt_binaries,
|
||||||
google_oslogin_
|
google_oslogin_
|
||||||
)
|
)
|
||||||
and not cmp_cp_by_passwd
|
and not cmp_cp_by_passwd
|
||||||
|
Loading…
Reference in New Issue
Block a user