Commit Graph

  • e4ffa55d58 Add a playbook which starts to capturing data using Sysdig and uploads capture to a s3 bucket (#414) Néstor Salceda 2018-10-12 01:55:40 +02:00
  • f746c4cd57 Add a integration with Demisto (#408) Néstor Salceda 2018-10-10 19:28:35 +02:00
  • 0499811762 Clean up Readme, Add CNCF requested files for project. (#440) Michael Ducy 2018-10-10 01:50:17 -05:00
  • 84ed509ec8 Merge remote-tracking branch 'origin/dev' into agent-master agent/0.85.1 Grzegorz Nosek 2018-10-01 14:38:08 +02:00
  • 6445cdb950 Better copyright notices (#426) Mark Stemm 2018-09-26 19:49:19 -07:00
  • 6b82ecfa79 Add base64 encoding and snap length support (#410) ztz 2018-09-26 03:44:09 +08:00
  • fc70c635d1 Add dkms+xz dependencies to falco container Brett Bertocci 2018-09-24 17:00:29 -07:00
  • 2352b96d6b Change license to Apache 2.0 (#419) Mark Stemm 2018-09-20 11:47:10 -07:00
  • ff299c1d43 Merge remote-tracking branch 'origin/dev' Mark Stemm 2018-09-11 13:33:56 -07:00
  • fb3f2178ba Prepare for 0.12.1 (#417) 0.12.1 Mark Stemm 2018-09-11 13:33:14 -07:00
  • a5ef1c4f4f Upgrade to curl 7.61.0 (#416) Mark Stemm 2018-09-11 13:26:57 -07:00
  • 5e38f130cc Merge remote-tracking branch 'origin/dev' 0.12.0 Mark Stemm 2018-09-11 11:02:10 -07:00
  • eaaff5a773 Prepare for 0.12.0 (#415) Mark Stemm 2018-09-11 10:25:10 -07:00
  • d1ac6edd78 Merge branch 'dev' into agent-master agent/0.85.0 Mattia Pagnozzi 2018-09-11 12:27:18 +02:00
  • 81e2e672f0 Add TBB dependency (#412) Mattia Pagnozzi 2018-09-11 11:59:58 +02:00
  • 323213fe0f Merge branch 'dev' into agent-master agent/0.84.3 agent/0.84.2 agent/0.84.1 Thom van Os 2018-08-17 14:08:04 -07:00
  • 071e7dff17 Allow Lua sample_dir to be passed to falco_engine constructor Grzegorz Nosek 2018-08-13 18:24:45 +02:00
  • e8ba42cae4 Falco fixes for SMBACK-1611 for vulnerability CVE-2016-9840, CVE-201… (#402) vani-pareek 2018-08-13 22:13:26 +05:30
  • 9c2e422803 Merge branch 'dev' into agent-master agent/0.84.0 Thom van Os 2018-08-07 15:26:49 -07:00
  • 470710366b Merge remote-tracking branch 'origin/dev' 0.11.1 Mark Stemm 2018-07-31 12:06:09 -07:00
  • 24ca38a819 Prepare for 0.11.1 (#399) Mark Stemm 2018-07-31 12:05:00 -07:00
  • ab0413a9ee Downgrade binutils in docker image (#397) Mark Stemm 2018-07-31 10:44:47 -07:00
  • 6acb13e6bb Merge branch 'dev' 0.11.0 Mark Stemm 2018-07-24 17:33:24 -07:00
  • fdbe62fdae Prepare for 0.11.0 (#393) Mark Stemm 2018-07-24 17:27:17 -07:00
  • d63542d8ff Rule updates 2018 07.v1 (#388) Mark Stemm 2018-07-24 13:14:35 -07:00
  • 7289315837 Ensure the /lib/modules symlink to /host/lib/modules is set correctly Brett Bertocci 2018-07-13 15:54:18 -07:00
  • 25efce033b Merge pull request #391 from nestorsalceda/move-examples-to-integrations Jorge Salamero Sanz 2018-07-16 16:47:51 +02:00
  • 8bc4a5e38f Move puppet module from examples to integrations Néstor Salceda 2018-07-13 13:09:13 +02:00
  • c05319927a Move kubernetes manifests from examples to integrations Néstor Salceda 2018-07-13 13:08:38 +02:00
  • 1e32d637b2 Move logrotate from examples to integrations Néstor Salceda 2018-07-13 13:02:26 +02:00
  • ccf35552dd Merge pull request #389 from nestorsalceda/kubernetes-response-engine Jorge Salamero Sanz 2018-07-12 18:55:07 +02:00
  • ec0c109d2a Merge pull request #390 from nestorsalceda/anchore-falco Jorge Salamero Sanz 2018-07-12 18:52:54 +02:00
  • 46b0fd833c Add a README Néstor Salceda 2018-07-12 17:51:03 +02:00
