Files
falco/rules
Mark Stemm e7c7a9b12d rule(Launch Package Management...): add sysdig nia
Example falco alert:

Package management process launched in container (user=root
user_loginuid=-1 command=rpm
--dbpath=/analysis_scratch/de10314b-70bb-4149-802e-1c2c3d47f23c/rpmtmp/rpmdbfinal/var/lib/rpm
-qa --queryformat
[%{FILENAMES}|ANCHORETOK|%{FILEDIGESTS}|ANCHORETOK|%{FILEMODES:octal}|ANCHORETOK|%{FILEGROUPNAME}|ANCHORETOK|%{FILEUSERNAME}|ANCHORETOK|%{FILESIZES}|ANCHORETOK|%{=NAME}|ANCHORETOK|%{FILEFLAGS:fflags}|ANCHORETOK|%{=FILEDIGESTALGO}\n]
container_id=3748cd603f28 container_name=sysdig-image-analyzer image=quay.io/sysdig/node-image-analyzer:latest)

Signed-off-by: Mark Stemm <mark.stemm@gmail.com>
2021-02-10 11:16:39 -08:00
..
2019-10-08 16:02:26 +02:00
2020-09-10 15:01:07 +02:00
2019-10-08 16:02:26 +02:00