Commit Graph

  • 9bce37a2c3 Readme.md: remove 'socket' from ignored syscalls Henri DF 2016-05-16 11:49:47 -07:00
  • 3283ca1e5d Add some detail back to outputs. Mark Stemm 2016-05-16 11:39:39 -07:00
  • a04fc9e2b5 Merge pull request #68 from draios/add-names-descriptions-loris Mark Stemm 2016-05-16 08:47:50 -07:00
  • fd3fa570a2 Add desc/rule fields to general rule documentation Mark Stemm 2016-05-15 22:06:19 -07:00
  • fe741c928d Merge pull request #70 from draios/build-release-by-default Henri DF 2016-05-15 10:48:08 -07:00
  • acfa8e7686 Make default release type "build" Henri DF 2016-05-15 17:43:10 +00:00
  • 21eb418878 merge add-names-descriptions Loris Degioanni 2016-05-15 10:07:43 -07:00
  • 4bd11ddcfc a couple of fixes in the rules file Loris Degioanni 2016-05-15 10:00:13 -07:00
  • 7436bc0952 Allow package mgmt binaries to work in bin dirs. Mark Stemm 2016-05-14 21:57:57 -07:00
  • 0a9a85d1da Also update README example to reflect new format. Mark Stemm 2016-05-14 21:51:55 -07:00
  • 5eb368035a rule file improvement pass Loris Degioanni 2016-05-14 13:00:58 -07:00
  • 4313c9f7a3 Tidy up output of existing rules. Mark Stemm 2016-05-13 17:25:45 -07:00
  • 7be0454f6f Add ability to print name/description of rules. Mark Stemm 2016-05-13 16:27:36 -07:00
  • e662d1eeeb Add name/description to rules. Mark Stemm 2016-05-13 14:00:11 -07:00
  • d16cc67e98 Merge pull request #63 from draios/reduce-rules-fps Mark Stemm 2016-05-13 09:39:00 -07:00
  • 070667cad0 Reduce rule FPs based on more complex environments Mark Stemm 2016-05-12 16:46:57 -07:00
  • 6e2c115e37 Merge pull request #54 from draios/rule-service-spawns-process Mark Stemm 2016-05-12 17:55:20 -07:00
  • 81df435471 Merge pull request #56 from draios/remove-install-falco Henri DF 2016-05-12 11:32:00 -07:00
  • fbdab4362c Remove install-falco script. Henri DF 2016-05-12 17:31:34 +00:00
  • d1fb172bff Merge pull request #55 from draios/run-falco-in-docker Mark Stemm 2016-05-12 09:24:38 -07:00
  • 0e40ad26c4 Run falco by default in containers. Mark Stemm 2016-05-11 16:28:07 -07:00
  • c761218bfe Don't let databases spawn processes after startup. Mark Stemm 2016-05-11 14:59:41 -07:00
  • 343e694ca4 Add back detection for mysql and sensitive files. Mark Stemm 2016-05-11 14:40:52 -07:00
  • f64ea7def5 Add addl groups of binary programs. Mark Stemm 2016-05-11 14:11:18 -07:00
  • f43e5e6c3d Merge pull request #52 from draios/add-license Mark Stemm 2016-05-11 08:54:59 -07:00
  • 6476a55ecc Add CLA section. Mark Stemm 2016-05-10 17:55:05 -07:00
  • 8902257e81 Add license. Mark Stemm 2016-05-10 16:22:05 -07:00
  • 92c4c8f622 Merge pull request #50 from draios/cmdline-opts-daemonize Mark Stemm 2016-05-11 08:46:59 -07:00
  • f0263285c3 Merge pull request #53 from draios/fix-lua-install-path Henri DF 2016-05-10 22:12:24 -07:00
  • 4949da5835 Merge pull request #51 from draios/fix-remaining-falco-rules-conf Mark Stemm 2016-05-10 21:08:25 -07:00
  • 451b450869 Fix install path for Lua files Henri DF 2016-05-10 20:54:20 -07:00
  • 56f806b7ea Update README.md Henri DF 2016-05-10 20:27:26 -07:00
