Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Rule updates 2018 02.v3 #344

Merged
merged 46 commits into from
Apr 3, 2018
Merged

Rule updates 2018 02.v3 #344

merged 46 commits into from
Apr 3, 2018

Conversation

mstemm
Copy link
Contributor

@mstemm mstemm commented Apr 3, 2018

Various rule improvements to address false positives.

chipsysdig and others added 30 commits April 2, 2018 17:04
Add a common fluentd command, and let docker operations modify bin dir
Microsoft SCX and Azure Network Watcher Agent.
The docker process can also be outside of a container when doing actions
like docker save, etc, so drop the docker requirement.
Let the parent process also be haproxy_reload and add an additional
directory.
Active Directory Client.
A few more openshift-related containers and datadog.
In this case, run by cassandra
This list will be limited only to those binaries known to spawn
shells. Add mesos-slave/mesos-health-ch.
Consul and mesos-slave.
Can also write files below /etc/pki/nssdb.
Rename macro to selinux_writing_conf and add additional programs.
Symantec av cli program.
Sometimes directly, sometimes by invoking openssl.
Also allow the general prefix /etc/haproxy.
Mongodb-related.
Used as a part of directly running get-pip.py.
Scripts start with /usr/share/centrifydc
Specifically, adjoin and addns.
The parent process is generally omsagent-<version> or scx-<version.
Combine the two macros into a single ms_oms_writing_conf and add both
direct and parent binaries.
Python scripts below /var/lib/waagent.
Parent process is google_accounts(_daemon).
mstemm added 16 commits April 2, 2018 17:04
This allows them to run programs like sed, cp, etc.
Related to post-install steps for systemd/udev.
Directory is /etc/azure, scripts are below /var/lib/waagent.
It may spawn intermediate shells and write below /etc/ssl.
Also allow subdirectories below /etc/openvpn.
Still used in some people's user rules files.
Some users pointed out that name= was ambiguous, especially when the
event includes files being acted upon. Change to program=.
It can run things like python scripts.
@mstemm mstemm merged commit 1516fe4 into dev Apr 3, 2018
@mstemm mstemm deleted the rule-updates-2018-02.v3 branch April 3, 2018 01:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants