Commit Graph

  • 0b516b7d42 rule(macro user_known_k8s_ns_kube_system_images): add new macro image name inside kube-system namespace DingGGu 2020-11-10 16:12:01 +09:00
  • 4954593261 rule(macro user_known_k8s_client_container): add node-problem-detector pattern to avoid false positive DingGGu 2020-11-09 11:57:29 +09:00
  • 4507d6b43e update(.circleci): split build steps Leonardo Di Donato 2020-11-11 10:07:59 +00:00
  • 0eff0f6003 docs: changelog for 0.26.2 Leonardo Di Donato 2020-11-10 10:34:07 +00:00
  • 082bd199d8 fix(.circleci): disable driver build for aarch64 CI job Leonardo Di Donato 2020-11-10 16:17:02 +00:00
  • 77b8110770 fix(scripts/ci-build-apline-aarch64.sh): -y flag not recognized by apk Leonardo Di Donato 2020-11-10 13:24:11 +00:00
  • 216f155ff5 update(.circleci): remove docker setup step for aarch64 Lorenzo Fontana 2020-11-10 13:01:28 +01:00
  • 8d10a60e42 build: remove duplicate item from FALCO_SOURCES Leo Di Donato 2020-11-10 10:11:27 +01:00
  • 7d5f982e4e update(.circleci): insert build for aarch64 in the CI workflow Leonardo Di Donato 2020-11-10 11:32:23 +00:00
  • e163207fd4 new(.circleci): job for aarch64 build Leonardo Di Donato 2020-11-10 11:30:02 +00:00
  • 1211215241 new(scripts): initial script to build Falco for aarch64 on CI Leonardo Di Donato 2020-11-10 11:29:27 +00:00
  • 0e6ae63d10 docs: changelog for 0.26.2 0.26.2 release/0.26.2 Leonardo Di Donato 2020-11-10 10:34:07 +00:00
  • 801f9f7686 update: new DRIVERS_REPO default Leonardo Di Donato 2020-10-27 16:18:29 +00:00
  • 4d6636a030 fix(scripts/falco-driver-loader): lsmod usage Dominic Evans 2020-11-05 16:02:59 +00:00
  • 55a93bce8b build: bump sinsp, scap and the drivers to 5c0b863ddade7a45568c0ac97d037422c9efb750 Lorenzo Fontana 2020-11-07 19:04:36 +01:00
  • 0f14821744 fix(userspace/falco): include directories and sources Lorenzo Fontana 2020-10-16 18:13:28 +02:00
  • e0175b1e06 build: cmake modules fixes and split Lorenzo Fontana 2020-10-16 16:59:38 +02:00
  • 8be299939a build: update sinsp, scap and the drivers to c4f096099bf81966803d26c40c6c2cb2b8d08033 Lorenzo Fontana 2020-10-15 18:18:02 +02:00
  • 9828c6aeb6 build: bump gRPC to 1.32.0 Lorenzo Fontana 2020-10-13 17:43:32 +02:00
  • 7ee0eb7e9c update: cpack specify architecture for debian packages Lorenzo Fontana 2020-10-13 17:00:50 +02:00
  • 0f155c3a1f build: switch Falco back to luajit Lorenzo Fontana 2020-10-13 15:44:08 +02:00
  • 3258bdd990 update: syscall table zero definition for arm64 Lorenzo Fontana 2020-10-13 15:23:07 +02:00
  • 9f41a390a7 update: bump sinsp and scap to fntlnz-aarch64 Lorenzo Fontana 2020-10-13 14:14:01 +02:00
  • 7aa6fa9897 build: use fields_info from libsinsp Lorenzo Fontana 2020-10-13 13:44:56 +02:00
  • 8dd9ebbdf9 build: moonjit replacement for luajit Lorenzo Fontana 2020-10-13 12:24:51 +02:00
  • 0852a88a16 rule(macro chage_list): create new macro chage_list as execption in rule Usermgmt binaries kaizhe 2020-11-05 16:23:11 -08:00
  • cea9c6a377 adding lkm rule divious1 2020-11-05 22:08:20 -05:00
  • c055f02dd0 rule(macro multipath_writing_conf): create and use the macro Nicolas Marier 2020-11-05 11:12:44 -05:00
  • 2f84bd8eeb build: what happens if a test does not pass on circleci? temporary/test-ci-broken-tests Lorenzo Fontana 2020-11-05 18:48:43 +01:00
  • f5c1e7c165 build: fix build directory for xunit tests Lorenzo Fontana 2020-11-05 15:59:29 +01:00
  • aaf6816821 build: make our integration tests report clear steps for circleCI UI inspection via collect test data [0] Lorenzo Fontana 2020-11-05 14:14:59 +01:00
  • ee5b55c02e docs: reach out documentation Lorenzo Fontana 2020-11-05 13:29:32 +01:00
  • 1d9188a316 wip: pointer to pointer in hawk_engine rules_cb libhawk Lorenzo Fontana 2020-11-04 13:58:50 +01:00
