Commit Graph

  • e1293a7eca Add some additional command lines. Mark Stemm 2017-07-05 14:14:44 -07:00
  • 02645e7a2e Be consistent about nested quotes. Mark Stemm 2017-07-05 14:14:13 -07:00
  • c8c0a97f64 Let Xvfb setuid. Mark Stemm 2017-07-05 14:12:54 -07:00
  • d96cf4c369 Allow programs to write below /etc/logstash Mark Stemm 2017-07-05 14:12:05 -07:00
  • e2be47e3c2 Allow update-ca-certi(ficates) to write below /etc Mark Stemm 2017-07-05 14:11:11 -07:00
  • ee2c668746 Add systemd as a program that can write below /etc Mark Stemm 2017-07-05 14:09:56 -07:00
  • 09e1caf4bb add mesos-executor as a mesos binary. Mark Stemm 2017-07-05 14:09:04 -07:00
  • 68d29fc906 Add shell management programs. Mark Stemm 2017-07-05 14:08:05 -07:00
  • 7ac49a2f99 Also allow sysdig agent to setuid. Mark Stemm 2017-06-28 11:38:14 -07:00
  • e6006e3787 Add additional dpkg binary Mark Stemm 2017-06-27 18:06:36 -07:00
  • 5d856ef97a Let _apt user setuid to itself. Mark Stemm 2017-06-27 18:00:29 -07:00
  • 3b486fb6c6 Let npm spawn shells in containers. Mark Stemm 2017-06-27 18:00:09 -07:00
  • daedcf172f Let hhvm spawn shells. Mark Stemm 2017-06-26 13:12:56 -07:00
  • 414a4aaba7 Another shell command line. Mark Stemm 2017-06-26 11:15:17 -07:00
  • 5382aa4e3b More shell spawners Mark Stemm 2017-06-26 11:08:20 -07:00
  • 3a60caa9ed Merge pull request #285 from draios/add-unbuffered-output Mark Stemm 2017-10-06 21:51:53 -07:00
  • 7a31c59fe4 Add ability to make outputs unbuffered Mark Stemm 2017-10-06 21:03:59 -07:00
  • 8167510694 Merge pull request #284 from draios/add-full-falco-share-dir Mark Stemm 2017-10-06 17:04:12 -07:00
  • e92ca7574e Merge pull request #283 from draios/long-lived-program-output Mark Stemm 2017-10-06 16:01:46 -07:00
  • ae73f75d81 add an absolute-path version of FALCO_SHARE_DIR Mark Stemm 2017-10-06 15:58:30 -07:00
  • 1635d08df0 Allow outputs to keep file/program open Mark Stemm 2017-10-06 14:57:41 -07:00
  • 5420d0e3a0 WIP on long-lived program outputs. Mark Stemm 2017-10-06 13:32:51 -07:00
  • 72014f3522 Merge pull request #282 from draios/fields-in-json-output Mark Stemm 2017-10-06 15:02:49 -07:00
  • aed1897cf1 Add individual event fields to json output Mark Stemm 2017-10-06 13:13:22 -07:00
  • 1e33358742 Merge pull request #278 from draios/handle-default-file Mark Stemm 2017-10-06 09:08:45 -07:00
  • dca7686e47 Merge pull request #281 from draios/filter-by-severity Mark Stemm 2017-10-06 09:08:26 -07:00
  • 5c09ef2c3f Fully remove package. Mark Stemm 2017-10-05 18:29:49 -07:00
  • 8641f3c958 Rework config file handling Mark Stemm 2017-09-25 07:08:49 -07:00
  • 283c6eea99 Fully remove falco package. Mark Stemm 2017-10-05 18:01:34 -07:00
  • aa073586f1 Add ability to filter events by priority/cleanups Mark Stemm 2017-10-05 17:20:54 -07:00
  • 498d083980 Merge branch 'dev' into agent-master agent/0.69.0 Mark Stemm 2017-09-25 10:58:36 -07:00
  • c41bcbd240 Merge pull request #277 from draios/append-macros-rules Mark Stemm 2017-09-25 10:56:23 -07:00
  • c7d61305cc Merge pull request #263 from draios/govt-cla Mark Stemm 2017-09-22 17:27:01 -07:00
  • ab3da5dfcf Update govt cla links. Mark Stemm 2017-09-22 17:25:16 -07:00
  • 95bb96e6ec Merge pull request #269 from dkerwin/add_keepalived_to_run_shell_cmd Mark Stemm 2017-09-22 17:19:54 -07:00
