Commit Graph

  • 14c9d05f9f Improve error messages when loading rules. Mark Stemm 2016-11-28 10:02:33 -08:00
  • 882c6c94ea Fully specify FALCO_SHARE_DIR. Mark Stemm 2016-11-10 10:00:26 -08:00
  • 349372d733 Honor USE_BUNDLED_DEPS option for third-party libs Mark Stemm 2016-11-10 12:02:40 -08:00
  • 858a69bb2c Added envvar SYSDIG_SKIP_LOAD to Dockerfile to skip kernel module manipulation Carl Sverre 2016-10-26 13:18:24 -07:00
  • 1d0c9b1714 Merge pull request #169 from jcoetzee/systemd agent/0.49.1 agent/0.49.0 Mark Stemm 2016-12-16 11:43:07 -08:00
  • 8aa9c21d11 Merge pull request #168 from jcoetzee/fail2ban Mark Stemm 2016-12-16 09:38:57 -08:00
  • 64ecd157fd Add systemd as a login binary Jonathan Coetzee 2016-12-16 11:27:43 +02:00
  • 2bad529d33 Add fail2ban-server as trusted binary Jonathan Coetzee 2016-12-16 11:09:45 +02:00
  • 09a9ab4f85 Merge pull request #164 from draios/revert-163-dev Mark Stemm 2016-12-14 18:29:27 -08:00
  • 39e9043ac7 Revert "Add fail2ban-server as spawn shell trusted binary" Mark Stemm 2016-12-14 18:28:37 -08:00
  • f4abec4639 Merge pull request #163 from jcoetzee/dev Mark Stemm 2016-12-14 18:28:16 -08:00
  • bed5ab4f0c Add fail2ban-server as spawn shell trusted binary Jonathan Coetzee 2016-12-15 00:12:31 +02:00
  • 4f645c49e1 Use sinsp utils version of get time. agent/0.48.0 Mark Stemm 2016-12-08 10:59:47 -08:00
  • 54b30bc248 Add rate-limiting for notifications Mark Stemm 2016-12-07 16:25:58 -08:00
  • b509c4f0c8 Fix misleading variable name. Mark Stemm 2016-12-07 16:24:52 -08:00
  • af8d6c9d10 Make google_containers/kube-proxy a trusted image. Mark Stemm 2016-12-07 15:15:36 -08:00
  • ef08478bb7 Add log levels. Mark Stemm 2016-12-07 16:13:12 -08:00
  • a616301bd9 Cache formatters. Mark Stemm 2016-12-06 11:34:30 -08:00
  • 8e2a3ef5c3 Modify plotting script to handle drop stats. Mark Stemm 2016-12-05 18:08:52 -08:00
  • 47bd6af69a Add ability to write "extra" stuff to stats file. Mark Stemm 2016-12-05 11:59:55 -08:00
  • d1d0dbdbde Add ability to write capture stats to a file. Mark Stemm 2016-12-05 10:11:41 -08:00
  • 212fd9353e Push formatter on lua stack only if does not throw exceptions agent/0.47.0 Luca Marturana 2016-12-02 16:13:37 +01:00
  • 28558959f3 Merge pull request #153 from djcross/dnf Mark Stemm 2016-12-01 17:51:58 -08:00
  • a8662c60da Adding DNF as non-alerting for RPM and package management Daniel Cross 2016-12-02 11:52:08 +11:00
  • b3c691e920 Prevent rule_result from leaking on error. Mark Stemm 2016-12-01 09:29:17 -08:00
  • ded3ee5bed Add unit test for rule with invalid output. Mark Stemm 2016-11-28 14:41:20 -08:00
  • 064b39f2be Validate rule outputs when loading rules. Mark Stemm 2016-11-28 14:39:17 -08:00
  • 2961eb4d21 Move container.info handling to falco engine. Mark Stemm 2016-11-28 11:31:36 -08:00
  • 704eb57e3c Allow run_performance_tests to run test_mm. Mark Stemm 2016-11-28 14:54:14 -08:00
  • 9ca8ed96b9 Improve error messages when loading rules. Mark Stemm 2016-11-28 10:02:33 -08:00
  • 8b18315c1e Fully specify FALCO_SHARE_DIR. agent/0.46.0 agent/0.45.0 agent/0.44.0 agent/0.43.0 Mark Stemm 2016-11-10 10:00:26 -08:00
  • f95a0ead62 Honor USE_BUNDLED_DEPS option for third-party libs Mark Stemm 2016-11-10 12:02:40 -08:00