  • 13fc4ca77a Fix remaining falco_rules.conf references. Mark Stemm 2016-05-10 16:12:32 -07:00
  • 79f9843256 Clean up handling cmdline options wrt config file. Mark Stemm 2016-05-10 15:52:59 -07:00
  • 5263181b15 Merge pull request #49 from draios/rules-conf-to-yaml Henri DF 2016-05-10 13:53:06 -07:00
  • dbd50b8c26 Config file: falco_rules.{yaml,conf} Henri DF 2016-05-10 20:52:02 +00:00
  • fae2c330dd Merge pull request #47 from draios/pre-release-documentation Henri DF 2016-05-10 13:47:59 -07:00
  • 492148d880 Running instructions Henri DF 2016-05-10 13:47:30 -07:00
  • 4e525e3114 Document general configuration Henri DF 2016-05-10 13:27:05 -07:00
  • 1c3ae275d7 Rewrite "rules" section Henri DF 2016-05-09 22:09:57 -07:00
  • cd82f6935d Adjust heading levels Henri DF 2016-05-09 21:10:30 -07:00
  • bcc7521e4e Add "how you use it" section Henri DF 2016-05-09 20:47:46 -07:00
  • 9d306e5a1c Add ToC and move things around Henri DF 2016-05-09 18:04:25 -07:00
  • ab80b4ce13 Move installation instructions down Henri DF 2016-05-09 17:51:23 -07:00
  • ca182a2dc8 Add installation instructions Henri DF 2016-05-09 12:11:25 -07:00
  • d5726aea04 Merge pull request #44 from draios/demo-rule-changes Mark Stemm 2016-05-10 11:43:06 -07:00
  • c23229263c Update rules to work on demo scenarios. Mark Stemm 2016-05-08 14:19:54 -07:00
  • 1d94d3aaed Merge pull request #43 from draios/package-as-service Mark Stemm 2016-05-09 17:29:24 -07:00
  • 6203c6be74 Change output options in file as well. Mark Stemm 2016-05-09 17:18:20 -07:00
  • 58d730c62a Don't start by default on debian. Mark Stemm 2016-05-09 17:17:39 -07:00
  • 3fa12ee794 Merge pull request #45 from draios/allow-missing-output-fields Mark Stemm 2016-05-09 10:30:26 -07:00
  • 594d3d66d5 Allow missing output fields. Mark Stemm 2016-05-08 14:27:08 -07:00
  • fda5162061 Merge pull request #41 from draios/error-on-filtered-syscall Mark Stemm 2016-05-07 09:18:44 -07:00
  • 7389e05852 Handle both ignored events and syscalls. Mark Stemm 2016-05-06 18:12:46 -07:00
  • a787dc84d5 Add daemonization, fix any bugs found. Mark Stemm 2016-05-06 17:25:54 -07:00
  • cfc89127e7 Add init.d files to debian/redhat packages. Mark Stemm 2016-05-06 14:04:44 -07:00
  • b8cdb8e46c Modify existing rules to not use ignored syscalls. Mark Stemm 2016-05-05 23:20:46 -07:00
  • 4f63461b59 Return errors for ignored syscalls. Mark Stemm 2016-05-04 10:23:12 -07:00
  • d220ff6bdc Merge pull request #39 from draios/add-dockerfiles Mark Stemm 2016-05-05 21:16:50 -07:00
  • 3d02acf3af Merge pull request #38 from draios/rules-yaml Henri DF 2016-05-05 20:39:34 -07:00
  • fc04ddfe40 Move output code into output.lua Henri DF 2016-05-04 17:39:30 -07:00
  • f6c8c4cb84 Fix (and rename) parser smoke test Henri DF 2016-05-04 17:07:52 -07:00
  • 9dd4e799cb Split out parsing into parser.lua Henri DF 2016-05-04 17:01:30 -07:00
  • e1b9b047d0 Support new yaml format for rules Henri DF 2016-05-04 16:44:16 -07:00
  • fdafc7da77 Remove dead macro-checking code Henri DF 2016-05-04 15:27:32 -07:00
  • 0ec141385d Remove outputs and macros from grammar Henri DF 2016-05-04 14:14:10 -07:00
