Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

rule(list network_tool_binaries): Add some network tools to detect suspicious network activity #975

Merged
merged 2 commits into from
Dec 16, 2019

Conversation

rung
Copy link
Contributor

@rung rung commented Dec 16, 2019

Signed-off-by: Hiroki Suezawa suezawa@gmail.com

What type of PR is this?
/kind rule-update

Any specific area of the project related to this PR?
/area rules

What this PR does / why we need it:

What this PR does

  • Add network tool binaries to detect suspicious network process.

Why we need it

  • I added some common tools which attackers often use.

Which issue(s) this PR fixes:

Fixes #

Special notes for your reviewer:
@Kaizhe sorry, this is same PR as this.
#973 (comment)

Does this PR introduce a user-facing change?:

rule(list network_tool_binaries): Add some network tools to detect suspicious network activity.

rung added 2 commits December 13, 2019 23:04
Signed-off-by: Hiroki Suezawa <suezawa@gmail.com>
Signed-off-by: Hiroki Suezawa <suezawa@gmail.com>
@rung
Copy link
Contributor Author

rung commented Dec 16, 2019

/cc @Kaizhe

@poiana poiana requested a review from Kaizhe December 16, 2019 17:15
Copy link
Contributor

@krisnova krisnova left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me
/lgtm

@poiana
Copy link
Contributor

poiana commented Dec 16, 2019

LGTM label has been added.

Git tree hash: ce8ba73274fecdf8ae5aa1c6edca16ae34a1e6e3

@poiana
Copy link
Contributor

poiana commented Dec 16, 2019

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: fntlnz, Kaizhe, kris-nova

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@fntlnz fntlnz merged commit cd94d05 into falcosecurity:dev Dec 16, 2019
@rung rung deleted the add-network-tools branch December 16, 2019 21:47
@fntlnz fntlnz added this to the 0.19.0 milestone Jan 22, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants