mirror of
https://github.com/helm/charts.git
synced 2026-08-23 22:37:45 +00:00
[stable/falco] Update Falco to 0.17.0 (#16366)
Signed-off-by: Federico Barcelona <fede_rico_94@hotmail.com>
This commit is contained in:
committed by
Kubernetes Prow Robot
parent
a12ec23aed
commit
23399f8428
@@ -3,6 +3,13 @@
|
||||
This file documents all notable changes to Sysdig Falco Helm Chart. The release
|
||||
numbering uses [semantic versioning](http://semver.org).
|
||||
|
||||
## v1.0.4
|
||||
|
||||
### Minor Changes
|
||||
|
||||
* Upgrade to Falco 0.17.0
|
||||
* Upgrade rules to Falco 0.17.0
|
||||
|
||||
## v1.0.3
|
||||
|
||||
### Minor Changes
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
apiVersion: v1
|
||||
name: falco
|
||||
version: 1.0.3
|
||||
appVersion: 0.16.0
|
||||
version: 1.0.4
|
||||
appVersion: 0.17.0
|
||||
description: Falco
|
||||
keywords:
|
||||
- monitoring
|
||||
|
||||
+72
-72
@@ -43,78 +43,78 @@ The command removes all the Kubernetes components associated with the chart and
|
||||
|
||||
The following table lists the configurable parameters of the Falco chart and their default values.
|
||||
|
||||
| Parameter | Description | Default |
|
||||
| --- | --- | --- |
|
||||
| `image.registry` | The image registry to pull from | `docker.io` |
|
||||
| `image.repository` | The image repository to pull from | `falcosecurity/falco` |
|
||||
| `image.tag` | The image tag to pull | `0.16.0` |
|
||||
| `image.pullPolicy` | The image pull policy | `IfNotPresent` |
|
||||
| `cri.socket` | The path of the CRI socket | `/run/containerd/containerd.sock` |
|
||||
| `docker.socket` | The path of the Docker daemon socket | `/var/run/docker.sock` |
|
||||
| `resources.requests.cpu` | CPU requested for being run in a node | `100m` |
|
||||
| `resources.requests.memory` | Memory requested for being run in a node | `512Mi` |
|
||||
| `resources.limits.cpu` | CPU limit | `200m` |
|
||||
| `resources.limits.memory` | Memory limit | `1024Mi` |
|
||||
| `extraArgs` | Specify additional container args | `[]` |
|
||||
| `rbac.create` | If true, create & use RBAC resources | `true` |
|
||||
| `serviceAccount.create` | Create serviceAccount | `true` |
|
||||
| `serviceAccount.name` | Use this value as serviceAccountName | ` ` |
|
||||
| `fakeEventGenerator.enabled` | Run falco-event-generator for sample events | `false` |
|
||||
| `fakeEventGenerator.replicas` | How many replicas of falco-event-generator to run | `1` |
|
||||
| `daemonset.updateStrategy.type` | The updateStrategy for updating the daemonset | `RollingUpdate` |
|
||||
| `daemonset.env` | Extra environment variables passed to daemonset pods | `{}` |
|
||||
| `podSecurityPolicy.create` | If true, create & use podSecurityPolicy | `false` |
|
||||
| `proxy.httpProxy` | Set the Proxy server if is behind a firewall | ` ` |
|
||||
| `proxy.httpsProxy` | Set the Proxy server if is behind a firewall | ` ` |
|
||||
| `proxy.noProxy` | Set the Proxy server if is behind a firewall | ` ` |
|
||||
| `timezone` | Set the daemonset's timezone | ` ` |
|
||||
| `priorityClassName` | Set the daemonset's priorityClassName | ` ` |
|
||||
| `ebpf.enabled` | Enable eBPF support for Falco instead of `falco-probe` kernel module | `false` |
|
||||
| `ebpf.settings.hostNetwork` | Needed to enable eBPF JIT at runtime for performance reasons | `true` |
|
||||
| `ebpf.settings.mountEtcVolume` | Needed to detect which kernel version are running in Google COS | `true` |
|
||||
| `falco.rulesFile` | The location of the rules files | `[/etc/falco/falco_rules.yaml, /etc/falco/falco_rules.local.yaml, /etc/falco/rules.d]` |
|
||||
| `falco.timeFormatISO8601` | Display times using ISO 8601 instead of local time zone | `false` |
|
||||
| `falco.jsonOutput` | Output events in json or text | `false` |
|
||||
| `falco.jsonIncludeOutputProperty` | Include output property in json output | `true` |
|
||||
| `falco.logStderr` | Send Falco debugging information logs to stderr | `true` |
|
||||
| `falco.logSyslog` | Send Falco debugging information logs to syslog | `true` |
|
||||
| `falco.logLevel` | The minimum level of Falco debugging information to include in logs | `info` |
|
||||
| `falco.priority` | The minimum rule priority level to load and run | `debug` |
|
||||
| `falco.bufferedOutputs` | Use buffered outputs to channels | `false` |
|
||||
| `falco.syscallEventDrops.actions` | Actions to be taken when system calls were dropped from the circular buffer | `[log, alert]` |
|
||||
| `falco.syscallEventDrops.rate` | Rate at which log/alert messages are emitted | `.03333` |
|
||||
| `falco.syscallEventDrops.maxBurst` | Max burst of messages emitted | `10` |
|
||||
| `falco.outputs.rate` | Number of tokens gained per second | `1` |
|
||||
| `falco.outputs.maxBurst` | Maximum number of tokens outstanding | `1000` |
|
||||
| `falco.syslogOutput.enabled` | Enable syslog output for security notifications | `true` |
|
||||
| `falco.fileOutput.enabled` | Enable file output for security notifications | `false` |
|
||||
| `falco.fileOutput.keepAlive` | Open file once or every time a new notification arrives | `false` |
|
||||
| `falco.fileOutput.filename` | The filename for logging notifications | `./events.txt` |
|
||||
| `falco.stdoutOutput.enabled` | Enable stdout output for security notifications | `true` |
|
||||
| `falco.webserver.enabled` | Enable Falco embedded webserver to accept K8s audit events | `false` |
|
||||
| `falco.webserver.listenPort` | Port where Falco embedded webserver listen to connections | `8765` |
|
||||
| `falco.webserver.k8sAuditEndpoint` | Endpoint where Falco embedded webserver accepts K8s audit events | `/k8s-audit` |
|
||||
| `falco.webserver.clusterIP` | ClusterIP address where Falco will listen to K8s audit events. If you enable the webserver, this field is required | ` ` |
|
||||
| `falco.programOutput.enabled` | Enable program output for security notifications | `false` |
|
||||
| `falco.programOutput.keepAlive` | Start the program once or re-spawn when a notification arrives | `false` |
|
||||
| `falco.programOutput.program` | Command to execute for program output | `mail -s "Falco Notification" someone@example.com` |
|
||||
| `falco.httpOutput.enabled` | Enable http output for security notifications | `false` |
|
||||
| `falco.httpOutput.url` | Url to notify using the http output when a notification arrives | `http://some.url` |
|
||||
| `customRules` | Third party rules enabled for Falco | `{}` |
|
||||
| `integrations.gcscc.enabled` | Enable Google Cloud Security Command Center integration | `false` |
|
||||
| `integrations.gcscc.webhookUrl` | The URL where sysdig-gcscc-connector webhook is listening | `http://sysdig-gcscc-connector.default.svc.cluster.local:8080/events` |
|
||||
| `integrations.gcscc.webhookAuthenticationToken` | Token used for authentication and webhook | `b27511f86e911f20b9e0f9c8104b4ec4` |
|
||||
| `integrations.natsOutput.enabled` | Enable NATS Output integration | `false` |
|
||||
| `integrations.natsOutput.natsUrl` | The NATS' URL where Falco is going to publish security alerts | `nats://nats.nats-io.svc.cluster.local:4222` |
|
||||
| `integrations.pubsubOutput.credentialsData` | Contents retrieved from `cat $HOME/.config/gcloud/legacy_credentials/<email>/adc.json | jq -c .` | ` ` |
|
||||
| `integrations.pubsubOutput.enabled` | Enable GCloud PubSub Output Integration | `false` |
|
||||
| `integrations.pubsubOutput.projectID` | GCloud Project ID where the Pub/Sub will be created | ` ` |
|
||||
| `integrations.snsOutput.enabled` | Enable Amazon SNS Output integration | `false` |
|
||||
| `integrations.snsOutput.topic` | The SNS topic where Falco is going to publish security alerts | ` ` |
|
||||
| `integrations.snsOutput.aws_access_key_id` | The AWS Access Key Id credentials for access to SNS n | ` ` |
|
||||
| `integrations.snsOutput.aws_secret_access_key` | The AWS Secret Access Key credential to access to SNS | ` ` |
|
||||
| `integrations.snsOutput.aws_default_region` | The AWS region where SNS is deployed | ` ` |
|
||||
| `tolerations` | The tolerations for scheduling | `node-role.kubernetes.io/master:NoSchedule` |
|
||||
| Parameter | Description | Default |
|
||||
| --- | --- | --- |
|
||||
| `image.registry` | The image registry to pull from | `docker.io` |
|
||||
| `image.repository` | The image repository to pull from | `falcosecurity/falco` |
|
||||
| `image.tag` | The image tag to pull | `0.17.0` |
|
||||
| `image.pullPolicy` | The image pull policy | `IfNotPresent` |
|
||||
| `cri.socket` | The path of the CRI socket | `/run/containerd/containerd.sock` |
|
||||
| `docker.socket` | The path of the Docker daemon socket | `/var/run/docker.sock` |
|
||||
| `resources.requests.cpu` | CPU requested for being run in a node | `100m` |
|
||||
| `resources.requests.memory` | Memory requested for being run in a node | `512Mi` |
|
||||
| `resources.limits.cpu` | CPU limit | `200m` |
|
||||
| `resources.limits.memory` | Memory limit | `1024Mi` |
|
||||
| `extraArgs` | Specify additional container args | `[]` |
|
||||
| `rbac.create` | If true, create & use RBAC resources | `true` |
|
||||
| `serviceAccount.create` | Create serviceAccount | `true` |
|
||||
| `serviceAccount.name` | Use this value as serviceAccountName | ` ` |
|
||||
| `fakeEventGenerator.enabled` | Run falco-event-generator for sample events | `false` |
|
||||
| `fakeEventGenerator.replicas` | How many replicas of falco-event-generator to run | `1` |
|
||||
| `daemonset.updateStrategy.type` | The updateStrategy for updating the daemonset | `RollingUpdate` |
|
||||
| `daemonset.env` | Extra environment variables passed to daemonset pods | `{}` |
|
||||
| `podSecurityPolicy.create` | If true, create & use podSecurityPolicy | `false` |
|
||||
| `proxy.httpProxy` | Set the Proxy server if is behind a firewall | ` ` |
|
||||
| `proxy.httpsProxy` | Set the Proxy server if is behind a firewall | ` ` |
|
||||
| `proxy.noProxy` | Set the Proxy server if is behind a firewall | ` ` |
|
||||
| `timezone` | Set the daemonset's timezone | ` ` |
|
||||
| `priorityClassName` | Set the daemonset's priorityClassName | ` ` |
|
||||
| `ebpf.enabled` | Enable eBPF support for Falco instead of `falco-probe` kernel module | `false` |
|
||||
| `ebpf.settings.hostNetwork` | Needed to enable eBPF JIT at runtime for performance reasons | `true` |
|
||||
| `ebpf.settings.mountEtcVolume` | Needed to detect which kernel version are running in Google COS | `true` |
|
||||
| `falco.rulesFile` | The location of the rules files | `[/etc/falco/falco_rules.yaml, /etc/falco/falco_rules.local.yaml, /etc/falco/rules.available/application_rules.yaml, /etc/falco/rules.d]` |
|
||||
| `falco.timeFormatISO8601` | Display times using ISO 8601 instead of local time zone | `false` |
|
||||
| `falco.jsonOutput` | Output events in json or text | `false` |
|
||||
| `falco.jsonIncludeOutputProperty` | Include output property in json output | `true` |
|
||||
| `falco.logStderr` | Send Falco debugging information logs to stderr | `true` |
|
||||
| `falco.logSyslog` | Send Falco debugging information logs to syslog | `true` |
|
||||
| `falco.logLevel` | The minimum level of Falco debugging information to include in logs | `info` |
|
||||
| `falco.priority` | The minimum rule priority level to load and run | `debug` |
|
||||
| `falco.bufferedOutputs` | Use buffered outputs to channels | `false` |
|
||||
| `falco.syscallEventDrops.actions` | Actions to be taken when system calls were dropped from the circular buffer | `[log, alert]` |
|
||||
| `falco.syscallEventDrops.rate` | Rate at which log/alert messages are emitted | `.03333` |
|
||||
| `falco.syscallEventDrops.maxBurst` | Max burst of messages emitted | `10` |
|
||||
| `falco.outputs.rate` | Number of tokens gained per second | `1` |
|
||||
| `falco.outputs.maxBurst` | Maximum number of tokens outstanding | `1000` |
|
||||
| `falco.syslogOutput.enabled` | Enable syslog output for security notifications | `true` |
|
||||
| `falco.fileOutput.enabled` | Enable file output for security notifications | `false` |
|
||||
| `falco.fileOutput.keepAlive` | Open file once or every time a new notification arrives | `false` |
|
||||
| `falco.fileOutput.filename` | The filename for logging notifications | `./events.txt` |
|
||||
| `falco.stdoutOutput.enabled` | Enable stdout output for security notifications | `true` |
|
||||
| `falco.webserver.enabled` | Enable Falco embedded webserver to accept K8s audit events | `false` |
|
||||
| `falco.webserver.listenPort` | Port where Falco embedded webserver listen to connections | `8765` |
|
||||
| `falco.webserver.k8sAuditEndpoint` | Endpoint where Falco embedded webserver accepts K8s audit events | `/k8s-audit` |
|
||||
| `falco.webserver.clusterIP` | ClusterIP address where Falco will listen to K8s audit events. If you enable the webserver, this field is required | ` ` |
|
||||
| `falco.programOutput.enabled` | Enable program output for security notifications | `false` |
|
||||
| `falco.programOutput.keepAlive` | Start the program once or re-spawn when a notification arrives | `false` |
|
||||
| `falco.programOutput.program` | Command to execute for program output | `mail -s "Falco Notification" someone@example.com` |
|
||||
| `falco.httpOutput.enabled` | Enable http output for security notifications | `false` |
|
||||
| `falco.httpOutput.url` | Url to notify using the http output when a notification arrives | `http://some.url` |
|
||||
| `customRules` | Third party rules enabled for Falco | `{}` |
|
||||
| `integrations.gcscc.enabled` | Enable Google Cloud Security Command Center integration | `false` |
|
||||
| `integrations.gcscc.webhookUrl` | The URL where sysdig-gcscc-connector webhook is listening | `http://sysdig-gcscc-connector.default.svc.cluster.local:8080/events` |
|
||||
| `integrations.gcscc.webhookAuthenticationToken` | Token used for authentication and webhook | `b27511f86e911f20b9e0f9c8104b4ec4` |
|
||||
| `integrations.natsOutput.enabled` | Enable NATS Output integration | `false` |
|
||||
| `integrations.natsOutput.natsUrl` | The NATS' URL where Falco is going to publish security alerts | `nats://nats.nats-io.svc.cluster.local:4222` |
|
||||
| `integrations.pubsubOutput.credentialsData` | Contents retrieved from `cat $HOME/.config/gcloud/legacy_credentials/<email>/adc.json | jq -c .` | ` ` |
|
||||
| `integrations.pubsubOutput.enabled` | Enable GCloud PubSub Output Integration | `false` |
|
||||
| `integrations.pubsubOutput.projectID` | GCloud Project ID where the Pub/Sub will be created | ` ` |
|
||||
| `integrations.snsOutput.enabled` | Enable Amazon SNS Output integration | `false` |
|
||||
| `integrations.snsOutput.topic` | The SNS topic where Falco is going to publish security alerts | ` ` |
|
||||
| `integrations.snsOutput.aws_access_key_id` | The AWS Access Key Id credentials for access to SNS n | ` ` |
|
||||
| `integrations.snsOutput.aws_secret_access_key` | The AWS Secret Access Key credential to access to SNS | ` ` |
|
||||
| `integrations.snsOutput.aws_default_region` | The AWS region where SNS is deployed | ` ` |
|
||||
| `tolerations` | The tolerations for scheduling | `node-role.kubernetes.io/master:NoSchedule` |
|
||||
|
||||
Specify each parameter using the `--set key=value[,key=value]` argument to `helm install`. For example,
|
||||
|
||||
|
||||
@@ -0,0 +1,189 @@
|
||||
#
|
||||
# Copyright (C) 2016-2018 Draios Inc dba Sysdig.
|
||||
#
|
||||
# This file is part of falco.
|
||||
#
|
||||
# Licensed under the Apache License, Version 2.0 (the "License");
|
||||
# you may not use this file except in compliance with the License.
|
||||
# You may obtain a copy of the License at
|
||||
#
|
||||
# http://www.apache.org/licenses/LICENSE-2.0
|
||||
#
|
||||
# Unless required by applicable law or agreed to in writing, software
|
||||
# distributed under the License is distributed on an "AS IS" BASIS,
|
||||
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
# See the License for the specific language governing permissions and
|
||||
# limitations under the License.
|
||||
#
|
||||
|
||||
- required_engine_version: 2
|
||||
|
||||
################################################################
|
||||
# By default all application-related rules are disabled for
|
||||
# performance reasons. Depending on the application(s) you use,
|
||||
# uncomment the corresponding rule definitions for
|
||||
# application-specific activity monitoring.
|
||||
################################################################
|
||||
|
||||
# Elasticsearch ports
|
||||
- macro: elasticsearch_cluster_port
|
||||
condition: fd.sport=9300
|
||||
- macro: elasticsearch_api_port
|
||||
condition: fd.sport=9200
|
||||
- macro: elasticsearch_port
|
||||
condition: elasticsearch_cluster_port or elasticsearch_api_port
|
||||
|
||||
# - rule: Elasticsearch unexpected network inbound traffic
|
||||
# desc: inbound network traffic to elasticsearch on a port other than the standard ports
|
||||
# condition: user.name = elasticsearch and inbound and not elasticsearch_port
|
||||
# output: "Inbound network traffic to Elasticsearch on unexpected port (connection=%fd.name)"
|
||||
# priority: WARNING
|
||||
|
||||
# - rule: Elasticsearch unexpected network outbound traffic
|
||||
# desc: outbound network traffic from elasticsearch on a port other than the standard ports
|
||||
# condition: user.name = elasticsearch and outbound and not elasticsearch_cluster_port
|
||||
# output: "Outbound network traffic from Elasticsearch on unexpected port (connection=%fd.name)"
|
||||
# priority: WARNING
|
||||
|
||||
|
||||
# ActiveMQ ports
|
||||
- macro: activemq_cluster_port
|
||||
condition: fd.sport=61616
|
||||
- macro: activemq_web_port
|
||||
condition: fd.sport=8161
|
||||
- macro: activemq_port
|
||||
condition: activemq_web_port or activemq_cluster_port
|
||||
|
||||
# - rule: Activemq unexpected network inbound traffic
|
||||
# desc: inbound network traffic to activemq on a port other than the standard ports
|
||||
# condition: user.name = activemq and inbound and not activemq_port
|
||||
# output: "Inbound network traffic to ActiveMQ on unexpected port (connection=%fd.name)"
|
||||
# priority: WARNING
|
||||
|
||||
# - rule: Activemq unexpected network outbound traffic
|
||||
# desc: outbound network traffic from activemq on a port other than the standard ports
|
||||
# condition: user.name = activemq and outbound and not activemq_cluster_port
|
||||
# output: "Outbound network traffic from ActiveMQ on unexpected port (connection=%fd.name)"
|
||||
# priority: WARNING
|
||||
|
||||
|
||||
# Cassandra ports
|
||||
# https://docs.datastax.com/en/cassandra/2.0/cassandra/security/secureFireWall_r.html
|
||||
- macro: cassandra_thrift_client_port
|
||||
condition: fd.sport=9160
|
||||
- macro: cassandra_cql_port
|
||||
condition: fd.sport=9042
|
||||
- macro: cassandra_cluster_port
|
||||
condition: fd.sport=7000
|
||||
- macro: cassandra_ssl_cluster_port
|
||||
condition: fd.sport=7001
|
||||
- macro: cassandra_jmx_port
|
||||
condition: fd.sport=7199
|
||||
- macro: cassandra_port
|
||||
condition: >
|
||||
cassandra_thrift_client_port or
|
||||
cassandra_cql_port or cassandra_cluster_port or
|
||||
cassandra_ssl_cluster_port or cassandra_jmx_port
|
||||
|
||||
# - rule: Cassandra unexpected network inbound traffic
|
||||
# desc: inbound network traffic to cassandra on a port other than the standard ports
|
||||
# condition: user.name = cassandra and inbound and not cassandra_port
|
||||
# output: "Inbound network traffic to Cassandra on unexpected port (connection=%fd.name)"
|
||||
# priority: WARNING
|
||||
|
||||
# - rule: Cassandra unexpected network outbound traffic
|
||||
# desc: outbound network traffic from cassandra on a port other than the standard ports
|
||||
# condition: user.name = cassandra and outbound and not (cassandra_ssl_cluster_port or cassandra_cluster_port)
|
||||
# output: "Outbound network traffic from Cassandra on unexpected port (connection=%fd.name)"
|
||||
# priority: WARNING
|
||||
|
||||
# Couchdb ports
|
||||
# https://github.com/davisp/couchdb/blob/master/etc/couchdb/local.ini
|
||||
- macro: couchdb_httpd_port
|
||||
condition: fd.sport=5984
|
||||
- macro: couchdb_httpd_ssl_port
|
||||
condition: fd.sport=6984
|
||||
# xxx can't tell what clustering ports are used. not writing rules for this
|
||||
# yet.
|
||||
|
||||
# Fluentd ports
|
||||
- macro: fluentd_http_port
|
||||
condition: fd.sport=9880
|
||||
- macro: fluentd_forward_port
|
||||
condition: fd.sport=24224
|
||||
|
||||
# - rule: Fluentd unexpected network inbound traffic
|
||||
# desc: inbound network traffic to fluentd on a port other than the standard ports
|
||||
# condition: user.name = td-agent and inbound and not (fluentd_forward_port or fluentd_http_port)
|
||||
# output: "Inbound network traffic to Fluentd on unexpected port (connection=%fd.name)"
|
||||
# priority: WARNING
|
||||
|
||||
# - rule: Tdagent unexpected network outbound traffic
|
||||
# desc: outbound network traffic from fluentd on a port other than the standard ports
|
||||
# condition: user.name = td-agent and outbound and not fluentd_forward_port
|
||||
# output: "Outbound network traffic from Fluentd on unexpected port (connection=%fd.name)"
|
||||
# priority: WARNING
|
||||
|
||||
# Gearman ports
|
||||
# http://gearman.org/protocol/
|
||||
# - rule: Gearman unexpected network outbound traffic
|
||||
# desc: outbound network traffic from gearman on a port other than the standard ports
|
||||
# condition: user.name = gearman and outbound and outbound and not fd.sport = 4730
|
||||
# output: "Outbound network traffic from Gearman on unexpected port (connection=%fd.name)"
|
||||
# priority: WARNING
|
||||
|
||||
# Zookeeper
|
||||
- macro: zookeeper_port
|
||||
condition: fd.sport = 2181
|
||||
|
||||
# Kafka ports
|
||||
# - rule: Kafka unexpected network inbound traffic
|
||||
# desc: inbound network traffic to kafka on a port other than the standard ports
|
||||
# condition: user.name = kafka and inbound and fd.sport != 9092
|
||||
# output: "Inbound network traffic to Kafka on unexpected port (connection=%fd.name)"
|
||||
# priority: WARNING
|
||||
|
||||
# Memcached ports
|
||||
# - rule: Memcached unexpected network inbound traffic
|
||||
# desc: inbound network traffic to memcached on a port other than the standard ports
|
||||
# condition: user.name = memcached and inbound and fd.sport != 11211
|
||||
# output: "Inbound network traffic to Memcached on unexpected port (connection=%fd.name)"
|
||||
# priority: WARNING
|
||||
|
||||
# - rule: Memcached unexpected network outbound traffic
|
||||
# desc: any outbound network traffic from memcached. memcached never initiates outbound connections.
|
||||
# condition: user.name = memcached and outbound
|
||||
# output: "Unexpected Memcached outbound connection (connection=%fd.name)"
|
||||
# priority: WARNING
|
||||
|
||||
|
||||
# MongoDB ports
|
||||
- macro: mongodb_server_port
|
||||
condition: fd.sport = 27017
|
||||
- macro: mongodb_shardserver_port
|
||||
condition: fd.sport = 27018
|
||||
- macro: mongodb_configserver_port
|
||||
condition: fd.sport = 27019
|
||||
- macro: mongodb_webserver_port
|
||||
condition: fd.sport = 28017
|
||||
|
||||
# - rule: Mongodb unexpected network inbound traffic
|
||||
# desc: inbound network traffic to mongodb on a port other than the standard ports
|
||||
# condition: >
|
||||
# user.name = mongodb and inbound and not (mongodb_server_port or
|
||||
# mongodb_shardserver_port or mongodb_configserver_port or mongodb_webserver_port)
|
||||
# output: "Inbound network traffic to MongoDB on unexpected port (connection=%fd.name)"
|
||||
# priority: WARNING
|
||||
|
||||
# MySQL ports
|
||||
# - rule: Mysql unexpected network inbound traffic
|
||||
# desc: inbound network traffic to mysql on a port other than the standard ports
|
||||
# condition: user.name = mysql and inbound and fd.sport != 3306
|
||||
# output: "Inbound network traffic to MySQL on unexpected port (connection=%fd.name)"
|
||||
# priority: WARNING
|
||||
|
||||
# - rule: HTTP server unexpected network inbound traffic
|
||||
# desc: inbound network traffic to a http server program on a port other than the standard ports
|
||||
# condition: proc.name in (http_server_binaries) and inbound and fd.sport != 80 and fd.sport != 443
|
||||
# output: "Inbound network traffic to HTTP Server on unexpected port (connection=%fd.name)"
|
||||
# priority: WARNING
|
||||
@@ -111,7 +111,7 @@
|
||||
items: [add-shell, remove-shell]
|
||||
|
||||
- macro: shell_procs
|
||||
condition: (proc.name in (shell_binaries))
|
||||
condition: proc.name in (shell_binaries)
|
||||
|
||||
- list: coreutils_binaries
|
||||
items: [
|
||||
@@ -1265,7 +1265,7 @@
|
||||
- list: known_root_files
|
||||
items: [/root/.monit.state, /root/.auth_tokens, /root/.bash_history, /root/.ash_history, /root/.aws/credentials,
|
||||
/root/.viminfo.tmp, /root/.lesshst, /root/.bzr.log, /root/.gitconfig.lock, /root/.babel.json, /root/.localstack,
|
||||
/root/.node_repl_history, /root/.mongorc.js, /root/.dbshell, /root/.augeas/history, /root/.rnd, /root/.wget-hsts, /health]
|
||||
/root/.node_repl_history, /root/.mongorc.js, /root/.dbshell, /root/.augeas/history, /root/.rnd, /root/.wget-hsts, /health, /exec.fifo]
|
||||
|
||||
- list: known_root_directories
|
||||
items: [/root/.oracle_jre_usage, /root/.ssh, /root/.subversion, /root/.nami]
|
||||
@@ -1774,7 +1774,8 @@
|
||||
gcr.io/google_containers/hyperkube,
|
||||
gcr.io/google_containers/kube-proxy, docker.io/calico/node,
|
||||
docker.io/rook/toolbox, docker.io/cloudnativelabs/kube-router, docker.io/consul,
|
||||
docker.io/datadog/docker-dd-agent, docker.io/datadog/agent, docker.io/docker/ucp-agent, docker.io/gliderlabs/logspout
|
||||
docker.io/datadog/docker-dd-agent, docker.io/datadog/agent, docker.io/docker/ucp-agent, docker.io/gliderlabs/logspout,
|
||||
docker.io/netdata/netdata, docker.io/google/cadvisor, docker.io/prom/node-exporter
|
||||
]
|
||||
|
||||
- macro: falco_sensitive_mount_containers
|
||||
@@ -2341,12 +2342,16 @@
|
||||
- macro: allowed_clear_log_files
|
||||
condition: (never_true)
|
||||
|
||||
- macro: trusted_logging_images
|
||||
condition: (container.image.repository endswith "splunk/fluentd-hec")
|
||||
|
||||
- rule: Clear Log Activities
|
||||
desc: Detect clearing of critical log files
|
||||
condition: >
|
||||
open_write and
|
||||
access_log_files and
|
||||
evt.arg.flags contains "O_TRUNC" and
|
||||
not trusted_logging_images and
|
||||
not allowed_clear_log_files
|
||||
output: >
|
||||
Log files were tampered (user=%user.name command=%proc.cmdline file=%fd.name container_id=%container.id image=%container.image.repository)
|
||||
|
||||
@@ -221,6 +221,8 @@ spec:
|
||||
path: falco_rules.yaml
|
||||
- key: falco_rules.local.yaml
|
||||
path: falco_rules.local.yaml
|
||||
- key: application_rules.yaml
|
||||
path: rules.available/application_rules.yaml
|
||||
{{- if .Values.falco.webserver.enabled }}
|
||||
- key: k8s_audit_rules.yaml
|
||||
path: k8s_audit_rules.yaml
|
||||
|
||||
@@ -3,7 +3,7 @@
|
||||
image:
|
||||
registry: docker.io
|
||||
repository: falcosecurity/falco
|
||||
tag: 0.16.0
|
||||
tag: 0.17.0
|
||||
pullPolicy: IfNotPresent
|
||||
|
||||
docker:
|
||||
|
||||
Reference in New Issue
Block a user