  • 5cc102545f wip Leonardo Di Donato 2020-10-30 13:30:25 +00:00
  • 294804daf4 rule(list falco_privileged_images): add calico/node without registry prefix Christian Zunker 2020-10-21 13:25:42 +02:00
  • 2801c62666 new(userspace/falco): destroy rules watcher when needed Leonardo Di Donato 2020-10-29 11:33:10 +00:00
  • c6cffc1f48 new(userspace): make hawk_watch_rules aware of the engine Leonardo Di Donato 2020-10-29 10:58:23 +00:00
  • 4894c93d5e new(userspace): initial draft for libhawk Lorenzo Fontana 2020-10-16 13:18:33 +02:00
  • b3679f8a59 update: new DRIVERS_REPO default Leonardo Di Donato 2020-10-27 16:18:29 +00:00
  • a575625043 docs(proposals): new drivers storage obsolate part of existing artifacts storage proposals Leonardo Di Donato 2020-10-27 16:18:02 +00:00
  • 26f2aaa3eb rule(Full K8s... Access): fix users list Mark Stemm 2020-10-20 15:10:58 -07:00
  • c8703b88bf update(userspace/engine): handle formatters with smart pointer Leonardo Grasso 2020-10-16 13:18:25 +02:00
  • cebec11552 fix(userspace/engine): free formatters, if any Leonardo Grasso 2020-10-15 19:31:34 +02:00
  • 61bfd5a158 update(proposals): proposal for moving the drivers to S3 Lorenzo Fontana 2020-10-23 17:07:54 +02:00
  • 81de65eb69 fix(userspace/falco): use given priority for msg Leonardo Grasso 2020-10-19 10:45:43 +02:00
  • bc9a2f38e1 update(falco/rules): re-use spawned_process macro inside container_started macro Leo Di Donato 2020-10-18 20:24:40 +02:00
  • c188f4a731 chore(userspace/falco): output class does not need to inherit from falco_common Leonardo Grasso 2020-10-20 15:41:57 +02:00
  • ca04145590 chore(userspace/falco): remove unused dep from falco_outputs Leonardo Grasso 2020-10-20 15:33:58 +02:00
  • 511a9fa97f chore: update copyright year to 2020 Leonardo Grasso 2020-10-14 17:08:25 +02:00
  • 7b8f67fdbd chore(userspace/falco): remove leftover from outputs Leonardo Grasso 2020-10-14 15:35:12 +02:00
  • 6e36afdba3 update(userspace/falco): move gRPC queue to proper namespace Leonardo Grasso 2020-10-14 11:24:24 +02:00
  • 9ea195a0b7 macro(allowed_k8s_users): exclude cloud-controller-manage to avoid false positives on k3s Lorenzo Fontana 2020-10-15 18:00:27 +02:00
  • dbd4ff08eb Rules changes (WIP) add-exceptions-support-copy2 Mark Stemm 2020-10-13 17:36:36 -07:00
  • 47fa7d53c4 rule(Outbound Connection to C2 Servers): Add a new rule to detect outbound connections to c2 servers kaizhe 2020-10-12 16:47:05 -07:00
  • 9c70ae19be Squash w/ code commit: single field exceptions Mark Stemm 2020-10-13 11:20:32 -07:00
  • 9cb25be5bd Squash w/ test commit. Mark Stemm 2020-10-13 11:20:12 -07:00
  • 0a33f555eb build: bump b64 to ce864b17ea0e24a91e77c7dd3eb2d1ac4175b3f0. Lorenzo Fontana 2020-10-13 13:15:00 +02:00
  • 38f524d1dd build: bump b64 to v2.0.0.1 Lorenzo Fontana 2020-10-13 11:58:28 +02:00
  • 388de27398 update(docker/tester): split version guessing of Falco version Leonardo Grasso 2020-10-12 15:44:23 +02:00
  • 69d2fa76ff fix(docker/tester): re-enable -e Leonardo Grasso 2020-10-12 14:27:22 +02:00
  • 39e6d21449 Added new macro user_known_remote_file_copy_activities Signed-off-by: Marc-Olivier Bouchard <mobouchard@coveo.com> Marc-Olivier Bouchard 2020-10-07 08:05:52 -04:00
  • 3418ed64aa Added new macro user_know_remote_file_copy_tools_in_container_conditions Signed-off-by: Marc-Olivier Bouchard <mobouchard@coveo.com> Marc-Olivier Bouchard 2020-09-30 11:23:46 -04:00
  • d07f18ad05 update(test): use to iso time Leonardo Grasso 2020-10-12 23:53:35 +02:00
  • 4af705c15d fix(test): correct parent dir creation for strict tests Leonardo Grasso 2020-10-12 19:09:15 +02:00
  • 469749a2b5 chore(userspace/engine): clean up leftover Leonardo Grasso 2020-10-12 18:12:13 +02:00
  • 3355d0d215 chore: update comments to reflect the impl Leonardo Grasso 2020-09-29 18:46:59 +02:00
  • b74d60289c chore: lua dir is not needed anymore in falco_outputs Leonardo Grasso 2020-09-29 18:40:06 +02:00
  • e4aa646146 chore(userspace/falco): cleanup unnecessary flush Leonardo Grasso 2020-09-29 17:30:54 +02:00
  • a4b3af29ae chore(userspace/falco): finalize program output impl Leonardo Grasso 2020-09-29 17:04:02 +02:00
  • 17685eaa3c update(userspace/falco): improve stdout buffering Leonardo Grasso 2020-09-29 11:28:59 +02:00
  • b75166ff60 build(userspace/falco): clean up residual lua references Leonardo Grasso 2020-09-24 18:53:49 +02:00
  • 2f3669b962 chore: clean up lua from dot files Leonardo Grasso 2020-09-24 18:52:30 +02:00
  • 1bcac6f251 chore(userspace/falco): prefix abstract class with "abstract_" Leonardo Grasso 2020-09-24 15:44:08 +02:00
  • 57c62ba6a7 chore(userspace/falco): move output config struct one level up Leonardo Grasso 2020-09-24 15:22:45 +02:00
  • 6451a55d82 chore(userspace/falco): simplify files naming Leonardo Grasso 2020-09-24 14:49:00 +02:00
  • 0ff220de1e chore(userspace/engine): clean up unused code Leonardo Grasso 2020-09-22 18:18:16 +02:00
  • 78fa43708b refactor(userspace/falco): falco_outputs Leonardo Grasso 2020-09-22 17:46:39 +02:00
  • 99d4a7d5c5 new(userspace/falco): syslog output C++ impl Leonardo Grasso 2020-09-22 17:45:55 +02:00
  • 7f4d5396c2 new(userspace/falco): program output C++ impl Leonardo Grasso 2020-09-22 17:45:13 +02:00
  • aa8edadf68 new(userspace/falco): http output C++ impl Leonardo Grasso 2020-09-22 17:44:57 +02:00
  • 6ecc691c68 new(userspace/falco): gRPC output C++ impl Leonardo Grasso 2020-09-22 17:44:45 +02:00
  • 4d61f1c739 new(userspace/falco): file output C++ impl Leonardo Grasso 2020-09-22 17:44:20 +02:00
  • 7b70f3c2ef new(userspace/falco): stdout output C++ impl Leonardo Grasso 2020-09-22 17:44:03 +02:00
  • 8371d1955a chore(userspace/falco): refine falco_output interface Leonardo Grasso 2020-09-22 12:24:45 +02:00
  • 270c3fa910 new(userspace/falco): base class for Falco outputs Leonardo Grasso 2020-09-21 18:47:08 +02:00
  • 0a2eab3f19 chore(userspace/falco): clean up lua deps from logger Leonardo Grasso 2020-09-21 18:44:44 +02:00
  • ac2a9a35cb chore(userspace/falco): remove lua code for outputs Leonardo Grasso 2020-09-21 18:43:24 +02:00
  • 85aa337b63 update(userspace/engine): refactor falco_formats to accept non-lua callers Leonardo Grasso 2020-09-21 16:06:31 +02:00
  • 1f533e5964 Bump falco engine version to 8 for exceptions. Mark Stemm 2020-10-12 15:46:54 -07:00
  • 854318cacf Allow lists/list names to be exception values Mark Stemm 2020-10-12 15:43:23 -07:00
  • 0cc10b0fbe Tests for exceptions using lists. Mark Stemm 2020-10-12 15:43:02 -07:00
  • d1211ecca8 feat(docs): Adding meeting notes step to RELASE.md Kris Nóva 2020-10-07 08:32:58 -07:00
  • f567f2f7f7 chore(test): update copyright year Leonardo Grasso 2020-10-09 18:02:49 +02:00
  • ab615c36ad update(test): check all fields for gRPC output Leonardo Grasso 2020-10-09 17:15:50 +02:00
  • 60c322a73d new(test): strict json output Leonardo Grasso 2020-10-09 16:33:54 +02:00
  • f12210325f chore(test): correct file name Leonardo Grasso 2020-10-09 16:27:48 +02:00
  • 682e53f5b5 update(test): strict output tests Leonardo Grasso 2020-10-09 13:11:51 +02:00
  • 6e8352e847 chore(test): cleanup tmp file Leonardo Grasso 2020-10-09 13:11:01 +02:00
  • c512784503 new(test): stdout output strict Leonardo Grasso 2020-10-09 13:00:35 +02:00
  • b0942f8774 new(test): add "output_strictly_contains" option Leonardo Grasso 2020-10-09 12:44:23 +02:00