  • b1ad9e644e Added envvar SYSDIG_SKIP_LOAD to Dockerfile to skip kernel module manipulation Carl Sverre 2016-10-26 13:18:24 -07:00
  • 94fcc5399e Updating for 0.4.0. 0.4.0 Mark Stemm 2016-10-25 09:27:20 -07:00
  • 8a2924ad72 Updating for 0.4.0. Mark Stemm 2016-10-25 09:27:20 -07:00
  • da61134463 Rule fixes for dragent. Mark Stemm 2016-10-24 13:22:33 -07:00
  • 4189bb72da Add stats on events processed/dropped. Mark Stemm 2016-10-21 15:30:47 -07:00
  • d2d6118b9b Add ability to write trace files. Mark Stemm 2016-10-21 15:42:02 -07:00
  • 4915fdfc3a Add k8s binaries as trusted programs Mark Stemm 2016-10-14 17:25:19 -07:00
  • b855066dcb Allow falco to spawn shells in containers. Mark Stemm 2016-10-14 16:51:41 -07:00
  • ae7f5eb631 Fix logic for detecting conf files. Mark Stemm 2016-10-14 13:15:37 -07:00
  • 5f9f5c47d1 Add k8s/mesos/container info to rule outputs Mark Stemm 2016-10-13 14:48:32 -07:00
  • c6b433c2df Alphabetize command line options. Mark Stemm 2016-10-13 14:47:00 -07:00
  • 29cc8ee571 Add notes on how to post to slack webhooks. Mark Stemm 2016-10-12 17:08:28 -07:00
  • c66b6402d8 Add jq to docker images. Mark Stemm 2016-10-12 17:05:07 -07:00
  • 2e5ed34357 Add exfiltration action, env-specified actions. Mark Stemm 2016-10-07 15:36:53 -07:00
  • 3e1117d746 Add license comments to all source code. Mark Stemm 2016-10-07 10:51:25 -07:00
  • 7fddaf2499 Install gcc-4.9 from Debian Jessie repositories Mark Stemm 2016-09-30 09:39:01 -07:00
  • 28e9478dbb Fix lua stack leak. Mark Stemm 2016-09-23 15:34:32 -07:00
  • ae0ba57306 Add the new pmatch operator. Mark Stemm 2016-09-22 14:57:43 -07:00
  • a0b26def13 Reduce FPs related to Kubernetes. Mark Stemm 2016-09-14 13:53:59 -07:00
  • 4fc2870c59 New rules related to containers. Mark Stemm 2016-09-08 16:20:30 -07:00
  • 2fad859600 Parser changes to support new sysdig features Mark Stemm 2016-09-08 16:18:53 -07:00
  • bef628dc05 Include condition in compilation errors. Mark Stemm 2016-09-08 16:15:10 -07:00
  • 1db2339ece Add test for enabled flag. Mark Stemm 2016-09-03 08:40:01 -07:00
  • f68fba103e Support enabled flag for rules. Mark Stemm 2016-09-03 08:37:35 -07:00
  • 897df28036 Add regression tests for configurable outputs. Mark Stemm 2016-08-23 14:18:48 -07:00
  • 6ab0139532 Fix output methods that take configurations. Mark Stemm 2016-08-23 14:15:52 -07:00
  • 24c21307d0 Don't alert on falco program notifications. Mark Stemm 2016-08-23 14:12:28 -07:00
  • da77df142f Change rule names to be human readable. Mark Stemm 2016-08-22 20:19:08 -07:00
  • 81a145fd4f Verifying rule names can have spaces. Mark Stemm 2016-08-22 19:34:54 -07:00
  • fa4c2948bf Install falco rules with configurable filename. Mark Stemm 2016-08-17 13:24:25 -07:00
  • e49c3e68e7 Improve ruleset based on falco event-generator. Mark Stemm 2016-08-12 14:17:13 -07:00
  • f64148999a Program/docker image that performs bad activities. Mark Stemm 2016-08-11 16:37:07 -07:00
  • 30b1f23b17 Handle dbus-daemon-launch-helper. Mark Stemm 2016-08-10 14:15:26 -07:00
  • 20d81523a1 Eliminate FPs. Mark Stemm 2016-08-10 13:48:06 -07:00