  • bed5993500 Create Falco rule from Anchore policy result Néstor Salceda 2018-07-12 17:15:21 +02:00
  • bed360497e Remove repeated configurations and other stuff Néstor Salceda 2018-07-11 17:52:11 +02:00
  • 3afe04629a Move kubernetes_response_engine under integrations Néstor Salceda 2018-07-11 17:49:25 +02:00
  • bebdff3d67 This rule does not add any value to the integration Néstor Salceda 2018-07-11 17:18:56 +02:00
  • e62b25a8fb Merge branch 'dev' into agent-master agent/0.83.1 Thom van Os 2018-07-10 14:00:56 -07:00
  • 9543514270 Update README.md Jorge Salamero Sanz 2018-07-10 18:29:02 +02:00
  • 46405510e2 Update link target Néstor Salceda 2018-07-10 18:19:20 +02:00
  • 42285687d4 Add a README for Kubernetes infrastructure Néstor Salceda 2018-07-10 18:16:57 +02:00
  • 8b82a08148 Add Kubernetes manifests for deploying Nats + Falco + Kubeless Néstor Salceda 2018-07-10 18:11:04 +02:00
  • 19d251ef4b Update README.md Jorge Salamero Sanz 2018-07-10 18:08:54 +02:00
  • 66ba09ea3b Add a README for playbooks Néstor Salceda 2018-07-10 17:38:26 +02:00
  • 4867c47d4b Upload playbooks code Néstor Salceda 2018-07-10 16:41:56 +02:00
  • 526f32b54b Add a README for falco-nats output Néstor Salceda 2018-07-10 16:22:58 +02:00
  • 26ca866162 Add nats output for Falco Néstor Salceda 2018-07-10 13:44:32 +02:00
  • 893554e0f0 Add README for the kubernetes response engine Néstor Salceda 2018-07-10 13:44:02 +02:00
  • c5523d89a7 Rule updates 2018 04.v2 (#366) Mark Stemm 2018-07-06 13:17:17 -07:00
  • b2412302e6 Merge branch 'dev' into agent-master agent/0.83.0 Thom van Os 2018-06-26 10:57:06 -07:00
  • 81dcee23a9 edit Falco license info so that GitHub recognizes it (#380) Andrea Kao 2018-06-18 09:44:07 -07:00
  • 81a38fb909 add gcc-6 to Dockerfiles: (#382) Michael Ducy 2018-06-12 16:07:15 -04:00
  • e9e9bd85c3 Add libcurl include directory in CMakeLists (#374) Mattia Pagnozzi 2018-06-08 02:59:02 +02:00
  • 70f768d9ea Enable all rules (#379) Mark Stemm 2018-06-07 17:16:30 -07:00
  • a0331c9602 Merge branch 'dev' into agent-master agent/0.82.0 agent/0.81.0 Brett Bertocci 2018-05-16 16:08:05 -07:00
  • c3b0f0d96d Fix Travis CI Gianluca Borello 2018-05-09 10:43:39 -07:00
  • 2a7851c77b eBPF support for Falco Gianluca Borello 2018-05-09 09:49:41 -07:00
  • cb5db7486b Merge branch 'dev' into agent-master agent/0.80.2 Thom van Os 2018-05-04 11:14:44 -07:00
  • 512a36dfe1 Conditional rules (#364) Mark Stemm 2018-05-03 14:24:32 -07:00
  • 73e1ae616a Don't make driver compilation fail when kernel is compiled with CONFIG_ORC_UNWINDER or CONFIG_STACK_VALIDATION. (#362) David Archer 2018-04-30 17:30:39 -04:00
  • b496116fe3 Don't make driver compilation fail when kernel is compiled with CONFIG_ORC_UNWINDER or CONFIG_STACK_VALIDATION. (#362) David Archer 2018-04-30 17:30:39 -04:00
  • c30c5a7a62 Merge branch 'dev' into agent-master agent/0.80.1 Luca Marturana 2018-04-26 13:17:01 -07:00
  • 2a0911dcfd Merge branch 'dev' 0.10.0 Mark Stemm 2018-04-24 16:21:18 -07:00
  • af57f2b5c8 Update CHANGELOG/README for 0.10.0 (#358) Mark Stemm 2018-04-24 16:20:16 -07:00
  • 30ae3447c3 Print ignored events/syscalls with -i (#359) Mark Stemm 2018-04-24 16:07:28 -07:00
  • 9d3392e9b9 Use better way to skip falco events (#356) Mark Stemm 2018-04-24 15:23:51 -07:00
  • 6be4830342 Improve compatibility with falco 0.9.0 (#357) Mark Stemm 2018-04-24 11:23:16 -07:00
