mirror of
https://github.com/falcosecurity/falco.git
synced 2025-07-01 17:12:21 +00:00
commit
f426c4292d
@ -241,6 +241,9 @@
|
|||||||
- macro: parent_linux_image_upgrade_script
|
- macro: parent_linux_image_upgrade_script
|
||||||
condition: proc.pname startswith linux-image-
|
condition: proc.pname startswith linux-image-
|
||||||
|
|
||||||
|
- macro: java_running_sdjagent
|
||||||
|
condition: proc.name=java and proc.cmdline contains sdjagent.jar
|
||||||
|
|
||||||
###############
|
###############
|
||||||
# General Rules
|
# General Rules
|
||||||
###############
|
###############
|
||||||
@ -355,7 +358,9 @@
|
|||||||
condition: >
|
condition: >
|
||||||
evt.type = setns
|
evt.type = setns
|
||||||
and not proc.name in (docker_binaries, k8s_binaries, lxd_binaries, sysdigcloud_binaries, sysdig, nsenter)
|
and not proc.name in (docker_binaries, k8s_binaries, lxd_binaries, sysdigcloud_binaries, sysdig, nsenter)
|
||||||
|
and not proc.name startswith "runc:"
|
||||||
and not proc.pname in (sysdigcloud_binaries)
|
and not proc.pname in (sysdigcloud_binaries)
|
||||||
|
and not java_running_sdjagent
|
||||||
output: "Namespace change (setns) by unexpected program (user=%user.name command=%proc.cmdline parent=%proc.pname %container.info)"
|
output: "Namespace change (setns) by unexpected program (user=%user.name command=%proc.cmdline parent=%proc.pname %container.info)"
|
||||||
priority: WARNING
|
priority: WARNING
|
||||||
tags: [process]
|
tags: [process]
|
||||||
|
Loading…
Reference in New Issue
Block a user