chainguard-dev / bincapz

detect malicious program behaviors
Apache License 2.0
404 stars 26 forks source link

ignore bincapz findings by default #134

Closed tstromberg closed 4 months ago

tstromberg commented 4 months ago

If you do a filesystem scan and encounter bincapz, it fires all sorts of alerts.

Since the filename isn't reliable in all circumsltances, my thought is to hide the results of bincapz if >X number of critical rules are hit, as well as some sort of bincapz specific rule.