  • c140b23678 Add tests for multiple files, disabled rules. Mark Stemm 2016-08-04 12:01:54 -07:00
  • 3fbcb35e91 Add configurable event dropping for falco engine. Mark Stemm 2016-07-27 15:18:37 -07:00
  • f547dc97ab Move falco engine to its own library. Mark Stemm 2016-07-20 15:31:34 -07:00
  • 917d66e9e8 Create embeddable falco engine. Mark Stemm 2016-07-15 13:26:14 -07:00
  • 73e52e1e91 Don't run the spawned program in a shell. Mark Stemm 2016-08-09 10:32:40 -07:00
  • 318286f8c4 Add ignores for test-related files. Mark Stemm 2016-07-26 08:05:15 -07:00
  • 0c44711e76 Fix docker builds. Mark Stemm 2016-08-05 17:51:54 -07:00
  • f98ec60c88 Rule fixes for dragent. Mark Stemm 2016-10-24 13:22:33 -07:00
  • 0211a94f60 Add stats on events processed/dropped. Mark Stemm 2016-10-21 15:30:47 -07:00
  • e0e640c67f Add ability to write trace files. Mark Stemm 2016-10-21 15:42:02 -07:00
  • faef5621dd Add k8s binaries as trusted programs Mark Stemm 2016-10-14 17:25:19 -07:00
  • e543fbf247 Allow falco to spawn shells in containers. agent/0.42.0 Mark Stemm 2016-10-14 16:51:41 -07:00
  • f761ddff9f Fix logic for detecting conf files. Mark Stemm 2016-10-14 13:15:37 -07:00
  • 1f7c711a69 Merge pull request #134 from draios/add-k8s-mesos-support Mark Stemm 2016-10-13 15:15:48 -07:00
  • 880c39633d Add k8s/mesos/container info to rule outputs Mark Stemm 2016-10-13 14:48:32 -07:00
  • 3bb84f5498 Alphabetize command line options. Mark Stemm 2016-10-13 14:47:00 -07:00
  • 7e60b4b6c2 Merge pull request #133 from draios/add-jq-to-docker Mark Stemm 2016-10-12 18:12:08 -07:00
  • 1a78e45d7a Merge pull request #132 from draios/event-generator-env Mark Stemm 2016-10-12 18:11:40 -07:00
  • 20440912b7 Add notes on how to post to slack webhooks. Mark Stemm 2016-10-12 17:08:28 -07:00
  • f6720d3993 Add jq to docker images. Mark Stemm 2016-10-12 17:05:07 -07:00
  • 82903359cb Add exfiltration action, env-specified actions. Mark Stemm 2016-10-07 15:36:53 -07:00
  • 144789475e Merge pull request #126 from draios/add-licenses agent/0.41.0 agent/0.40.0 Mark Stemm 2016-10-07 11:40:38 -07:00
  • 644f017b2a Add license comments to all source code. Mark Stemm 2016-10-07 10:51:25 -07:00
  • 5008003600 Merge pull request #125 from draios/add-pmatch Mark Stemm 2016-10-03 11:20:34 -07:00
  • 82597c9830 Merge pull request #124 from draios/fix-docker-gcc Mark Stemm 2016-09-30 10:07:46 -07:00
  • 4354043a44 Install gcc-4.9 from Debian Jessie repositories Mark Stemm 2016-09-30 09:39:01 -07:00
  • 08d204dde9 Merge pull request #123 from draios/fix-stack-leak Mark Stemm 2016-09-23 16:02:01 -07:00
  • 9a5e08d712 Fix lua stack leak. Mark Stemm 2016-09-23 15:34:32 -07:00
  • 930b38b894 Add the new pmatch operator. Mark Stemm 2016-09-22 14:57:43 -07:00
  • 889b252a3f Merge pull request #121 from draios/improve-docker-rules Mark Stemm 2016-09-15 15:36:37 -05:00
  • 164d5016ef Reduce FPs related to Kubernetes. Mark Stemm 2016-09-14 13:53:59 -07:00
  • 6e9241a983 Merge pull request #120 from draios/addl-container-rules Mark Stemm 2016-09-12 15:01:51 -05:00
  • 23e3e99162 New rules related to containers. Mark Stemm 2016-09-08 16:20:30 -07:00
  • f632fa62b0 Parser changes to support new sysdig features Mark Stemm 2016-09-08 16:18:53 -07:00