  • 480c964075 Remove traces of in-expr expansion Henri DF 2016-05-04 13:39:31 -07:00
  • 77a3e3b110 Load statically-linked lyaml lib and lua bindings Henri DF 2016-05-04 11:01:00 -07:00
  • 1703d048c3 Add libyaml (c lib) and lyaml (lua bindings) to build Henri DF 2016-05-02 22:02:52 -07:00
  • a9f9454d26 Remove unneeded include dir Henri DF 2016-05-02 17:31:13 -07:00
  • e3adaf2a5a Convert rules file to yaml format Henri DF 2016-05-02 21:48:53 +00:00
  • 0914651d1d Merge pull request #37 from draios/remaining-digwatch-falco-renames Mark Stemm 2016-05-04 18:34:10 -07:00
  • ba80367116 Remove remaining digwatch references (really). Mark Stemm 2016-05-04 15:44:11 -07:00
  • bd7b9880ee Merge pull request #36 from draios/readme-build-additions Mark Stemm 2016-05-04 13:07:32 -07:00
  • c2ee87976c Add docker files to create images using apt-get. Mark Stemm 2016-05-03 17:10:55 -07:00
  • dfa6da47a3 Update README to always use local kernel module. Mark Stemm 2016-05-03 15:45:28 -07:00
  • 345452836b Changes related to use of kernel module. Mark Stemm 2016-05-02 22:44:41 -07:00
  • 7040d018c4 Merge pull request #35 from draios/remove-digiwatch-refs Mark Stemm 2016-05-02 12:09:31 -07:00
  • 738f555bae Remove remaining Digwatch references. Mark Stemm 2016-05-02 11:32:33 -07:00
  • 9729058b9b Update README.md Henri DF 2016-05-02 10:59:31 -07:00
  • 14c1e30c24 Simple script to list ignored syscalls Henri DF 2016-05-01 23:35:16 +00:00
  • c7648e01ee Merge pull request #34 from draios/falco-digwatch-renaming Henri DF 2016-05-01 16:19:30 -07:00
  • bde9631cd4 More falco->digwatch renaming Henri DF 2016-05-01 23:13:28 +00:00
  • c702713107 Add discarded syscalls to README Henri DF 2016-05-01 09:14:43 -07:00
  • 244ebad1da Merge pull request #33 from draios/falco-digwatch-renaming Henri DF 2016-05-01 09:10:08 -07:00
  • 5052039ee1 More falco->digwatch renaming Henri DF 2016-05-01 16:09:49 +00:00
  • 81e51d13e7 Update README.md Henri DF 2016-04-28 17:06:57 -07:00
  • 657573d3a9 Merge pull request #31 from draios/discard-by-type Henri DF 2016-04-28 15:36:33 -07:00
  • e207bc5f3a Drop high-volume events Henri DF 2016-04-23 01:42:02 +00:00
  • 8252b9decb Update README.md Henri DF 2016-04-27 22:10:35 -07:00
  • edb112f167 Merge pull request #32 from draios/rename-falco Henri DF 2016-04-27 20:28:52 -07:00
  • abe6220651 Renaming Henri DF 2016-04-28 02:57:50 +00:00
  • 8b5fcf866a Merge pull request #30 from draios/logging Henri DF 2016-04-22 16:01:37 -07:00
  • 6d72619968 rename digwatch_syslog -> digwatch_logger Henri DF 2016-04-22 16:00:35 -07:00
  • 4c64295adc Digwatch logging Henri DF 2016-04-22 15:56:18 -07:00
  • 5413935f15 Small tweak to usage message Henri DF 2016-04-22 15:33:43 -07:00
  • fad88ee4b7 Remove signal handling Henri DF 2016-04-22 14:54:49 -07:00
  • 6b2ef3088c Merge pull request #29 from draios/install-digwat Henri DF 2016-04-21 16:36:15 -07:00
  • 1baedc156f Add install-digwatch script template Henri DF 2016-04-21 16:33:17 -07:00
  • d59e66da86 Merge pull request #28 from draios/json-output Henri DF 2016-04-21 16:31:53 -07:00