Commit Graph

  • 33b9ef5d50 Include condition in compilation errors. Mark Stemm 2016-09-08 16:15:10 -07:00
  • fbcddba06a Merge pull request #119 from draios/add-enabled-flag Mark Stemm 2016-09-07 10:40:07 -05:00
  • 5644919e70 Add test for enabled flag. Mark Stemm 2016-09-03 08:40:01 -07:00
  • f974922f84 Support enabled flag for rules. Mark Stemm 2016-09-03 08:37:35 -07:00
  • 08c3befe25 Merge pull request #117 from draios/fix-outputs Mark Stemm 2016-08-24 10:06:12 -07:00
  • ef52e627ec Add regression tests for configurable outputs. Mark Stemm 2016-08-23 14:18:48 -07:00
  • 23a9b6e1b0 Fix output methods that take configurations. Mark Stemm 2016-08-23 14:15:52 -07:00
  • 3ee1c0f602 Don't alert on falco program notifications. Mark Stemm 2016-08-23 14:12:28 -07:00
  • ceee146f39 Merge pull request #116 from draios/rule-names-with-spaces Mark Stemm 2016-08-23 07:34:04 -07:00
  • ceedd772c7 Change rule names to be human readable. Mark Stemm 2016-08-22 20:19:08 -07:00
  • 2731fd5ae1 Verifying rule names can have spaces. Mark Stemm 2016-08-22 19:34:54 -07:00
  • e717e3e3e0 Merge pull request #114 from draios/configurable-rules-filename Mark Stemm 2016-08-17 14:44:13 -07:00
  • 34fcce7c26 Install falco rules with configurable filename. Mark Stemm 2016-08-17 13:24:25 -07:00
  • 822770a154 Merge pull request #113 from draios/add-event-simulator Mark Stemm 2016-08-12 15:05:39 -07:00
  • 65f3725e76 Improve ruleset based on falco event-generator. Mark Stemm 2016-08-12 14:17:13 -07:00
  • 6e1f23b9a5 Program/docker image that performs bad activities. Mark Stemm 2016-08-11 16:37:07 -07:00
  • 2aa8a5c114 Merge pull request #112 from draios/fix-addl-false-positives Mark Stemm 2016-08-10 15:55:12 -07:00
  • 39ae7680a7 Handle dbus-daemon-launch-helper. Mark Stemm 2016-08-10 14:15:26 -07:00
  • 12391ee508 Eliminate FPs. Mark Stemm 2016-08-10 13:48:06 -07:00
  • dcaeebda77 Merge pull request #103 from draios/falco-engine Mark Stemm 2016-08-10 10:50:09 -07:00
  • f1748060c5 Add tests for multiple files, disabled rules. Mark Stemm 2016-08-04 12:01:54 -07:00
  • 09405e4fad Add configurable event dropping for falco engine. Mark Stemm 2016-07-27 15:18:37 -07:00
  • b1857eff35 Move falco engine to its own library. Mark Stemm 2016-07-20 15:31:34 -07:00
  • fc9690b1d3 Create embeddable falco engine. Mark Stemm 2016-07-15 13:26:14 -07:00
  • 03e6c1b3d9 Merge pull request #111 from draios/update-nodejs-example Mark Stemm 2016-08-09 11:00:07 -07:00
  • bf431cf222 Don't run the spawned program in a shell. Mark Stemm 2016-08-09 10:32:40 -07:00
  • b57eb8659f Add ignores for test-related files. Mark Stemm 2016-07-26 08:05:15 -07:00
  • f82288f373 Merge pull request #110 from draios/fix-docker-build Mark Stemm 2016-08-05 18:16:59 -07:00
  • a769373bb8 Fix docker builds. Mark Stemm 2016-08-05 17:51:54 -07:00
  • b6f08cc403 Merge pull request #109 from draios/dev 0.3.0 Mark Stemm 2016-08-05 12:35:31 -07:00
  • 2bc56118a8 Merge pull request #108 from draios/0-3-0-docs-changes Mark Stemm 2016-08-05 11:41:28 -07:00
  • 3d640c8a24 Update docs for 0.3.0 release. Mark Stemm 2016-08-05 11:15:46 -07:00
  • bae6eb64d6 Merge pull request #107 from draios/make-falco-drop-configurable Mark Stemm 2016-08-05 08:50:47 -07:00
  • 160ffe506b Add ability to run on all events. Mark Stemm 2016-08-04 16:49:12 -07:00
  • c4c5298f68 Merge pull request #106 from draios/add-agent-to-perf-tests Mark Stemm 2016-08-04 16:37:12 -07:00
  • 00107537b6 Merge pull request #105 from draios/add-process-output Mark Stemm 2016-08-04 16:20:48 -07:00
  • f05bb2b3ec Add ability to run agent for performance tests. Mark Stemm 2016-08-04 16:03:07 -07:00
  • d5dbe59d85 Add ability to write output to a program Mark Stemm 2016-08-04 15:50:30 -07:00
  • f7ed616535 Merge pull request #104 from draios/more-rule-perf-updates Mark Stemm 2016-08-02 15:15:47 -07:00
  • e04ac08fac More perf-related rule updates. Mark Stemm 2016-08-02 14:26:42 -07:00
  • 7a43007e0d Merge pull request #101 from draios/event-specific-filters Mark Stemm 2016-07-18 17:56:50 -07:00
  • 7b68fc2692 Add tests for event type rule identification Mark Stemm 2016-07-13 18:42:34 -07:00
  • ddedf595ba Rule updates related to event-specific filters Mark Stemm 2016-07-13 17:59:20 -07:00
  • b76423b31d Useful scripts to collect/display perf results. Mark Stemm 2016-06-10 15:35:15 -07:00
  • 8050009aa5 Add support for event-specific filters. Mark Stemm 2016-07-14 12:51:37 -07:00
  • 5955c00f9c Add a verbose flag. Mark Stemm 2016-07-13 17:57:11 -07:00
  • e66b3a817e Merge pull request #95 from draios/rule-perf-updates Mark Stemm 2016-07-12 10:07:25 -07:00
  • 8ffb553c75 Add ability to run branch-specific trace files. Mark Stemm 2016-07-11 16:33:30 -07:00
  • a2011c37a0 Performance/FP rule updates. Mark Stemm 2016-06-16 17:03:44 -07:00
  • 8225dc0762 Merge pull request #98 from draios/add-lists Mark Stemm 2016-07-11 16:05:29 -07:00
  • 022614a98d Merge pull request #100 from draios/use-startswith Mark Stemm 2016-07-11 15:04:43 -07:00
  • 3cf0dd8ab0 Utilize sysdig's startswith operator. Mark Stemm 2016-07-08 18:28:17 -07:00
  • 502941b804 Add list support to rules file. Mark Stemm 2016-07-08 09:31:17 -07:00
  • d16bb8fd2c Merge pull request #97 from draios/nodejs-bad-rest-api Mark Stemm 2016-07-07 15:58:05 -07:00
  • 4a941df787 Example showing running bash via a bad rest api. Mark Stemm 2016-07-07 15:35:11 -07:00
  • 7b26eb0eb1 Merge pull request #96 from draios/add-jq Mark Stemm 2016-06-28 14:10:00 -07:00
  • 8426117ffd Add jq library. Mark Stemm 2016-06-28 13:42:21 -07:00
  • 8572f58c45 Merge pull request #93 from draios/add-examples Mark Stemm 2016-06-10 17:13:22 -07:00
  • 139ee56af7 Docker-compose environment for mitm example. Mark Stemm 2016-06-06 10:56:35 -07:00
  • 8d181e9051 Merge pull request #92 from draios/dev v0.2.0 Mark Stemm 2016-06-09 10:40:20 -07:00
  • 674e63eef0 Merge pull request #91 from draios/update-releasenotes-0_2_0 Mark Stemm 2016-06-09 09:57:25 -07:00
  • b8cd89757a Add release notes for 0.2.0. Mark Stemm 2016-06-07 14:20:06 -07:00
  • 85fd7c0227 Merge pull request #89 from draios/update-json-output Mark Stemm 2016-06-07 14:37:56 -07:00
  • 995e61210e Add regression tests for json output. Mark Stemm 2016-06-07 13:35:27 -07:00
  • 52a7c77596 Add more useful json output. Mark Stemm 2016-06-06 16:52:40 -07:00
  • 9ab7f52fb0 Merge pull request #90 from draios/migrate-readme-to-wiki Mark Stemm 2016-06-07 11:57:10 -07:00
  • 23322700b4 Migrate README contents to wiki. Mark Stemm 2016-06-07 10:18:16 -07:00
  • 8ecdb80a73 Merge pull request #87 from draios/update-fbash-rules Mark Stemm 2016-06-06 10:53:59 -07:00
  • fc6d775e5b Add additional rules/tests for pipe installers. Mark Stemm 2016-06-01 16:01:37 -07:00
  • 31c87c295a Update fbash rules to use proc.sname. Mark Stemm 2016-05-31 17:41:08 -07:00
  • e9cdd46838 Merge pull request #83 from draios/add-correctness-tests Mark Stemm 2016-05-25 18:13:07 -07:00
  • 0f4b378775 Add .gitignore for test directory. Mark Stemm 2016-05-23 16:14:07 -07:00
  • b3ae480fac Another round of rule cleanups. Mark Stemm 2016-05-23 15:32:12 -07:00
  • 4751546c03 Add correctness tests using Avocado Mark Stemm 2016-05-18 17:08:01 -07:00
  • a41bb0dac0 Print stats when shutting down. Mark Stemm 2016-05-19 16:19:45 -07:00
  • 1a2719437f Add graceful shutdown on SIGINT/SIGTERM. Mark Stemm 2016-05-19 16:17:27 -07:00
  • 18f4a20338 Merge pull request #84 from draios/cmake-cleanups Mark Stemm 2016-05-24 09:44:23 -07:00
  • 583afbf941 Merge pull request #85 from draios/remove-unnecessary-delete Mark Stemm 2016-05-24 09:24:15 -07:00
  • 66cedc89f2 Don't null-check inspector. Mark Stemm 2016-05-23 17:24:38 -07:00
  • 2237532ff0 Quote path variables that may contain spaces. Mark Stemm 2016-05-23 17:20:15 -07:00
  • 22dce61974 Readme.md: overview tweaks Henri DF 2016-05-18 09:32:04 -07:00
  • acbb2f5862 Merge pull request #76 from draios/add-travis Mark Stemm 2016-05-17 22:43:03 -07:00
  • 450c347ef3 Add a basic test to run falco. Mark Stemm 2016-05-17 16:26:05 -07:00
  • 467fe33e37 Add travis badges. Mark Stemm 2016-05-17 16:07:40 -07:00
  • c9d2550ecd Add minimal travis support. Mark Stemm 2016-05-11 10:44:32 -07:00
  • b5055e34af Merge pull request #75 from draios/readme-release-info Henri DF 2016-05-17 14:17:20 -07:00
  • 5fe663e62a readme: lowercase falco Henri DF 2016-05-17 13:41:57 -07:00
  • 38caea4388 README: add "latest release" section Henri DF 2016-05-17 13:37:52 -07:00
  • 260b96167c README: Minor format changes, remove tagline Henri DF 2016-05-17 13:33:57 -07:00
  • 0ed09d72db Use 0.1.0 as initial version. v0.1.0 Mark Stemm 2016-05-17 12:52:03 -07:00
  • d33ab98822 Merge pull request #74 from draios/remove-old-rule-examples Henri DF 2016-05-17 11:40:12 -07:00
  • 6b749b3a5c Remove outdated rule examples Henri DF 2016-05-17 18:36:26 +00:00
  • aec85ad6f3 Merge pull request #73 from draios/initial-changelog Mark Stemm 2016-05-17 11:27:04 -07:00
  • 88c903e6ba Initial CHANGELOG. Mark Stemm 2016-05-17 11:26:22 -07:00
  • 084267ae32 Merge pull request #71 from draios/rule-perf-improvements Mark Stemm 2016-05-17 11:17:04 -07:00
  • ff9907b552 Merge pull request #66 from draios/add-community-readme Mark Stemm 2016-05-17 09:36:01 -07:00
  • d373644bc1 Readme.md: update ignored syscalls Henri DF 2016-05-16 17:58:06 -07:00
  • 6b58e94068 Add community links to README. Mark Stemm 2016-05-13 17:36:55 -07:00
  • a7ecbcef38 Additional rule cleanups to improve performance. Mark Stemm 2016-05-16 17:38:01 -07:00
  • f5c3fc3a1c Merge pull request #64 from draios/add-names-descriptions Mark Stemm 2016-05-16 12:33:45 -07:00