Commit Graph

  • d42d0e2dd1 Merge branch 'dev' into agent-master agent/0.58.0 agent/0.57.0 Luca Marturana 2017-04-14 14:57:56 +02:00
  • 718113f7bd Merge pull request #232 from draios/remove-apache-shell-spawner Mark Stemm 2017-04-07 13:05:30 -07:00
  • 955e1d78b1 Don't allow apache2 to spawn shells in containers Mark Stemm 2017-04-06 15:24:21 -07:00
  • 135b4d9975 Merge branch 'dev' into agent-master agent/0.56.0 Luca Marturana 2017-03-30 14:46:44 +02:00
  • d1b6b2be87 Merge pull request #229 from draios/dev 0.6.0 Mark Stemm 2017-03-29 16:00:06 -07:00
  • 0cabeddf49 Merge pull request #228 from draios/prepare-for-0.6.0 Mark Stemm 2017-03-29 15:11:05 -07:00
  • 6127ca6e41 Update k8s README Mark Stemm 2017-03-29 14:39:27 -07:00
  • a2a707f771 Update changelog/readme for 0.6.0. Mark Stemm 2017-03-29 11:36:44 -07:00
  • 3c2051176e Merge pull request #224 from draios/own-driver 0.6.0-test Mark Stemm 2017-03-24 21:35:48 -07:00
  • 73fbbdb577 Add automated tests for packages/driver installs Mark Stemm 2017-03-20 16:54:45 -07:00
  • 52b006e875 Add ability to run live for specific duration Mark Stemm 2017-03-22 13:06:23 -07:00
  • f72182d9af Merge pull request #226 from draios/fix-k8s-daemonset Mark Stemm 2017-03-21 14:44:57 -07:00
  • 8d58589c39 Make sure entrypoint runs for docker pod. Mark Stemm 2017-03-21 14:07:19 -07:00
  • ec5adfe892 Build and package standalone falco kernel module Mark Stemm 2017-03-20 15:36:03 -07:00
  • a25166b7ac Merge branch 'dev' into agent-master agent/0.55.0 Luca Marturana 2017-03-20 15:45:29 +01:00
  • 18900089f3 Merge pull request #221 from dkerwin/erl_child_setup_spawn_in_container Mark Stemm 2017-03-14 20:05:51 -07:00
  • 490a3fef00 Merge pull request #222 from draios/add-k8s-example Mark Stemm 2017-03-07 14:36:33 -05:00
  • 5e8dc8bce4 Add falco,event generator files for k8s. Mark Stemm 2017-03-06 10:45:56 -08:00
  • d29742a617 Add erl_child_setup to shell spawning binaries in a container. Daniel Kerwin 2017-03-06 21:33:44 +01:00
  • 353defe362 Merge pull request #220 from dkerwin/add_gitlab_binaries Mark Stemm 2017-03-06 11:13:28 -08:00
  • 6b9620084f Merge pull request #218 from draios/add-erl-child-setup Mark Stemm 2017-03-06 11:07:25 -08:00
  • 537565d27a Add support for gitlab omnibus containers/pod (https://docs.gitlab.com/omnibus/README.html). Daniel Kerwin 2017-03-06 17:20:13 +01:00
  • b2529f1108 Add erl_child_setup as a shell spawner. Mark Stemm 2017-03-06 08:00:30 -08:00
  • 561c388dab Merge pull request #212 from draios/use-formatter-cache Mark Stemm 2017-02-27 21:10:44 -08:00
  • db469c6514 Use sysdig's formatter cache. Mark Stemm 2017-02-27 11:59:51 -08:00
  • fb36af12cf Return lua errors not falco_exceptions Mark Stemm 2017-02-27 11:57:36 -08:00
  • 7d711dbb32 Merge branch 'compile-osx2' into dev Riccardo Schirone 2017-02-23 18:42:27 +01:00
  • 58357d3bf9 CMakeLists: set ExternalProject dependencies only when necessary Riccardo Schirone 2017-02-22 14:40:44 +01:00
  • 8b98a61bcc CMakeLists: fix compilation on OS X Riccardo Schirone 2017-02-22 14:25:34 +01:00
  • f70a7aef6f CMakeLists: fix whitespaces Riccardo Schirone 2017-02-22 14:18:02 +01:00
  • c12ab700ec engine: throw an exception if lua cannot be opened Riccardo Schirone 2017-02-22 14:16:16 +01:00
