Thomas Stromberg
|
49a19a6fd5
|
Sort out more false positives
|
2022-12-16 17:37:32 -05:00 |
|
Thomas Stromberg
|
404adf3e1f
|
Another false positive flush: Capital One, tailscaled, agetty, snap, ninja, epson printers, etc
|
2022-12-15 16:51:58 -05:00 |
|
Thomas Stromberg
|
0b8a67a48f
|
Add exception for JetBrains Toolbox
|
2022-12-15 10:25:35 -05:00 |
|
Thomas Strömberg
|
26a800d52b
|
Merge pull request #96 from tstromberg/dec15
Clear more false positives: Signal, Kitty, KIND, Acrobat, etc
|
2022-12-15 10:21:49 -05:00 |
|
Thomas Stromberg
|
16f9b2f3ee
|
Remove more false positives: kind, gopls, docker.socket, etc
|
2022-12-15 10:20:16 -05:00 |
|
Thomas Stromberg
|
60e5435ed4
|
Allow mount-product-files and / (bad data), add cgroup_path
|
2022-12-15 09:20:41 -05:00 |
|
Thomas Stromberg
|
47b208eb71
|
Allow gcloud auth application-default login
|
2022-12-15 09:12:30 -05:00 |
|
Thomas Stromberg
|
685a79d3e1
|
Add Vimium
|
2022-12-15 09:11:14 -05:00 |
|
Thomas Stromberg
|
2731759d9b
|
Add Signal Helper
|
2022-12-15 09:07:11 -05:00 |
|
Thomas Stromberg
|
76d5c8564b
|
Resolve latest reported false positives
|
2022-12-02 11:20:18 -05:00 |
|
Thomas Strömberg
|
b40eb32d0f
|
Merge pull request #95 from tstromberg/post-tgiving
Post-Thanksgiving false positive flush
|
2022-11-28 16:08:37 -05:00 |
|
Thomas Stromberg
|
b9e0ad34a3
|
Post-Thanksgiving false positive flush
|
2022-11-28 16:06:07 -05:00 |
|
Thomas Strömberg
|
7e038c7e2a
|
Merge pull request #94 from tstromberg/makefile-fixes
Add IR no-wifi ruleset
|
2022-11-23 07:33:39 -05:00 |
|
Thomas Stromberg
|
09962c8dca
|
Add IR no-wifi ruleset
|
2022-11-23 07:32:52 -05:00 |
|
Thomas Strömberg
|
f99109d962
|
Merge pull request #93 from tstromberg/makefile-fixes
Makefile: Rename .sql targets to .conf, extend max-duration for IR
|
2022-11-23 07:15:17 -05:00 |
|
Thomas Stromberg
|
724e2fbc84
|
Makefile: Rename .sql targets to .conf, extend max-duration for IR
|
2022-11-23 07:14:53 -05:00 |
|
Thomas Strömberg
|
9e0e618070
|
Merge pull request #92 from tstromberg/pre-turkey-day
Split parent-missing-from-disk, add more explicit name to long-uptime, address fps
|
2022-11-23 07:12:21 -05:00 |
|
Thomas Stromberg
|
546d1367eb
|
Rename unusually-long-uptime
|
2022-11-23 07:10:41 -05:00 |
|
Thomas Stromberg
|
39e9aee6eb
|
Split parent-missing-from-disk, address false positives
|
2022-11-23 07:10:03 -05:00 |
|
Thomas Strömberg
|
9e321d022b
|
Merge pull request #91 from tstromberg/pre-turkey-day
Pre-Thanksgiving False Positive cleanup, including Pop!OS support
|
2022-11-22 16:35:26 -05:00 |
|
Thomas Stromberg
|
4c242773a2
|
Add ~/Code exception, widen pnpm exception
|
2022-11-22 16:30:09 -05:00 |
|
Thomas Stromberg
|
8281a825db
|
Add dnf with python 3.11
|
2022-11-22 16:29:52 -05:00 |
|
Thomas Stromberg
|
a134827165
|
Add gdm-session-wor
|
2022-11-22 09:24:03 -05:00 |
|
Thomas Stromberg
|
6a7c4b6668
|
Pre-Thanksgiving False Positive cleanup, including Pop!OS support
|
2022-11-22 09:21:03 -05:00 |
|
Thomas Strömberg
|
df4fdeba30
|
Merge pull request #90 from tstromberg/last-false-week
False positives: melange, ~/dev, debian-sa1, AdBlock, cover, kubelr, etc
