From 23399f8428b7e8557352fed1844282297c601f6f Mon Sep 17 00:00:00 2001 From: Fede Barcelona Date: Fri, 16 Aug 2019 22:40:10 +0200 Subject: [PATCH] [stable/falco] Update Falco to 0.17.0 (#16366) Signed-off-by: Federico Barcelona --- stable/falco/CHANGELOG.md | 7 + stable/falco/Chart.yaml | 4 +- stable/falco/README.md | 144 ++++++++--------- stable/falco/rules/application_rules.yaml | 189 ++++++++++++++++++++++ stable/falco/rules/falco_rules.yaml | 11 +- stable/falco/templates/daemonset.yaml | 2 + stable/falco/values.yaml | 2 +- 7 files changed, 281 insertions(+), 78 deletions(-) create mode 100644 stable/falco/rules/application_rules.yaml diff --git a/stable/falco/CHANGELOG.md b/stable/falco/CHANGELOG.md index a441769e3d..9bab3c89d9 100644 --- a/stable/falco/CHANGELOG.md +++ b/stable/falco/CHANGELOG.md @@ -3,6 +3,13 @@ This file documents all notable changes to Sysdig Falco Helm Chart. The release numbering uses [semantic versioning](http://semver.org). +## v1.0.4 + +### Minor Changes + +* Upgrade to Falco 0.17.0 +* Upgrade rules to Falco 0.17.0 + ## v1.0.3 ### Minor Changes diff --git a/stable/falco/Chart.yaml b/stable/falco/Chart.yaml index 9207098f3c..03ab9086cd 100644 --- a/stable/falco/Chart.yaml +++ b/stable/falco/Chart.yaml @@ -1,7 +1,7 @@ apiVersion: v1 name: falco -version: 1.0.3 -appVersion: 0.16.0 +version: 1.0.4 +appVersion: 0.17.0 description: Falco keywords: - monitoring diff --git a/stable/falco/README.md b/stable/falco/README.md index 6ef90ead99..001282524f 100644 --- a/stable/falco/README.md +++ b/stable/falco/README.md @@ -43,78 +43,78 @@ The command removes all the Kubernetes components associated with the chart and The following table lists the configurable parameters of the Falco chart and their default values. -| Parameter | Description | Default | -| --- | --- | --- | -| `image.registry` | The image registry to pull from | `docker.io` | -| `image.repository` | The image repository to pull from | `falcosecurity/falco` | -| `image.tag` | The image tag to pull | `0.16.0` | -| `image.pullPolicy` | The image pull policy | `IfNotPresent` | -| `cri.socket` | The path of the CRI socket | `/run/containerd/containerd.sock` | -| `docker.socket` | The path of the Docker daemon socket | `/var/run/docker.sock` | -| `resources.requests.cpu` | CPU requested for being run in a node | `100m` | -| `resources.requests.memory` | Memory requested for being run in a node | `512Mi` | -| `resources.limits.cpu` | CPU limit | `200m` | -| `resources.limits.memory` | Memory limit | `1024Mi` | -| `extraArgs` | Specify additional container args | `[]` | -| `rbac.create` | If true, create & use RBAC resources | `true` | -| `serviceAccount.create` | Create serviceAccount | `true` | -| `serviceAccount.name` | Use this value as serviceAccountName | ` ` | -| `fakeEventGenerator.enabled` | Run falco-event-generator for sample events | `false` | -| `fakeEventGenerator.replicas` | How many replicas of falco-event-generator to run | `1` | -| `daemonset.updateStrategy.type` | The updateStrategy for updating the daemonset | `RollingUpdate` | -| `daemonset.env` | Extra environment variables passed to daemonset pods | `{}` | -| `podSecurityPolicy.create` | If true, create & use podSecurityPolicy | `false` | -| `proxy.httpProxy` | Set the Proxy server if is behind a firewall | ` ` | -| `proxy.httpsProxy` | Set the Proxy server if is behind a firewall | ` ` | -| `proxy.noProxy` | Set the Proxy server if is behind a firewall | ` ` | -| `timezone` | Set the daemonset's timezone | ` ` | -| `priorityClassName` | Set the daemonset's priorityClassName | ` ` | -| `ebpf.enabled` | Enable eBPF support for Falco instead of `falco-probe` kernel module | `false` | -| `ebpf.settings.hostNetwork` | Needed to enable eBPF JIT at runtime for performance reasons | `true` | -| `ebpf.settings.mountEtcVolume` | Needed to detect which kernel version are running in Google COS | `true` | -| `falco.rulesFile` | The location of the rules files | `[/etc/falco/falco_rules.yaml, /etc/falco/falco_rules.local.yaml, /etc/falco/rules.d]` | -| `falco.timeFormatISO8601` | Display times using ISO 8601 instead of local time zone | `false` | -| `falco.jsonOutput` | Output events in json or text | `false` | -| `falco.jsonIncludeOutputProperty` | Include output property in json output | `true` | -| `falco.logStderr` | Send Falco debugging information logs to stderr | `true` | -| `falco.logSyslog` | Send Falco debugging information logs to syslog | `true` | -| `falco.logLevel` | The minimum level of Falco debugging information to include in logs | `info` | -| `falco.priority` | The minimum rule priority level to load and run | `debug` | -| `falco.bufferedOutputs` | Use buffered outputs to channels | `false` | -| `falco.syscallEventDrops.actions` | Actions to be taken when system calls were dropped from the circular buffer | `[log, alert]` | -| `falco.syscallEventDrops.rate` | Rate at which log/alert messages are emitted | `.03333` | -| `falco.syscallEventDrops.maxBurst` | Max burst of messages emitted | `10` | -| `falco.outputs.rate` | Number of tokens gained per second | `1` | -| `falco.outputs.maxBurst` | Maximum number of tokens outstanding | `1000` | -| `falco.syslogOutput.enabled` | Enable syslog output for security notifications | `true` | -| `falco.fileOutput.enabled` | Enable file output for security notifications | `false` | -| `falco.fileOutput.keepAlive` | Open file once or every time a new notification arrives | `false` | -| `falco.fileOutput.filename` | The filename for logging notifications | `./events.txt` | -| `falco.stdoutOutput.enabled` | Enable stdout output for security notifications | `true` | -| `falco.webserver.enabled` | Enable Falco embedded webserver to accept K8s audit events | `false` | -| `falco.webserver.listenPort` | Port where Falco embedded webserver listen to connections | `8765` | -| `falco.webserver.k8sAuditEndpoint` | Endpoint where Falco embedded webserver accepts K8s audit events | `/k8s-audit` | -| `falco.webserver.clusterIP` | ClusterIP address where Falco will listen to K8s audit events. If you enable the webserver, this field is required | ` ` | -| `falco.programOutput.enabled` | Enable program output for security notifications | `false` | -| `falco.programOutput.keepAlive` | Start the program once or re-spawn when a notification arrives | `false` | -| `falco.programOutput.program` | Command to execute for program output | `mail -s "Falco Notification" someone@example.com` | -| `falco.httpOutput.enabled` | Enable http output for security notifications | `false` | -| `falco.httpOutput.url` | Url to notify using the http output when a notification arrives | `http://some.url` | -| `customRules` | Third party rules enabled for Falco | `{}` | -| `integrations.gcscc.enabled` | Enable Google Cloud Security Command Center integration | `false` | -| `integrations.gcscc.webhookUrl` | The URL where sysdig-gcscc-connector webhook is listening | `http://sysdig-gcscc-connector.default.svc.cluster.local:8080/events` | -| `integrations.gcscc.webhookAuthenticationToken` | Token used for authentication and webhook | `b27511f86e911f20b9e0f9c8104b4ec4` | -| `integrations.natsOutput.enabled` | Enable NATS Output integration | `false` | -| `integrations.natsOutput.natsUrl` | The NATS' URL where Falco is going to publish security alerts | `nats://nats.nats-io.svc.cluster.local:4222` | -| `integrations.pubsubOutput.credentialsData` | Contents retrieved from `cat $HOME/.config/gcloud/legacy_credentials//adc.json | jq -c .