  • 38f562ea89 Merge pull request #209 from draios/address-falco-beta-fps Mark Stemm 2017-02-21 16:21:18 -08:00
  • f1aadef054 More changes to address FPs. Mark Stemm 2017-02-21 14:58:55 -08:00
  • 800a3f1ea1 Merge branch 'dev' into agent-master agent/0.54.0 Luca Marturana 2017-02-21 11:47:36 +01:00
  • 1c21b3bc8a Merge pull request #206 from draios/add-tags Mark Stemm 2017-02-13 13:18:27 -08:00
  • 185729d5d6 Address feedback from PR Mark Stemm 2017-02-10 11:53:39 -08:00
  • 0a69fc0c85 Tag existing falco ruleset. Mark Stemm 2017-02-03 17:59:38 -08:00
  • 88faa7c1e7 Add automated tests for tagged rules Mark Stemm 2017-02-03 17:36:55 -08:00
  • a0a6914b6a Add support for tagging rules. Mark Stemm 2017-02-03 18:08:48 -08:00
  • 31464de885 Merge branch 'dev' into agent-master agent/0.53.0 Luca Marturana 2017-02-07 11:06:22 +01:00
  • df08a80a12 Merge pull request #207 from draios/address-addl-falco-fps Mark Stemm 2017-02-06 16:46:11 -08:00
  • 8a1f62c610 Additional changes to reduce FPs. Mark Stemm 2017-02-06 15:57:54 -08:00
  • 1e205db8aa Use right name for event-generator. Mark Stemm 2017-02-03 17:19:40 -08:00
  • 9b308d2793 Merge branch 'dev' into agent-master agent/0.52.0 Luca Marturana 2017-02-02 12:35:47 +01:00
  • 3d5789a297 Merge pull request #200 from draios/ndis-hids-etc-rule-updates Mark Stemm 2017-02-01 17:37:09 -08:00
  • b9d0857362 Rule updates related to other security products Mark Stemm 2017-01-26 15:52:51 -08:00
  • 1afbaba632 Merge pull request #205 from draios/demo-improvements Mark Stemm 2017-02-01 16:24:05 -08:00
  • e0a5034a43 Ensure falco-event-generator actions are detected. Mark Stemm 2017-02-01 14:55:45 -08:00
  • 6356490b1c Misc demo improvements. Mark Stemm 2017-02-01 14:51:18 -08:00
  • 511d0997da Merge pull request #204 from draios/cmake-dependencies Mark Stemm 2017-01-31 14:40:05 -08:00
  • 6f9f1e4792 CMakeLists: add dependencies to lyaml project Riccardo Schirone 2017-01-31 21:57:26 +00:00
  • a99f09da96 Merge branch 'dev' into agent-master Luca Marturana 2017-01-31 11:47:33 +01:00
  • c09b6390a3 Merge pull request #202 from draios/more-spurious-alerts Mark Stemm 2017-01-27 12:21:22 -08:00
  • 3f2814259a Address more spurious alerts Mark Stemm 2017-01-27 11:49:02 -08:00
  • b04bccd1a7 Merge pull request #201 from draios/remove-cchh Mark Stemm 2017-01-27 10:14:51 -08:00
  • e21fecf0ef Remove cchh image. Mark Stemm 2017-01-27 09:03:25 -08:00
  • ceafeca87e Merge pull request #199 from draios/no-assert-travis-debug Mark Stemm 2017-01-26 10:55:32 -08:00
  • 9285aa59c1 Set -DNDEBUG for travis debug builds. Mark Stemm 2017-01-26 10:12:11 -08:00
  • 1e0ddba11a Merge branch 'dev' into agent-master agent/0.51.0 Luca Marturana 2017-01-25 18:08:35 +01:00
  • 34e17cb951 Several changes to reduce FPs Mark Stemm 2017-01-20 15:22:28 -08:00
  • bc83ac18a0 Allow shells spawned by ansible. Mark Stemm 2017-01-17 10:03:21 -08:00
  • 10d0c8f982 Add a local dockerfile variant. Mark Stemm 2017-01-05 11:08:39 -08:00
  • 8f53bcbb05 Patch jq 1.5 with a fix for security vulns. Mark Stemm 2017-01-03 16:22:51 -08:00
  • 7286b50f4d Update libcurl to 7.52.1. Mark Stemm 2016-12-29 17:14:07 -08:00
  • 4c60b7c1d2 Update openssl to 1.0.2j. Mark Stemm 2016-12-29 17:13:37 -08:00
  • 85480f32d6 Avoid FPs resulting from ubuntu weekly cron jobs Mark Stemm 2017-01-16 10:32:31 -08:00
