mirror of
https://github.com/falcosecurity/falco.git
synced 2026-04-26 10:33:02 +00:00
12 lines
272 B
YAML
12 lines
272 B
YAML
- list: my_list
|
|
items: [not-cat]
|
|
|
|
- list: my_list
|
|
append: true
|
|
items: [cat]
|
|
|
|
- rule: Open From Cat
|
|
desc: A process named cat does an open
|
|
condition: evt.type=open and proc.name in (my_list)
|
|
output: "An open was seen (command=%proc.cmdline)"
|
|
priority: WARNING |