falcosecurity / rules

Falco rule repository
https://falcosecurity.github.io/rules/
Apache License 2.0
91 stars 64 forks source link

Falco 0.36. Rules Messaging #132

Closed incertum closed 9 months ago

incertum commented 10 months ago

What to document

Discuss the rules release note and general messaging for Falco 0.36.0 with respect to rules changes.

CC @leogr @LucaGuerra @loresuso @darryk10 @Andreagit97 @jasondellaluce

incertum commented 10 months ago

Starting with some thoughts around libs changes that influence Falco's existing fields and rules behavior:

We are excited to share that we have undertaken enhancements to Falco's underlying libraries. As a result of these improvements, we have achieved a higher level of accuracy and data quality regarding the existing proc.exepath and the process tree reconstruction in general. This step forward reinforces our commitment to refining Falco and providing you with an even better user experience.

In more detail:

[Note: I am trying to strike a balance between providing some technical details, but not too much either]

As I have time I will continue adding thoughts to this issue ...

leogr commented 10 months ago

Ref about syslinks https://github.com/falcosecurity/libs/pull/1300