  • 4139370df5 Merge branch 'agent-master' into dev Luca Marturana 2017-01-17 10:55:07 +01:00
  • b6d1101cb6 Merge branch 'agent-master' into dev agent/0.50.1 agent/0.50.0 Luca Marturana 2017-01-17 10:55:07 +01:00
  • 43d53bb09e Add exechealthz as a k8s binary. Mark Stemm 2017-01-12 09:04:09 -08:00
  • af3a708251 Improve comment Luca Marturana 2017-01-04 18:05:46 +01:00
  • f4bb49f1f5 Add test for truncated outputs. Mark Stemm 2017-01-03 11:12:56 -08:00
  • 362a6b7b9a Prefix outputs with * within the engine. Mark Stemm 2016-12-30 15:15:39 -08:00
  • 77a5429cae Add cchh/sysdig as a trusted container. Mark Stemm 2016-12-30 11:05:34 -08:00
  • 9ecdf30314 tests for overriding rules/macros/lists Mark Stemm 2016-12-28 15:19:59 -08:00
  • 7c419b6d6b Allow any macro/list/rule to be overridden Mark Stemm 2016-12-28 15:08:00 -08:00
  • 767f2d5bb4 Add ability to clear loaded rules. Mark Stemm 2016-12-28 15:06:46 -08:00
  • 3cbf641ded Add confd/fleetctl as acceptable programs. Mark Stemm 2016-12-28 11:37:06 -08:00
  • e00181d553 Merge pull request #174 from draios/dev Mark Stemm 2016-12-22 13:25:32 -08:00
  • 4ab72d0391 Updating docs for 0.5.0. 0.5.0 Mark Stemm 2016-12-22 11:18:24 -08:00
  • 9e933ce5ba Add apt and apt-get as trusted shells Jonathan Coetzee 2016-12-17 11:53:11 +02:00
  • c3c6ec67f7 Add systemd as a login binary Jonathan Coetzee 2016-12-16 11:27:43 +02:00
  • 9062459669 Add fail2ban-server as trusted binary Jonathan Coetzee 2016-12-16 11:09:45 +02:00
  • 94cef1b541 Revert "Add fail2ban-server as spawn shell trusted binary" Mark Stemm 2016-12-14 18:28:37 -08:00
  • dd6b4fd7c0 Add fail2ban-server as spawn shell trusted binary Jonathan Coetzee 2016-12-15 00:12:31 +02:00
  • c6953e810b Use sinsp utils version of get time. Mark Stemm 2016-12-08 10:59:47 -08:00
  • 104c99c42e Add rate-limiting for notifications Mark Stemm 2016-12-07 16:25:58 -08:00
  • f2bfa584e4 Fix misleading variable name. Mark Stemm 2016-12-07 16:24:52 -08:00
  • 6f54a752a2 Make google_containers/kube-proxy a trusted image. Mark Stemm 2016-12-07 15:15:36 -08:00
  • 6c04f53d24 Add log levels. Mark Stemm 2016-12-07 16:13:12 -08:00
  • db67034338 Cache formatters. Mark Stemm 2016-12-06 11:34:30 -08:00
  • 2a2dcaf25d Modify plotting script to handle drop stats. Mark Stemm 2016-12-05 18:08:52 -08:00
  • e6aefef4eb Add ability to write "extra" stuff to stats file. Mark Stemm 2016-12-05 11:59:55 -08:00
  • 7db8e0921c Add ability to write capture stats to a file. Mark Stemm 2016-12-05 10:11:41 -08:00
  • ea97325708 Push formatter on lua stack only if does not throw exceptions Luca Marturana 2016-12-02 16:13:37 +01:00
  • 3840622984 Adding DNF as non-alerting for RPM and package management Daniel Cross 2016-12-02 11:52:08 +11:00
  • 0ee32178b7 Prevent rule_result from leaking on error. Mark Stemm 2016-12-01 09:29:17 -08:00
  • 8b116c2ad1 Add unit test for rule with invalid output. Mark Stemm 2016-11-28 14:41:20 -08:00
  • 37388c56ff Validate rule outputs when loading rules. Mark Stemm 2016-11-28 14:39:17 -08:00
  • 0d46fcf819 Move container.info handling to falco engine. Mark Stemm 2016-11-28 11:31:36 -08:00
  • c6c074ef60 Allow run_performance_tests to run test_mm. Mark Stemm 2016-11-28 14:54:14 -08:00