falcosecurity / rules

Falco rule repository
https://falcosecurity.github.io/rules/
Apache License 2.0
93 stars 68 forks source link

update(rules): comment how to reduce reverse shell detection noise #136

Closed allanembedded closed 1 year ago

allanembedded commented 1 year ago

The fd.types field introduced in libs 0.12.0 allows us to improve the reverse shell rule so it fires only once all three of stdout/stderr/stdin are redirected.

What type of PR is this?

Uncomment one (or more) /kind <> lines:

/kind feature

/kind bug

/kind cleanup

/kind design

/kind documentation

/kind failing-test

Any specific area of the project related to this PR?

Uncomment one (or more) /area <> lines:

/area rules

/area registry

/area build

/area documentation

Proposed rule maturity level

Uncomment one (or more) /area <> lines (only for PRs that add or modify rules):

/area maturity-stable

/area maturity-incubating

/area maturity-sandbox

/area maturity-deprecated

What this PR does / why we need it:

Informs users of the new fd.types[] field and how it can be used to improve the existing reverse shell rule.

Which issue(s) this PR fixes:

Fixes #131

Special notes for your reviewer:

Please see discussion in the above issue for more context to the change.

poiana commented 1 year ago

Welcome @allanembedded! It looks like this is your first PR to falcosecurity/rules 🎉

github-actions[bot] commented 1 year ago

Rules files suggestions

falco_rules.yaml

Comparing 0599aed7d3e963f79f811d25e22c625834de2212 with latest tag falco-rules-1.0.1

Major changes:

Patch changes:

poiana commented 1 year ago

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: allanembedded, incertum

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files: - ~~[OWNERS](https://github.com/falcosecurity/rules/blob/main/OWNERS)~~ [incertum] Approvers can indicate their approval by writing `/approve` in a comment Approvers can cancel approval by writing `/approve cancel` in a comment
poiana commented 1 year ago

LGTM label has been added.

Git tree hash: 8925438e04476cac6e96d350425be03cc23048cb