rule(Read sensitive file untrusted): let salt-call read sensitive files

Signed-off-by: vin01 <vinc.i@protonmail.ch>
This commit is contained in:
vin01 2022-11-14 21:53:09 +01:00 committed by poiana
parent 3697d1fae2
commit d03826379b

View File

@ -1441,7 +1441,7 @@
and not proc.name in (user_mgmt_binaries, userexec_binaries, package_mgmt_binaries,
cron_binaries, read_sensitive_file_binaries, shell_binaries, hids_binaries,
vpn_binaries, mail_config_binaries, nomachine_binaries, sshkit_script_binaries,
in.proftpd, mandb, salt-minion, postgres_mgmt_binaries,
in.proftpd, mandb, salt-call, salt-minion, postgres_mgmt_binaries,
google_oslogin_
)
and not cmp_cp_by_passwd