Commit Graph

  • 91a0b510fa rule(macro user_expected_system_procs_network_activity_conditions): create the macro Nicolas Marier 2020-03-02 15:59:59 -05:00
  • 76062b93ab rule(list known_system_procs_network_activity_binaries): add a list of known procs for convenience Nicolas Marier 2020-03-02 15:55:13 -05:00
  • 9fd08ce3e4 Introduce missing allowed_full_admin_users macro so its corresponding rule is disabled by default Vicente Herrera 2020-04-07 19:19:18 +02:00
  • 3ce11f093f Removed default K3s admin user from list, clarified comments Vicente Herrera 2020-04-07 11:05:32 +02:00
  • e7b3d7a7e0 Added four new rules, to detect k8s operation by an administrator, nodes successfully joining the cluster, nodes unsuccessfully attempt to join, creation ingress without TLS certificate Vicente Herrera 2020-03-26 12:00:00 +01:00
  • 2c2d126a54 Added two new rules to detect traffic to image outside local subnet and detect traffic that is not to authorized server process and port Vicente Herrera 2020-03-26 11:54:21 +01:00
  • ffa137fc7c rule(Delete Bash History): Fix typo in tags Bob Aman 2020-04-13 19:45:17 -07:00
  • 534a642074 rule(Delete or rename shell history): Fix typo in tags Bob Aman 2020-04-13 19:41:56 -07:00
  • fd572f4bd2 update(cmake/modules): driver version bump to a259b4bf49c3 Leonardo Di Donato 2020-04-10 09:35:20 +00:00
  • 1548ccbc4f rule(Write below root): use pmatch to check against known root directories kaizhe 2020-04-08 17:26:30 -07:00
  • a0c189b730 fix: HOST_ROOT environment variable detection Lorenzo Fontana 2020-04-08 18:19:15 +02:00
  • 37476aabed fix(driver/bpf): exact check on bpf_probe_read_str() return value Lorenzo Fontana 2020-04-07 13:35:38 +02:00
  • 39a27e0a09 docs: badges links to bintray repos now Leonardo Di Donato 2020-04-07 16:59:48 +00:00
  • 11843948e8 docs(README): versions section Leonardo Di Donato 2020-02-28 21:17:12 +01:00
  • 35691b0e05 update(docker): update README.md Leonardo Grasso 2020-03-30 16:45:26 +02:00
  • ea0f78c2c2 chore(docker): remove kernel/linuxkit and kernel/probeloader images Leonardo Grasso 2020-03-30 16:10:00 +02:00
  • 61e859745d chore(docker): remove RHEL-base image Leonardo Grasso 2020-03-30 15:51:30 +02:00
  • 6834649fa5 rule(Service Account Created in Kube Namespace): only detect sa created in kube namespace with success kaizhe 2020-03-24 12:02:08 -07:00
  • 4df5fe83be update(cmake): using sha256 instead of md5 danmx 2020-03-24 23:29:19 +01:00
  • e1cb2e9bb0 rule(Detect outbound connections to common miner pool ports): whitelist sysdig/agent and falcosecurity/falco for query miner domain dns kaizhe 2020-03-24 11:21:34 -07:00
  • 09b87b9a3d fix(test): use .falco dir Leonardo Di Donato 2020-03-23 16:56:48 +00:00
  • a9658d446f fix(test): urrlib from python 2 to 3 Lorenzo Fontana 2020-03-23 17:34:36 +01:00
  • fbcdb57cea update(docker): entrypoints to call falco-driver-loader now Leonardo Di Donato 2020-03-23 13:44:52 +00:00
  • b3998a6b44 build(scripts): insert versions into falco-driver-version and install it Leonardo Di Donato 2020-03-23 13:44:31 +00:00
  • b39f322994 fix(scripts): falco-probe-loader becomes falco-driver-loader and distinghuishes driver version from falco version Leonardo Di Donato 2020-03-23 13:44:03 +00:00
  • c1d840d471 update(test): account only for falco version in tests, not driver version Leonardo Di Donato 2020-03-23 13:42:43 +00:00
  • d3a215a2db new(userspace/falco): return also driver version from --version flag Leonardo Di Donato 2020-03-23 13:42:19 +00:00
  • 3934f19f3d build: cmake var to store the URL where to lookup for prebuilt drivers Leonardo Di Donato 2020-03-23 13:41:29 +00:00
  • 7f9d3ca422 fix(.circleci): ensure stable docker images (packages built from tag) have exact FALCO_VERSION env variable Leonardo Di Donato 2020-03-23 10:32:08 +00:00
  • c1c9ba56ac fix(.circleci): ensure docker images (packages built from master) have correct FALCO_VERSION env variable Leonardo Di Donato 2020-03-23 10:29:36 +00:00
  • 7b44aafc6a ci: avoid stable releases to be published to *-dev repositories too Leonardo Di Donato 2020-03-19 16:51:44 +00:00
  • a56803e3c7 ci: override package update Leonardo Di Donato 2020-03-19 16:45:46 +00:00
  • ce5bc89698 ci: upsert versions on git tag (release) Leonardo Di Donato 2020-03-19 16:40:11 +00:00
  • ea46adfbc8 new(userspace/falco): add --disable-cri-async flag Lorenzo Fontana 2020-03-17 15:24:43 +01:00
  • c5674c9001 build: fix tbb dependency rename Lorenzo Fontana 2020-03-18 11:40:54 +01:00
  • 1cbe0b27bb docs(readme): adding new release archive Kris Nova 2020-03-17 07:13:36 -07:00
  • 9db36822e7 update(docker/tester): python 3 support for regression tests Lorenzo Fontana 2020-03-12 16:39:50 +01:00
  • 5909eac307 fix(.circleci): remove --labels flag from circleci 0.21.0 Leonardo Di Donato 2020-03-17 18:24:57 +01:00
  • f69c419940 fix(.circleci): remove github tag rel nots flag (not working) Leonardo Di Donato 2020-03-17 17:30:59 +01:00
  • 10e4983297 fix(.circleci): to create stable versions bintray secret and user are needed Leonardo Di Donato 2020-03-17 16:15:40 +01:00
  • 9e69972ec4 docs: highlight breaking change in the changelog for 0.21.0 Leonardo Di Donato 2020-03-17 15:05:56 +01:00
  • 87e8457ce7 docs: bump versions to 0.21.0 Leonardo Di Donato 2020-03-17 15:02:49 +01:00
  • 56ccdf29c8 docs: CHANGELOG for 0.21.0 Leonardo Di Donato 2020-03-17 14:59:58 +01:00
  • 2126616529 Fix image for event generator deployment yaml Mark Stemm 2020-03-12 07:45:35 -07:00
  • 3067af566e rule(Change thread namespace): fix regression test Hiroki Suezawa 2020-02-26 09:58:34 +09:00
  • 742538ac86 rule(Change thread namespace): change condition to detect suspicious container activity Hiroki Suezawa 2019-12-17 01:25:27 +09:00
  • 6488ea8456 (WIP) K8s Deployment to run event generator w k8s_audit Mark Stemm 2020-03-10 16:14:19 -07:00
  • 3fd67aa5c3 K8s Daemonset to run event generator w/ syscalls Mark Stemm 2020-03-10 14:17:59 -07:00
  • 085009ad93 Fixed use of "tag" instead of "tags" in default rules Vicente Herrera 2020-01-27 15:47:19 +01:00
  • 788d3294bd chore: re-enabling package build, sign, and docker push from master Leonardo Di Donato 2020-03-10 18:07:49 +00:00
  • de5cd1ce6f update(docker): latest or explicit FALCO_VERSION for docker images via docker build argument Leonardo Di Donato 2020-03-10 17:36:30 +00:00
  • 4d4a2af8b6 chore: temporary test for circleci Leonardo Di Donato 2020-03-10 16:25:04 +00:00
  • 36501c5f1d new(cmake/modules): provide and parse FALCO_VERSION_PRERELEASE too Leonardo Di Donato 2020-03-10 16:19:31 +00:00
  • 123a75062e build: passing driver checksum down to download makefile Lorenzo Fontana 2020-03-09 20:00:23 +01:00
  • 74b0e18253 build: PROBE_VERSION must use the driver version Lorenzo Fontana 2020-03-09 19:50:29 +01:00
  • aef06f1dda fix(.circleci): fix get falco version for image build Lorenzo Fontana 2020-03-06 18:02:48 +01:00
  • 6711abf3d7 fix(.circleci): build args for minimal dockerfile Lorenzo Fontana 2020-03-06 11:22:29 +01:00
  • 941313b1f1 fix(docker/minimal): untar of downloaded falco package Lorenzo Fontana 2020-03-06 11:21:58 +01:00
  • 210da83402 docs: updating branding Kris Nova 2020-03-04 10:27:02 -08:00
  • 8481b94f4c fix(.circleci): docker minimal images need exact FALCO_VERSION Leonardo Di Donato 2020-03-02 11:59:39 +01:00
  • 4a8d8a049f add comments kaizhe 2020-02-25 14:14:03 -08:00
  • b4f2fdc439 disable cryptomining rule by default; add exception of localhost and rfc1918 ip addresses kaizhe 2020-02-25 13:41:59 -08:00
  • 1c74c68ff3 fix(.circleci): dockerhub authentication during releasing process Leonardo Di Donato 2020-02-28 20:50:52 +01:00
  • e637b1ebbc update(.circleci): build and publish from master Leonardo Di Donato 2020-02-28 15:58:40 +01:00
  • f4c152a216 fix(.circleci): sign RPMs Leonardo Di Donato 2020-02-28 14:36:47 +01:00
  • 906585d31a new(.circleci): build and publish docker images Leonardo Di Donato 2020-02-28 14:35:37 +01:00