  • e6bf402117 Rule updates 2018 04.v1 (#350) Mark Stemm 2018-04-24 09:24:50 -07:00
  • 2b75439d08 Merge branch 'dev' into agent-master agent/0.80.0 Brett Bertocci 2018-04-23 07:10:44 -07:00
  • e922a849a9 Add tests catchall order (#355) Mark Stemm 2018-04-19 09:31:20 -07:00
  • b6b490e26e Add Rule for unexpected udp traffic (#320) Mark Stemm 2018-04-18 10:07:22 -07:00
  • ac190ca457 Properly support syscalls in filter conditions (#352) Mark Stemm 2018-04-17 17:14:45 -07:00
  • 96b4ff0ee5 Fix/Expand "Modify bin dirs" rule (#353) Mattia Pagnozzi 2018-04-14 00:17:23 +02:00
  • 5c58da2604 Start setting autodrop, which filters addl events (#351) Mark Stemm 2018-04-11 20:07:25 -07:00
  • c5b3097a65 Add ability to read rules files from directories (#348) Mark Stemm 2018-04-05 17:03:37 -07:00
  • 8389e44d7b Rotate logs (#347) Mark Stemm 2018-04-05 14:31:36 -07:00
  • a5daf8b058 Allow append skipped rules (#346) Mark Stemm 2018-04-05 10:28:45 -07:00
  • a0053dba18 Use distinct names for file and program output pointers. (#335) Joshua Carp 2018-04-05 01:07:00 -04:00
  • b99a4e5ccf Merge remote-tracking branch 'origin/dev' into agent-master agent/0.79.1 agent/0.79.0 Anoop Gupta 2018-04-04 15:29:24 -07:00
  • 88327abb41 Unit test for fd.net + in operator fixes (#343) Mark Stemm 2018-04-04 14:23:21 -07:00
  • 1516fe4eac Rule updates 2018 02.v3 (#344) Mark Stemm 2018-04-02 18:10:11 -07:00
  • 559240b628 Example puppet module for falco (#341) Mark Stemm 2018-03-28 11:50:04 -07:00
  • 2a3ca21779 Skip output json format (#342) Mark Stemm 2018-03-28 11:24:09 -07:00
  • a3f53138d3 Example showing cryptomining exploit (#336) Mark Stemm 2018-03-16 15:17:39 -07:00
  • 05c4ba1842 Merge branch 'dev' into agent-master agent/0.78.1 agent/0.78.0 Brett Bertocci 2018-03-08 14:47:06 -08:00
  • eb4feed1b6 Associate --validate with -V. (#334) Mark Stemm 2018-03-08 13:03:26 -08:00
  • 45d467656f Merge branch 'dev' into agent-master Brett Bertocci 2018-03-08 12:38:44 -08:00
  • ba6d6dbf9d Use gcc 5 by default to compile properly on Ubuntu Xenial, remove gcc 4.9 since CentOS does not work anyway due to glibc Luca Marturana 2018-02-27 09:35:30 -08:00
  • 38eb5b8741 Add more validations (#329) Mark Stemm 2018-02-26 16:59:18 -05:00
  • 947faca334 Rule updates 2018 02.v2 (#326) Mark Stemm 2018-02-26 13:26:28 -05:00
  • 0a66bc554a Improvements to falco daemonset configuration (#325) Mark Stemm 2018-02-20 12:57:59 -05:00
  • 4d8e982f78 + Add gdb in the development Docker image to help debugging (#323) Jean-Philippe Lachance 2018-02-20 11:54:13 -05:00
  • 52e8c16903 + Add the user_known_change_thread_namespace_binaries list to simplify "Change thread namespace" rule tweaks (#324) Jean-Philippe Lachance 2018-02-20 11:53:25 -05:00
  • 414c9a0eed Rule updates 2018 02.v1 (#321) Mark Stemm 2018-02-20 10:06:13 -05:00
  • 3912e6e44b Merge branch 'dev' into agent-master agent/0.77.0 agent/0.76.4 Thom van Os 2018-01-30 14:51:13 -08:00
  • 1564e87177 Rule updates 2018.01.v1 (#319) Mark Stemm 2018-01-25 16:06:15 -08:00
  • 958c0461bb Merge remote-tracking branch 'origin/dev' into agent-master agent/0.76.3 Anoop Gupta 2018-01-25 15:05:25 -08:00
  • 94df00e512 Merge branch 'dev' 0.9.0 Mark Stemm 2018-01-18 09:07:00 -08:00
  • 070a67d069 Use http dependencies (#317) Mark Stemm 2018-01-18 09:04:08 -08:00
  • 3ee76637f4 Merge branch 'dev' Mark Stemm 2018-01-17 20:30:28 -08:00