  • 1666d03afc Merge pull request #270 from dkerwin/add_gitlab_ee Mark Stemm 2017-09-22 17:19:14 -07:00
  • a38f7f181b Add ability to append to rules/macros Mark Stemm 2017-09-22 17:08:00 -07:00
  • 2d0963e97c CMakeLists: add messages for lpeg, lyaml and libyaml Riccardo Schirone 2017-09-21 11:47:01 -07:00
  • fbdeb26e99 Merge pull request #276 from draios/fix-readme Mark Stemm 2017-09-19 16:16:27 -07:00
  • 7e4d9f5b51 Fix readme. Mark Stemm 2017-09-19 16:14:30 -07:00
  • 5bb94c81ed Merge pull request #275 from draios/change-example-port Mark Stemm 2017-09-18 13:55:22 -07:00
  • 30ebfd4bcc Switch port to 8181. Mark Stemm 2017-09-18 08:46:50 -07:00
  • 64145ba961 Add official gitlab EE docker image to list of known shell spawning images. sysdig-CLA-1.0-signed-off-by: Daniel Kerwin <daniel@gini.net> Daniel Kerwin 2017-09-05 13:41:05 +02:00
  • 598cbbe5e7 Add keepalived to list oh shell spawning binaries. sysdig-CLA-1.0-signed-off-by: Daniel Kerwin <daniel@gini.net> Daniel Kerwin 2017-09-04 22:02:30 +02:00
  • 6fd7f0d628 Merge branch 'dev' into agent-master agent/0.68.0 agent/0.67.0 agent/0.66.0 Luca Marturana 2017-08-23 10:30:27 +02:00
  • 240a8ffffa Merge pull request #264 from draios/mergable-lists Mark Stemm 2017-08-10 11:08:36 -07:00
  • d1265ff520 Merge pull request #265 from draios/remove-trailing-newline-output Mark Stemm 2017-08-10 09:44:39 -07:00
  • 0bc2d4f162 Automated tests for list append. Mark Stemm 2017-08-09 16:47:53 -07:00
  • 2c189d6a60 Add ability to append to lists. Mark Stemm 2017-08-09 16:45:47 -07:00
  • ebed9f8dfd Remove trailing newlines from output Mark Stemm 2017-08-09 17:53:53 -07:00
  • ed2586eafb adding govt CLA Chris Crane 2017-08-04 13:59:17 -07:00
  • 9d6fe878e1 Merge pull request #262 from draios/allow-dots-in-paths Mark Stemm 2017-08-04 11:56:15 -07:00
  • de520a60fb Allow dots in paths. Mark Stemm 2017-08-04 11:06:51 -07:00
  • d6fe29b47d Merge branch 'dev' into agent-master agent/0.65.1 agent/0.65.0 Thom van Os 2017-07-27 14:04:16 -07:00
  • 5c1aa8dc44 Merge pull request #260 from draios/fix-kernel-path Mark Stemm 2017-07-14 10:08:41 -07:00
  • 8d57d18959 Use uname -r for kernel modules Mark Stemm 2017-07-14 09:17:28 -07:00
  • a71cbcd7ee Merge branch 'dev' into agent-master agent/0.64.0 agent/0.63.1 agent/0.63.0 Riccardo Schirone 2017-07-03 12:18:10 +02:00
  • 3349decd22 Merge pull request #258 from draios/better-list-substitution Mark Stemm 2017-06-30 16:01:05 -07:00
  • eecc92736b Add unit tests for list substitution/order Mark Stemm 2017-06-30 15:11:05 -07:00
  • f1b44da90c Perform list substitution only on word boundaries Mark Stemm 2017-06-30 15:03:33 -07:00
  • 42e50356cf Merge pull request #257 from draios/validate-macros Mark Stemm 2017-06-27 17:18:13 -07:00
  • 9e7ce4d36f Also validate macros at parse time. Mark Stemm 2017-06-27 16:44:42 -07:00
  • 2991ea423a Merge pull request #254 from draios/dont-trim-strings Mark Stemm 2017-06-20 13:48:31 -07:00
  • 481582ca09 Don't trim quoted strings Mark Stemm 2017-06-20 11:47:00 -07:00
  • 38f488bfda Beta rule updates (#247) Mark Stemm 2017-06-19 11:28:15 -07:00
  • 42a3dd1ea3 Merge branch 'osx-install' into dev Riccardo Schirone 2017-06-19 10:08:59 +02:00
  • b8743385e8 Fix installation of falco on OS X (no driver, /usr not writable) Riccardo Schirone 2017-06-16 11:34:22 +02:00
  • 87caa55b17 Merge pull request #248 from draios/fix-nodejs-example Mark Stemm 2017-06-14 16:12:59 -07:00
  • 646aed5b8b Explicitly spawn program via shell. Mark Stemm 2017-06-14 15:26:17 -07:00
  • 6bfff60fc3 Add *.pyc to .gitignore Brett 2017-06-14 13:04:14 -07:00
  • 99d6bccc81 Merge branch 'dev' into agent-master agent/0.62.0 agent/0.61.0 Mark Stemm 2017-06-06 10:13:23 -07:00
  • 809d20c294 Merge pull request #246 from draios/dev 0.7.0 Mark Stemm 2017-05-30 13:30:39 -07:00
  • 6ebbbd47d8 Merge pull request #245 from draios/prepare-for-0-7-0 Mark Stemm 2017-05-30 12:52:44 -07:00
  • 69ebcdd8e9 Update for 0.7.0. Mark Stemm 2017-05-30 09:21:50 -07:00
  • 74c97489bd Merge pull request #244 from draios/better-priorities Mark Stemm 2017-05-25 13:51:12 -07:00
  • 5bafa198c6 Update automated tests to handle new priority lvls Mark Stemm 2017-05-25 12:15:35 -07:00
  • edce729bd9 Use a wider range of priorities in rules. Mark Stemm 2017-05-24 18:54:14 -07:00
  • f426c4292d Merge pull request #243 from draios/falco-fps Mark Stemm 2017-05-24 13:18:08 -07:00
  • 277d8ab887 Merge pull request #242 from draios/container-shell-with-tty Mark Stemm 2017-05-24 10:49:03 -07:00
  • 697d718739 Merge pull request #237 from dkerwin/add_gitlab_mon_command Mark Stemm 2017-05-24 10:29:28 -07:00
  • 307a484425 Merge pull request #241 from sublimino/patch-1 Mark Stemm 2017-05-24 10:28:22 -07:00
  • c5a964e651 Address some setns FPs. Mark Stemm 2017-05-24 10:17:57 -07:00
  • 612fbb00d9 fix: invalid spaces in README markdown Andrew Martin 2017-05-17 18:11:13 +01:00
  • e88612a1af Add rule for shell with terminal in container. Mark Stemm 2017-05-23 13:37:44 -07:00
  • b0ae29c23a Merge branch 'dev' 0.6.1 Mark Stemm 2017-05-15 11:12:11 -07:00
  • a86e3fc748 Merge pull request #239 from draios/update-for-0.6.1 Mark Stemm 2017-05-15 11:07:44 -07:00
  • e97056569f Update for 0.6.1. Mark Stemm 2017-05-15 10:37:57 -07:00
  • f92f74eaa8 Merge branch 'dev' into agent-master agent/0.60.0 agent/0.59.0 Brett 2017-05-05 12:01:57 -07:00
  • 0e163b892f Merge pull request #238 from draios/claim-multiple-tokens Mark Stemm 2017-05-02 14:04:23 -07:00
  • 4d148ce28f Add ability to claim multiple tokens. Mark Stemm 2017-05-02 11:46:20 -07:00
  • 974d864b3b Add gitlab-mon command Daniel Kerwin 2017-05-02 17:27:50 +02:00
  • a3c83e7f6e Merge pull request #236 from draios/expose-tokens Mark Stemm 2017-04-27 13:19:47 -07:00
  • dafc4c2b88 Expose last seen time. Mark Stemm 2017-04-27 12:03:02 -07:00
  • c066be3905 Allow the initial time to be externally provided. Mark Stemm 2017-04-27 12:02:21 -07:00
  • f5ce6752be Add ability to get number of tokens. Mark Stemm 2017-04-27 11:22:19 -07:00
  • 060db62644 Merge pull request #235 from draios/fix-token-bucket-rate Mark Stemm 2017-04-27 08:12:25 -07:00
  • 1ad91c05f5 Fix token bucket rate Mark Stemm 2017-04-26 19:02:04 -07:00
  • 76876bc3ae Merge pull request #234 from draios/token-bucket-external-time Mark Stemm 2017-04-25 17:40:50 -07:00
  • e183de3b89 Allow rate to be less than 1. Mark Stemm 2017-04-25 13:02:34 -07:00
  • 87a6c74290 Allow for an external clock in token bucket. Mark Stemm 2017-04-25 10:01:25 -07:00