  • 272bb59df4 update(docker): reorganize docker images with build arguments Leonardo Di Donato 2020-02-28 14:34:11 +01:00
  • fae4bcf9ae fix(.circleci): expect script needs eof Leonardo Di Donato 2020-02-28 13:55:50 +01:00
  • b3117ebcab fix(.circleci): rpmsign needs enter for empty passphrases Leonardo Di Donato 2020-02-28 13:16:21 +01:00
  • d694c58e04 new(.circleci): rpm sign for release workflow too Leonardo Di Donato 2020-02-28 12:22:04 +01:00
  • 443eb0f08c new(.circleci): sign rpm packages Lorenzo Fontana 2020-02-28 12:08:05 +01:00
  • 8cf43cd9ae fix(.circleci): bintray auth for version creation Leonardo Di Donato 2020-02-28 08:57:15 +01:00
  • eeea37a298 update(.circleci): split run steps for publishing artifacts Leonardo Di Donato 2020-02-28 02:10:13 +01:00
  • 8e92b588d5 update(.circleci): create version before uploading it Leonardo Di Donato 2020-02-27 22:25:27 +01:00
  • 76a5976906 new(.circleci): build and publish docker images (skeleton) Leonardo Di Donato 2020-02-27 21:22:07 +01:00
  • e9b5b815da new(docker/dev): update local dockerfile to use our own repositories Lorenzo Fontana 2020-02-27 17:30:16 +01:00
  • 4e3a279e47 new(docker): update local to use our own repositories Lorenzo Fontana 2020-02-27 17:00:01 +01:00
  • 9d6c714bdf update(docker/stable): use the new debian packages infrastructure Lorenzo Fontana 2020-02-27 16:46:26 +01:00
  • d6ed1ca39a fix(docker): falcosecurity sources list Leonardo Di Donato 2020-02-27 16:59:07 +01:00
  • 5cdca39ae6 update(docker/stable): use the falcosecurity deb repo Leonardo Di Donato 2020-02-27 15:37:58 +01:00
  • 1ec2f2cea3 update(docker/minimal): download falco binary Leonardo Di Donato 2020-02-27 14:54:54 +01:00
  • 201ce0ddc6 new(.circleci): publish binary distributions (tar.gz) Leonardo Di Donato 2020-02-27 14:32:06 +01:00
  • dfdd9693fc update(docker): slim images to use falcosecurity new repo and new GPG key Leonardo Di Donato 2020-02-26 19:16:14 +01:00
  • 8415576097 update(docker/rhel): using the new falcosecurity repo and falcosecurity GPG key Leonardo Di Donato 2020-02-26 19:15:17 +01:00
  • 4d99ce1b65 new(.circleci): run the debug build on centos7 on CI (USE_BUNDLED_DEPS=ON, CMAKE_BUILD_TYPE=debug) Leonardo Di Donato 2020-02-26 17:31:20 +01:00
  • 5ee72367a4 new(.circleci): debug build on ubuntu bionic (CI) Leonardo Di Donato 2020-02-26 17:12:09 +01:00
  • acaa8d75e1 update(.circleci): publish packages only from master Leonardo Di Donato 2020-02-26 17:04:12 +01:00
  • dfc600f719 new(.circleci): release stable packages from git tags Leonardo Di Donato 2020-02-26 16:35:20 +01:00
  • dd98291692 fix(.circleci): push to deb-dev and rpm-dev Leonardo Di Donato 2020-02-26 16:16:03 +01:00
  • 0a5e36a28a new(.circleci): publish packages for rpm, debian stretch, debian sid, debian buster Leonardo Di Donato 2020-02-26 14:42:37 +01:00
  • e190d7cdbf fix(.circleci): specify target path for deb packages Leonardo Di Donato 2020-02-26 13:43:37 +01:00
  • f268c5aa0b update(cmake/modules): declare cpack version component variables Leonardo Di Donato 2020-02-26 13:03:25 +01:00
  • f44098cf2d fix(.circleci): obtain FALCO_VERSION without executing Falco Leonardo Di Donato 2020-02-26 12:55:48 +01:00
  • c19b2f14ad fix(.circleci): version + xenial Leonardo Di Donato 2020-02-26 11:51:50 +01:00
  • b59e4b6072 chore(docker,cmake,scripts): correct maintainers email Leonardo Di Donato 2020-02-25 20:22:02 +01:00
  • d0a44f4285 new(.circleci): initial job to publish deb package Leonardo Di Donato 2020-02-25 17:15:38 +01:00
  • 2a739364d6 fix(docker): fix symbolic linking for /usrc/src inside docker images entrypoint Leonardo Di Donato 2020-01-24 14:14:15 +01:00
  • bcfc1fc9ff fix: indentation Adrián Arroyo Calle 2019-12-18 09:54:37 +00:00
  • 3eb634d49f fix: entrypoint now uses base path Adrián Arroyo Calle 2019-12-18 09:50:33 +00:00
  • 9eeed5912b Updating falco:local Kris Nova 2020-01-23 10:25:19 -08:00