|
2022-11-18 10:29:02 -05:00 |
|
Thomas Stromberg
|
8e3d6a1614
|
False positives: melange, ~/dev, debian-sa1, AdBlock, cover, kubelr, etc
|
2022-11-18 10:27:43 -05:00 |
|
Thomas Strömberg
|
967bac31db
|
Merge pull request #89 from tstromberg/more-alerts
empty-environ: only check root pids to reduce false-positives
|
2022-11-18 09:33:52 -05:00 |
|
Thomas Stromberg
|
85fdfaaa62
|
empty-environ: only check root pids to reduce false-positives
|
2022-11-18 09:32:00 -05:00 |
|
Thomas Strömberg
|
f13d52a84c
|
Merge pull request #88 from tstromberg/more-alerts
Add goa-daemon exception (sends telemetry to Google)
|
2022-11-17 10:19:19 -05:00 |
|
Thomas Stromberg
|
018eb595c5
|
Add goa-daemon exception (sends telemetry to Google)
|
2022-11-17 10:17:45 -05:00 |
|
Thomas Strömberg
|
81f0f52bcb
|
Merge pull request #87 from tstromberg/more-alerts
Add exceptions for Microsoft teams, gcloud, qemu, ldconfig, fix go build paths
|
2022-11-17 07:21:30 -05:00 |
|
Thomas Stromberg
|
eeeaeecda1
|
Add exceptions for Microsoft teams, ldconfig, fix go build paths
|
2022-11-17 07:20:19 -05:00 |
|
Thomas Strömberg
|
60d66a5e41
|
Merge pull request #86 from tstromberg/hidden-exec
Add hidden-executable rule
|
2022-11-16 20:56:14 -05:00 |
|
Thomas Stromberg
|
288ec9e0f5
|
Add hidden-executable rule
|
2022-11-16 20:55:49 -05:00 |
|
Thomas Strömberg
|
f04f1cdf94
|
Merge pull request #85 from tstromberg/alert-cleanup
Begin making use of cgroup_paths, clear more false positives
|
2022-11-16 16:53:23 -05:00 |
|
Thomas Stromberg
|
9f63e3b21d
|
Begin making use of cgroup_paths, clear more false positives
|
2022-11-16 16:52:39 -05:00 |
|
Thomas Stromberg
|
205e45a934
|
Merge branch 'main' into alert-cleanup
|
2022-11-16 14:49:42 -05:00 |
|
Thomas Stromberg
|
3d7bc8363e
|
More false positive management
|
2022-11-16 14:49:36 -05:00 |
|
Thomas Strömberg
|
e844869be8
|
Merge pull request #84 from tstromberg/alert-cleanup
Fedora 37, better touch logic (macOS) and other false-positive cleanup
|
2022-11-16 11:19:47 -05:00 |
|
Thomas Stromberg
|
18f17bbee8
|
Complete cleanup phase 1
|
2022-11-16 11:18:45 -05:00 |
|
Thomas Stromberg
|
b8d66ae814
|
Allow -sP /usr/sbin/firewalld
|
2022-11-16 11:03:34 -05:00 |
|
Thomas Stromberg
|
8047c88374
|
Run 'make reformat'
|
2022-11-16 11:02:29 -05:00 |
|
Thomas Stromberg
|
5d1e64ecc1
|
Fix file.mode comparisons
|
2022-11-16 11:01:22 -05:00 |
|
Thomas Stromberg
|
febf6cfebd
|
Remove newer access time check, add Sublime/Microsoft exclusion
|
2022-11-16 10:56:58 -05:00 |
|
Thomas Stromberg
|
2f30604c07
|
Allow Software Signing procs to be empty
|
2022-11-16 10:56:36 -05:00 |
|
Thomas Stromberg
|
f78cca5844
|
Be more lenient about Software Signing processes
|
2022-11-16 10:54:23 -05:00 |
|
Thomas Stromberg
|
398cbde41f
|
Add more exception for local webhook development
|
2022-11-16 10:40:46 -05:00 |
|
Thomas Stromberg
|
e8ee572311
|
Add exception for snap container mounts
|
2022-11-16 10:39:21 -05:00 |
|
Thomas Stromberg
|
f36b74c487
|
Fix ko-app allowance
|
2022-11-16 10:38:22 -05:00 |
|
Thomas Stromberg
|
7527e11a3b
|
Add systemd-fsckd, blueman-mechanism
|
2022-11-16 10:37:38 -05:00 |
|