` | ` ` | -| `integrations.pubsubOutput.enabled` | Enable GCloud PubSub Output Integration | `false` | -| `integrations.pubsubOutput.projectID` | GCloud Project ID where the Pub/Sub will be created | ` ` | -| `integrations.snsOutput.enabled` | Enable Amazon SNS Output integration | `false` | -| `integrations.snsOutput.topic` | The SNS topic where Falco is going to publish security alerts | ` ` | -| `integrations.snsOutput.aws_access_key_id` | The AWS Access Key Id credentials for access to SNS n | ` ` | -| `integrations.snsOutput.aws_secret_access_key` | The AWS Secret Access Key credential to access to SNS | ` ` | -| `integrations.snsOutput.aws_default_region` | The AWS region where SNS is deployed | ` ` | -| `tolerations` | The tolerations for scheduling | `node-role.kubernetes.io/master:NoSchedule` | +| Parameter | Description | Default | +| --- | --- | --- | +| `image.registry` | The image registry to pull from | `docker.io` | +| `image.repository` | The image repository to pull from | `falcosecurity/falco` | +| `image.tag` | The image tag to pull | `0.17.0` | +| `image.pullPolicy` | The image pull policy | `IfNotPresent` | +| `cri.socket` | The path of the CRI socket | `/run/containerd/containerd.sock` | +| `docker.socket` | The path of the Docker daemon socket | `/var/run/docker.sock` | +| `resources.requests.cpu` | CPU requested for being run in a node | `100m` | +| `resources.requests.memory` | Memory requested for being run in a node | `512Mi` | +| `resources.limits.cpu` | CPU limit | `200m` | +| `resources.limits.memory` | Memory limit | `1024Mi` | +| `extraArgs` | Specify additional container args | `[]` | +| `rbac.create` | If true, create & use RBAC resources | `true` | +| `serviceAccount.create` | Create serviceAccount | `true` | +| `serviceAccount.name` | Use this value as serviceAccountName | ` ` | +| `fakeEventGenerator.enabled` | Run falco-event-generator for sample events | `false` | +| `fakeEventGenerator.replicas` | How many replicas of falco-event-generator to run | `1` | +| `daemonset.updateStrategy.type` | The updateStrategy for updating the daemonset | `RollingUpdate` | +| `daemonset.env` | Extra environment variables passed to daemonset pods | `{}` | +| `podSecurityPolicy.create` | If true, create & use podSecurityPolicy | `false` | +| `proxy.httpProxy` | Set the Proxy server if is behind a firewall | ` ` | +| `proxy.httpsProxy` | Set the Proxy server if is behind a firewall | ` ` | +| `proxy.noProxy` | Set the Proxy server if is behind a firewall | ` ` | +| `timezone` | Set the daemonset's timezone | ` ` | +| `priorityClassName` | Set the daemonset's priorityClassName | ` ` | +| `ebpf.enabled` | Enable eBPF support for Falco instead of `falco-probe` kernel module | `false` | +| `ebpf.settings.hostNetwork` | Needed to enable eBPF JIT at runtime for performance reasons | `true` | +| `ebpf.settings.mountEtcVolume` | Needed to detect which kernel version are running in Google COS | `true` | +| `falco.rulesFile` | The location of the rules files | `[/etc/falco/falco_rules.yaml, /etc/falco/falco_rules.local.yaml, /etc/falco/rules.available/application_rules.yaml, /etc/falco/rules.d]` | +| `falco.timeFormatISO8601` | Display times using ISO 8601 instead of local time zone | `false` | +| `falco.jsonOutput` | Output events in json or text | `false` | +| `falco.jsonIncludeOutputProperty` | Include output property in json output | `true` | +| `falco.logStderr` | Send Falco debugging information logs to stderr | `true` | +| `falco.logSyslog` | Send Falco debugging information logs