-
Notifications
You must be signed in to change notification settings - Fork 920
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Rule updates 2018 02.v3 #344
Merged
Merged
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add a common fluentd command, and let docker operations modify bin dir
Microsoft SCX and Azure Network Watcher Agent.
The docker process can also be outside of a container when doing actions like docker save, etc, so drop the docker requirement.
Let the parent process also be haproxy_reload and add an additional directory.
For node cli.
Active Directory Client.
A few more openshift-related containers and datadog.
In this case, run by cassandra
gradle and crashlytics
This list will be limited only to those binaries known to spawn shells. Add mesos-slave/mesos-health-ch.
Consul and mesos-slave.
Can also write files below /etc/pki/nssdb.
Rename macro to selinux_writing_conf and add additional programs.
Symantec av cli program.
Sometimes directly, sometimes by invoking openssl.
Also allow the general prefix /etc/haproxy.
Mongodb-related.
rpmdb_stat
Used as a part of directly running get-pip.py.
Scripts start with /usr/share/centrifydc
Specifically, adjoin and addns.
The parent process is generally omsagent-<version> or scx-<version.
Combine the two macros into a single ms_oms_writing_conf and add both direct and parent binaries.
Python scripts below /var/lib/waagent.
Parent process is google_accounts(_daemon).
This allows them to run programs like sed, cp, etc.
Related to post-install steps for systemd/udev.
Directory is /etc/azure, scripts are below /var/lib/waagent.
Related to strongswan (https://strongswan.org/).
It may spawn intermediate shells and write below /etc/ssl.
Also allow subdirectories below /etc/openvpn.
Still used in some people's user rules files.
Some users pointed out that name= was ambiguous, especially when the event includes files being acted upon. Change to program=.
It can run things like python scripts.
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Various rule improvements to address false positives.