Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add ignored comms for /etc/shadow access #490

Merged
merged 3 commits into from
Feb 23, 2025

Conversation

slashben
Copy link
Contributor

This pull request introduces new functionality to the pkg/ruleengine/v1/r0010_unexpected_sensitive_file_access.go file. The changes include adding a list of legitimate process names and modifying the event processing logic to ignore events from these processes.

Key changes:

  • Added a list of legitimate process names to the CreateRuleR0010UnexpectedSensitiveFileAccess function.
  • Updated the ProcessEvent function to skip processing events if they originate from any of the legitimate processes listed.

@slashben slashben marked this pull request as ready for review February 23, 2025 19:02
amitschendel
amitschendel previously approved these changes Feb 23, 2025
matthyx
matthyx previously approved these changes Feb 23, 2025
Copy link

Summary:

  • License scan: failure
  • Credentials scan: failure
  • Vulnerabilities scan: failure
  • Unit test: success
  • Go linting: success

@slashben slashben dismissed stale reviews from matthyx and amitschendel via c92fdb0 February 23, 2025 21:13
Copy link

Summary:

  • License scan: failure
  • Credentials scan: failure
  • Vulnerabilities scan: failure
  • Unit test: success
  • Go linting: success

@slashben slashben merged commit 257dc64 into main Feb 23, 2025
19 checks passed
@slashben slashben deleted the fix/ignore-comms-for-sensitive-access branch February 23, 2025 21:37
@slashben slashben added the release Create release label Feb 23, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
release Create release
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants