Thomas Stromberg
|
a100aa307f
|
Add more paths to unexpected-hidden-system-paths, rename
|
2023-01-19 11:42:44 -05:00 |
|
Thomas Stromberg
|
5abe66644b
|
old binaries: fix errant mtime comparison
|
2023-01-19 11:42:00 -05:00 |
|
Thomas Stromberg
|
5c421f7c96
|
Refactor unexpected-tmp-executables for magic awareness
|
2023-01-18 14:41:36 -05:00 |
|
Thomas Stromberg
|
f5e08ceec2
|
False positives: Chrome extensions, Steam games, tmp files, Photoshop
|
2023-01-18 14:10:33 -05:00 |
|
Thomas Stromberg
|
ef5d8afdd0
|
False positives: homekit, setxid overflows, buildx, tmp files
|
2023-01-18 10:57:43 -05:00 |
|
Thomas Stromberg
|
7b79b19090
|
False positive reduction: Messenger, Chrome, Final Cut Pro, etc
|
2023-01-18 09:49:56 -05:00 |
|
Thomas Stromberg
|
42e9f2721b
|
FP removal: plymouth, 1Password, firejail, systemd
|
2023-01-16 13:55:53 -05:00 |
|
Thomas Stromberg
|
d415b36b57
|
FP removal: Selenium, PolKit helper, gephi, docker-credential-gcloud, firejail, etc
|
2023-01-16 12:56:39 -05:00 |
|
Thomas Stromberg
|
e3401a07c6
|
Weekend false-positive flush
|
2023-01-14 08:19:26 -05:00 |
|
Thomas Stromberg
|
cb896b9e10
|
Filter out new false positives
|
2023-01-13 15:24:18 -05:00 |
|
Thomas Stromberg
|
1b79359b68
|
Friday False Positive Flush
|
2023-01-13 14:10:43 -05:00 |
|
Thomas Strömberg
|
cb0ed647d8
|
Merge branch 'main' into bugfixesJan13
|
2023-01-13 13:56:19 -05:00 |
|
Thomas Stromberg
|
4ec1581cc3
|
Also include binaries running from a hidden directory (1 deep)
|
2023-01-13 13:48:47 -05:00 |
|
Thomas Stromberg
|
420d269025
|
Reformat and reduce false positives
|
2023-01-09 15:10:48 -05:00 |
|
Thomas Stromberg
|
c7e4252af1
|
Remove false positives, fix some queries that failed to show a parent pid
|
2023-01-09 10:46:30 -05:00 |
|
Thomas Stromberg
|
e8af31a348
|
false positives: dots, ipn, apport-gtk, homebrew, hyperkey, contexts
|
2023-01-09 09:34:20 -05:00 |
|
Thomas Stromberg
|
2bcf9316cf
|
Add some hash fields, fix some false positives
|
2023-01-09 09:04:38 -05:00 |
|
Thomas Stromberg
|
4eb6993272
|
Catch up to some older false positives we ran into
|
2023-01-06 17:11:24 -05:00 |
|
Thomas Stromberg
|
1aefbe5e91
|
More false positive removal
|
2023-01-06 16:01:35 -05:00 |
|
Thomas Stromberg
|
05a39a78d3
|
Flush out more false positives across the stack
|
2023-01-06 10:36:48 -05:00 |
|
Thomas Stromberg
|
7455c22e3c
|
Fix missing /
|
2023-01-06 10:19:33 -05:00 |
|
Thomas Stromberg
|
9843def319
|
Fix more false positives, particularly in shell/fetcher parents
|
2023-01-06 10:18:19 -05:00 |
|
Thomas Stromberg
|
ba23df1fef
|
Catch up to other false positives over winter break
|
2023-01-04 11:03:38 -05:00 |
|
Thomas Strömberg
|
12acae7250
|
Merge pull request #104 from tstromberg/new-years
New Years FP cleanup: monitorix, snap-confine, steam, spotify, etc
|
2023-01-03 08:50:59 -05:00 |
|
Thomas Stromberg
|
a8b95a2c9e
|
New Years cleanup: monitorix, snap-confine, steam, spotify, etc
|
2023-01-03 08:50:19 -05:00 |
|
Thomas Stromberg
|
6ca3d92243
|
Filter out Docker children too
|
2022-12-20 07:52:04 -05:00 |
|
Thomas Stromberg
|
15d3251120
|
False-positive flush: mount.ntfs, docker-credential-desktop, exotic socket refactor
|
2022-12-19 18:06:06 -05:00 |
|
Thomas Stromberg
|
49a19a6fd5
|
Sort out more false positives
|
2022-12-16 17:37:32 -05:00 |
|
Thomas Stromberg
|
404adf3e1f
|
Another false positive flush: Capital One, tailscaled, agetty, snap, ninja, epson printers, etc
|
2022-12-15 16:51:58 -05:00 |
|
Thomas Stromberg
|
16f9b2f3ee
|
Remove more false positives: kind, gopls, docker.socket, etc
|
2022-12-15 10:20:16 -05:00 |
|
Thomas Stromberg
|
76d5c8564b
|
Resolve latest reported false positives
|
2022-12-02 11:20:18 -05:00 |
|
Thomas Stromberg
|
b9e0ad34a3
|
Post-Thanksgiving false positive flush
|
2022-11-28 16:06:07 -05:00 |
|
Thomas Stromberg
|
39e9aee6eb
|
Split parent-missing-from-disk, address false positives
|
2022-11-23 07:10:03 -05:00 |
|
Thomas Stromberg
|
a134827165
|
Add gdm-session-wor
|
2022-11-22 09:24:03 -05:00 |
|
Thomas Stromberg
|
6a7c4b6668
|
Pre-Thanksgiving False Positive cleanup, including Pop!OS support
|
2022-11-22 09:21:03 -05:00 |
|
Thomas Stromberg
|
8e3d6a1614
|
False positives: melange, ~/dev, debian-sa1, AdBlock, cover, kubelr, etc
|
2022-11-18 10:27:43 -05:00 |
|
Thomas Stromberg
|
85fdfaaa62
|
empty-environ: only check root pids to reduce false-positives
|
2022-11-18 09:32:00 -05:00 |
|
Thomas Stromberg
|
eeeaeecda1
|
Add exceptions for Microsoft teams, ldconfig, fix go build paths
|
2022-11-17 07:20:19 -05:00 |
|
Thomas Strömberg
|
60d66a5e41
|
Merge pull request #86 from tstromberg/hidden-exec
Add hidden-executable rule
|
2022-11-16 20:56:14 -05:00 |
|
Thomas Stromberg
|
288ec9e0f5
|
Add hidden-executable rule
|
2022-11-16 20:55:49 -05:00 |
|
Thomas Stromberg
|
9f63e3b21d
|
Begin making use of cgroup_paths, clear more false positives
|
2022-11-16 16:52:39 -05:00 |
|
Thomas Stromberg
|
3d7bc8363e
|
More false positive management
|
2022-11-16 14:49:36 -05:00 |
|
Thomas Stromberg
|
18f17bbee8
|
Complete cleanup phase 1
|
2022-11-16 11:18:45 -05:00 |
|
Thomas Stromberg
|
8047c88374
|
Run 'make reformat'
|
2022-11-16 11:02:29 -05:00 |
|
Thomas Stromberg
|
5d1e64ecc1
|
Fix file.mode comparisons
|
2022-11-16 11:01:22 -05:00 |
|
Thomas Stromberg
|
febf6cfebd
|
Remove newer access time check, add Sublime/Microsoft exclusion
|
2022-11-16 10:56:58 -05:00 |
|
Thomas Stromberg
|
2f30604c07
|
Allow Software Signing procs to be empty
|
2022-11-16 10:56:36 -05:00 |
|
Thomas Stromberg
|
f78cca5844
|
Be more lenient about Software Signing processes
|
2022-11-16 10:54:23 -05:00 |
|
Thomas Stromberg
|
e8ee572311
|
Add exception for snap container mounts
|
2022-11-16 10:39:21 -05:00 |
|
Thomas Stromberg
|
ac4a0b84df
|
var executables: put quote marks around modes with leading zeros
|
2022-11-11 07:53:45 -05:00 |
|