to syslog | `true` | +| `falco.logLevel` | The minimum level of Falco debugging information to include in logs | `info` | +| `falco.priority` | The minimum rule priority level to load and run | `debug` | +| `falco.bufferedOutputs` | Use buffered outputs to channels | `false` | +| `falco.syscallEventDrops.actions` | Actions to be taken when system calls were dropped from the circular buffer | `[log, alert]` | +| `falco.syscallEventDrops.rate` | Rate at which log/alert messages are emitted | `.03333` | +| `falco.syscallEventDrops.maxBurst` | Max burst of messages emitted | `10` | +| `falco.outputs.rate` | Number of tokens gained per second | `1` | +| `falco.outputs.maxBurst` | Maximum number of tokens outstanding | `1000` | +| `falco.syslogOutput.enabled` | Enable syslog output for security notifications | `true` | +| `falco.fileOutput.enabled` | Enable file output for security notifications | `false` | +| `falco.fileOutput.keepAlive` | Open file once or every time a new notification arrives | `false` | +| `falco.fileOutput.filename` | The filename for logging notifications | `./events.txt` | +| `falco.stdoutOutput.enabled` | Enable stdout output for security notifications | `true` | +| `falco.webserver.enabled` | Enable Falco embedded webserver to accept K8s audit events | `false` | +| `falco.webserver.listenPort` | Port where Falco embedded webserver listen to connections | `8765` | +| `falco.webserver.k8sAuditEndpoint` | Endpoint where Falco embedded webserver accepts K8s audit events | `/k8s-audit` | +| `falco.webserver.clusterIP` | ClusterIP address where Falco will listen to K8s audit events. If you enable the webserver, this field is required | ` ` | +| `falco.programOutput.enabled` | Enable program output for security notifications | `false` | +| `falco.programOutput.keepAlive` | Start the program once or re-spawn when a notification arrives | `false` | +| `falco.programOutput.program` | Command to execute for program output | `mail -s "Falco Notification" someone@example.com` | +| `falco.httpOutput.enabled` | Enable http output for security notifications | `false` | +| `falco.httpOutput.url` | Url to notify using the http output when a notification arrives | `http://some.url` | +| `customRules` | Third party rules enabled for Falco | `{}` | +| `integrations.gcscc.enabled` | Enable Google Cloud Security Command Center integration | `false` | +| `integrations.gcscc.webhookUrl` | The URL where sysdig-gcscc-connector webhook is listening | `http://sysdig-gcscc-connector.default.svc.cluster.local:8080/events` | +| `integrations.gcscc.webhookAuthenticationToken` | Token used for authentication and webhook | `b27511f86e911f20b9e0f9c8104b4ec4` | +| `integrations.natsOutput.enabled` | Enable NATS Output integration | `false` | +| `integrations.natsOutput.natsUrl` | The NATS' URL where Falco is going to publish security alerts | `nats://nats.nats-io.svc.cluster.local:4222` | +| `integrations.pubsubOutput.credentialsData` | Contents retrieved from `cat $HOME/.config/gcloud/legacy_credentials//adc.json | jq -c .` | ` ` | +| `integrations.pubsubOutput.enabled` | Enable GCloud PubSub Output Integration | `false` | +| `integrations.pubsubOutput.projectID` | GCloud Project ID where the Pub/Sub will be created | ` ` | +| `integrations.snsOutput.enabled` | Enable Amazon SNS Output integration | `false` | +| `integrations.snsOutput.topic` | The SNS topic where Falco is going to publish security alerts | ` ` | +| `integrations.snsOutput.aws_access_key_id` | The AWS Access Key Id credentials for access to SNS n | ` ` | +| `integrations.snsOutput.aws_secret_access_key` | The AWS Secret Access Key credential to access to SNS | ` ` | +| `integrations.snsOutput.aws_default_region` | The AWS region where SNS is deployed | ` ` | +| `tolerations` | The tolerations for scheduling | `node-role.kubernetes.io/master:NoSchedule` | Specify each parameter using the `--set key=value[,key=value]` argument to `helm install`. For example, diff --git a/stable/falco/rules/application_rules.yaml b/stable/falco/rules/application_rules.yaml new file mode 100644 index 0000000000..6d19a203be --- /dev/null +++ b/stable/falco/rules/application_rules.yaml @@ -0,0 +1,189 @@ +# +# Copyright (C) 2016-2018 Draios Inc dba Sysdig. +# +# This file is part of falco. +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. +# + +- required_engine_version: 2 + +################################################################ +# By default all application-related rules are disabled for +# performance reasons. Depending on the application(s) you use, +# uncomment the corresponding rule definitions for +# application-specific activity monitoring. +################################################################ + +# Elasticsearch ports +- macro: elasticsearch_cluster_port + condition: fd.sport=9300 +- macro: elasticsearch_api_port + condition: fd.sport=9200 +- macro: elasticsearch_port + condition: elasticsearch_cluster_port or elasticsearch_api_port + +# - rule: Elasticsearch unexpected network inbound traffic +# desc: inbound network traffic to elasticsearch on a port other than the standard ports +# condition: user.name = elasticsearch and inbound and not elasticsearch_port +# output: "Inbound network traffic to Elasticsearch on unexpected port (connection=%fd.name)" +# priority: WARNING + +# - rule: Elasticsearch unexpected network outbound traffic +# desc: outbound network traffic from elasticsearch on a port other than the standard ports +# condition: user.name = elasticsearch and outbound and not elasticsearch_cluster_port +# output: "Outbound network traffic from Elasticsearch on unexpected port (connection=%fd.name)" +# priority: WARNING + + +# ActiveMQ ports +- macro: activemq_cluster_port + condition: fd.sport=61616 +- macro: activemq_web_port + condition: fd.sport=8161 +- macro: activemq_port + condition: activemq_web_port or activemq_cluster_port + +# - rule: Activemq unexpected network inbound traffic +# desc: inbound network traffic to activemq on a port other than the standard ports +# condition: user.name = activemq and inbound and not activemq_port +# output: "Inbound network traffic to ActiveMQ on unexpected port (connection=%fd.name)" +# priority: WARNING + +# - rule: Activemq unexpected network outbound traffic +# desc: outbound network traffic from activemq on a port other than the standard ports +# condition: user.name = activemq and outbound and not activemq_cluster_port +# output: "Outbound network traffic from ActiveMQ on unexpected port (connection=%fd.name)" +# priority: WARNING + + +# Cassandra ports +# https://docs.datastax.com/en/cassandra/2.0/cassandra/security/secureFireWall_r.html +- macro: cassandra_thrift_client_port + condition: fd.sport=9160 +- macro: cassandra_cql_port + condition: fd.sport=9042 +- macro: cassandra_cluster_port + condition: fd.sport=7000 +- macro: cassandra_ssl_cluster_port + condition: fd.sport=7001 +- macro: cassandra_jmx_port + condition: fd.sport=7199 +- macro: cassandra_port + condition: > + cassandra_thrift_client_port or + cassandra_cql_port or cassandra_cluster_port or + cassandra_ssl_cluster_port or cassandra_jmx_port + +# - rule: Cassandra unexpected network inbound traffic +# desc: inbound network traffic to cassandra on a port other than the standard ports +# condition: user.name = cassandra and inbound and not cassandra_port +# output: "Inbound network traffic to Cassandra on unexpected port (connection=%fd.name)" +# priority: WARNING + +# - rule: Cassandra unexpected network outbound traffic +# desc: outbound network traffic from cassandra on a port other than the standard ports +# condition: user.name = cassandra and outbound and not (cassandra_ssl_cluster_port or cassandra_cluster_port) +# output: "Outbound network traffic from Cassandra on unexpected port (connection=%fd.name)" +# priority: WARNING + +# Couchdb ports +# https://github.com/davisp/couchdb/blob/master/etc/couchdb/local.ini +- macro: couchdb_httpd_port + condition: fd.sport=5984 +- macro: couchdb_httpd_ssl_port + condition: fd.sport=6984 +# xxx can't tell what clustering ports are used. not writing rules for this +# yet. + +# Fluentd ports +- macro: fluentd_http_port + condition: fd.sport=9880 +- macro: fluentd_forward_port + condition: fd.sport=24224 + +# - rule: Fluentd unexpected network inbound traffic +# desc: inbound network traffic to fluentd on a port other than the standard ports +# condition: user.name = td-agent and inbound and not (fluentd_forward_port or fluentd_http_port) +# output: "Inbound network traffic to Fluentd on unexpected port (connection=%fd.name)" +# priority: WARNING + +# - rule: Tdagent unexpected network outbound traffic +# desc: outbound network traffic from fluentd on a port other than the standard ports +# condition: user.name = td-agent and outbound and not fluentd_forward_port +# output: "Outbound network traffic from Fluentd on unexpected port (connection=%fd.name)" +# priority: WARNING + +# Gearman ports +# http://gearman.org/protocol/ +# - rule: Gearman unexpected network outbound traffic +# desc: outbound network traffic from gearman on a port other than the standard ports +# condition: user.name = gearman and outbound and outbound and not fd.sport = 4730 +# output: "Outbound network traffic from Gearman on unexpected port (connection=%fd.name)" +# priority: WARNING + +# Zookeeper +- macro: zookeeper_port + condition: fd.sport = 2181 + +# Kafka ports +# - rule: Kafka unexpected network inbound traffic +# desc: inbound network traffic to kafka on a port other than the standard ports +# condition: user.name = kafka and inbound and fd.sport != 9092 +# output: "Inbound network traffic to Kafka on unexpected port (connection=%fd.name)" +# priority: WARNING + +# Memcached ports +# - rule: Memcached unexpected network inbound traffic +# desc: inbound network traffic to memcached on a port other than the standard ports +# condition: user.name = memcached and inbound and fd.sport != 11211 +# output: "Inbound network traffic to Memcached on unexpected port (connection=%fd.name)" +# priority: WARNING + +# - rule: Memcached unexpected network outbound traffic +# desc: any outbound network traffic from memcached. memcached never initiates outbound connections. +# condition: user.name = memcached and outbound +# output: "Unexpected Memcached outbound connection (connection=%fd.name)" +# priority: WARNING + + +# MongoDB ports +- macro: mongodb_server_port + condition: fd.sport = 27017 +- macro: mongodb_shardserver_port + condition: fd.sport = 27018 +- macro: mongodb_configserver_port + condition: fd.sport = 27019 +- macro: mongodb_webserver_port + condition: fd.sport = 28017 + +# - rule: Mongodb unexpected network inbound traffic +# desc: inbound network traffic to mongodb on a port other than the standard ports +# condition: > +# user.name = mongodb and inbound and not (mongodb_server_port or +# mongodb_shardserver_port or mongodb_configserver_port or mongodb_webserver_port) +# output: "Inbound network traffic to MongoDB on unexpected port (connection=%fd.name)" +# priority: WARNING + +# MySQL ports +# - rule: Mysql unexpected network inbound traffic +# desc: inbound network traffic to mysql on a port other than the standard ports +# condition: user.name = mysql and inbound and fd.sport != 3306 +# output: "Inbound network traffic to MySQL on unexpected port (connection=%fd.name)" +# priority: WARNING + +# - rule: HTTP server unexpected network inbound traffic +# desc: inbound network traffic to a http server program on a port other than the standard ports +# condition: proc.name in (http_server_binaries) and inbound and fd.sport != 80 and fd.sport != 443 +# output: "Inbound network traffic to HTTP Server on unexpected port (connection=%fd.name)" +# priority: WARNING diff --git a/stable/falco/rules/falco_rules.yaml b/stable/falco/rules/falco_rules.yaml index df8c12ae90..1a2a3c83fb 100644 --- a/stable/falco/rules/falco_rules.yaml +++ b/stable/falco/rules/falco_rules.yaml @@ -111,7 +111,7 @@ items: [add-shell, remove-shell] - macro: shell_procs - condition: (proc.name in (shell_binaries)) + condition: proc.name in (shell_binaries) - list: coreutils_binaries items: [ @@ -1265,7 +1265,7 @@ - list: known_root_files items: [/root/.monit.state, /root/.auth_tokens, /root/.bash_history, /root/.ash_history, /root/.aws/credentials, /root/.viminfo.tmp, /root/.lesshst, /root/.bzr.log, /root/.gitconfig.lock, /root/.babel.json, /root/.localstack, - /root/.node_repl_history, /root/.mongorc.js, /root/.dbshell, /root/.augeas/history, /root/.rnd, /root/.wget-hsts, /health] + /root/.node_repl_history, /root/.mongorc.js, /root/.dbshell, /root/.augeas/history, /root/.rnd, /root/.wget-hsts, /health, /exec.fifo] - list: known_root_directories items: [/root/.oracle_jre_usage, /root/.ssh, /root/.subversion, /root/.nami] @@ -1774,7 +1774,8 @@ gcr.io/google_containers/hyperkube, gcr.io/google_containers/kube-proxy, docker.io/calico/node, docker.io/rook/toolbox, docker.io/cloudnativelabs/kube-router, docker.io/consul, - docker.io/datadog/docker-dd-agent, docker.io/datadog/agent, docker.io/docker/ucp-agent, docker.io/gliderlabs/logspout + docker.io/datadog/docker-dd-agent, docker.io/datadog/agent, docker.io/docker/ucp-agent, docker.io/gliderlabs/logspout, + docker.io/netdata/netdata, docker.io/google/cadvisor, docker.io/prom/node-exporter ] - macro: falco_sensitive_mount_containers @@ -2341,12 +2342,16 @@ - macro: allowed_clear_log_files condition: (never_true) +- macro: trusted_logging_images + condition: (container.image.repository endswith "splunk/fluentd-hec") + - rule: Clear Log Activities desc: Detect clearing of critical log files condition: > open_write and access_log_files and evt.arg.flags contains "O_TRUNC" and + not trusted_logging_images and not allowed_clear_log_files output: > Log files were tampered (user=%user.name command=%proc.cmdline file=%fd.name container_id=%container.id image=%container.image.repository) diff --git a/stable/falco/templates/daemonset.yaml b/stable/falco/templates/daemonset.yaml index 645c71d931..e1b19ada12 100644 --- a/stable/falco/templates/daemonset.yaml +++ b/stable/falco/templates/daemonset.yaml @@ -221,6 +221,8 @@ spec: path: falco_rules.yaml - key: falco_rules.local.yaml path: falco_rules.local.yaml + - key: application_rules.yaml + path: rules.available/application_rules.yaml {{- if .Values.falco.webserver.enabled }} - key: k8s_audit_rules.yaml path: k8s_audit_rules.yaml diff --git a/stable/falco/values.yaml b/stable/falco/values.yaml index cc8b91ae7e..b1eb1e3093 100644 --- a/stable/falco/values.yaml +++ b/stable/falco/values.yaml @@ -3,7 +3,7 @@ image: registry: docker.io repository: falcosecurity/falco - tag: 0.16.0 + tag: 0.17.0 pullPolicy: IfNotPresent docker: