Thomas Stromberg
|
1961531adf
|
fpr: more refactor fallout
|
2023-04-28 14:40:12 -04:00 |
|
Thomas Stromberg
|
fbdd253d6a
|
fpr: post-refactor talker reduction
|
2023-04-28 14:09:57 -04:00 |
|
Thomas Stromberg
|
02337c28f0
|
fpr: cleanup and new additions
|
2023-04-27 12:00:08 -04:00 |
|
Thomas Stromberg
|
df925eaa6c
|
fpr: lghub, brew, pve, chrome exts, etc
|
2023-04-20 20:45:35 -04:00 |
|
Thomas Stromberg
|
9c3f783491
|
fpr everything
|
2023-04-17 16:20:35 -04:00 |
|
Thomas Stromberg
|
0dc6748dff
|
fpr: LGHUB keys, go, Acrobat, code, yum, fwupdatemgr
|
2023-03-31 06:19:30 -04:00 |
|
Thomas Stromberg
|
d4dd423745
|
fpr: Grammarly, semodule, docker-compose, xdg, etc
|
2023-03-30 18:44:01 -04:00 |
|
Thomas Stromberg
|
5ea01eabeb
|
Exclude .rustup toolchains
|
2023-03-28 17:02:30 -04:00 |
|
Thomas Stromberg
|
2d6ced6ae5
|
Remove powershell indicator
|
2023-03-28 17:02:14 -04:00 |
|
Thomas Stromberg
|
9b0ed09c8e
|
fpr: xdg, docker, dbus, bpfilter_umh, docker, spotify, mage
|
2023-03-28 16:25:26 -04:00 |
|
Thomas Stromberg
|
284796b895
|
fpr: snyk-ls, electron
|
2023-03-24 11:03:55 -04:00 |
|
Thomas Stromberg
|
570c36dc71
|
fpr: tilt, electron, cilium, write/read improvements
|
2023-03-24 10:42:06 -04:00 |
|
Thomas Stromberg
|
7a78199906
|
fpr: traceroute, thunderbird, garmin installer, chainctl, etc
|
2023-03-21 14:07:06 -04:00 |
|
Thomas Stromberg
|
fbab3701c0
|
fpr: Docker, Zwift, macOS updates, etc
|
2023-03-20 17:05:02 -04:00 |
|
Thomas Strömberg
|
621967a085
|
Merge pull request #230 from tstromberg/split-chmod
Add exceptions for Kandji
|
2023-03-17 15:49:30 -04:00 |
|
Thomas Stromberg
|
13a95a4f41
|
Add exceptions for Kandji
|
2023-03-17 15:46:00 -04:00 |
|
Thomas Strömberg
|
1b9e2a6ec1
|
Merge pull request #229 from tstromberg/split-chmod
unexpected-chmod-exec: Split and Linux/macOS queries
|
2023-03-17 15:39:26 -04:00 |
|
Thomas Stromberg
|
15c666a170
|
Fix references to p0.cmdline
|
2023-03-17 15:38:22 -04:00 |
|
Thomas Stromberg
|
e1db6fc2de
|
Fix split chmod detector
|
2023-03-17 15:19:33 -04:00 |
|
Thomas Stromberg
|
feb7c234e7
|
split unexpected-chmod-exec-event into Linux/macOS
|
2023-03-17 15:13:36 -04:00 |
|
Thomas Stromberg
|
6ddc478df4
|
fpr: Brother, Intel OneAPI, k6, firefox
|
2023-03-17 15:08:22 -04:00 |
|
Thomas Stromberg
|
fb6af4858a
|
chmod events: broaden snap exception
|
2023-03-17 10:52:28 -04:00 |
|
Thomas Stromberg
|
2bfd736d37
|
Use p0_cmd instead of p0.cmdline
|
2023-03-17 06:37:18 -04:00 |
|
Thomas Stromberg
|
7ceb7b2b19
|
fpr: NetworkManager, packer, rancher desktop, proxmox, sd
|
2023-03-17 06:32:54 -04:00 |
|
Thomas Stromberg
|
8154560703
|
chmod events: Include macOS, improve results
|
2023-03-17 06:24:26 -04:00 |
|
Thomas Stromberg
|
fbc2b207b4
|
fpr: Signal, apko, aws, melange, dash, stern
|
2023-03-16 17:29:11 -04:00 |
|
Thomas Stromberg
|
af9a78236e
|
New detector: unexpected chmod exec event
|
2023-03-16 16:53:32 -04:00 |
|
Thomas Stromberg
|
824efa9705
|
fpr: yum, systemd, cloud-sql-proxy, image-automation-controller, helm, bom, aws
|
2023-03-14 19:00:44 -04:00 |
|
Thomas Stromberg
|
09652bd91f
|
fpr: SA keys, libgtop, haproxy, gvproxy, slirp
|
2023-03-14 16:05:16 -04:00 |
|
Thomas Stromberg
|
b3825ba2b9
|
fpr: Canon Universal Installer, melange, GPG, key names
|
2023-03-06 15:11:11 -05:00 |
|
Thomas Stromberg
|
f25cfe1399
|
fpr: aws-sdk, melange, Tailscale, Xprotect, etc
|
2023-03-03 07:24:42 -05:00 |
|
Thomas Stromberg
|
12a5507907
|
Optimize recently-created-executables-macos
|
2023-02-24 17:24:09 -05:00 |
|
Thomas Stromberg
|
4150b1ee7c
|
macOS: Exceptions for TestFlight apps & specifically Kindle
|
2023-02-24 17:04:34 -05:00 |
|
Thomas Stromberg
|
fb7cd56249
|
fpr: abrt-dbus, gdm, chrome, ff, etc
|
2023-02-24 16:30:17 -05:00 |
|
Thomas Stromberg
|
995c1e1104
|
Fixes so that ODK can run under CI
|
2023-02-24 12:15:56 -05:00 |
|
Thomas Stromberg
|
d904ca60cf
|
Add exceptions for Debian running under lima
|
2023-02-23 10:33:10 -05:00 |
|
Thomas Stromberg
|
baab22e282
|
Run make reformat-updates
|
2023-02-20 19:12:51 -05:00 |
|
Thomas Stromberg
|
d3780c0a6c
|
Remove ubuntu-lts false-positives on lima
|
2023-02-20 19:10:12 -05:00 |
|
Thomas Stromberg
|
e8cf7ecbe3
|
fpr: exceptions for pacman, StreamDeck, gcloud, Rocket, thunderbird
|
2023-02-20 18:04:17 -05:00 |
|
Thomas Stromberg
|
c2b0423606
|
Rewrite exotic-command-events-linux with INSTR to decrease CPU time
|
2023-02-17 16:39:52 -05:00 |
|
Thomas Stromberg
|
d25a89f241
|
execdir events macOS: Fix ambiguous path
|
2023-02-17 12:01:08 -05:00 |
|
Thomas Stromberg
|
f87541c945
|
False positive flush, particularly in talkers
|
2023-02-17 11:57:23 -05:00 |
|
Thomas Stromberg
|
00398d447b
|
Look for setuid binaries in /usr/libexec too
|
2023-02-17 10:41:28 -05:00 |
|
Thomas Stromberg
|
bc359d69ce
|
Linux events: decrease CPU usage of elevated children & execdir
|
2023-02-17 10:40:58 -05:00 |
|
Thomas Stromberg
|
5eefbd0dba
|
Add chattr, setenforce to unexpected-sysutils
|
2023-02-14 20:35:24 -05:00 |
|
Thomas Stromberg
|
cf858d193d
|
fpr: ACE, Prusa, steam, pacman, Xcode, Adobe
|
2023-02-14 20:16:02 -05:00 |
|
Thomas Stromberg
|
8d4531198f
|
fpr: My ORA, Ecamm, setroubleshootd, etc
|
2023-02-14 19:46:36 -05:00 |
|
Thomas Stromberg
|
d897f0b50d
|
fpr: Nessus, mysql-shell, ntia-checker, Ecamm, CopyClip, etc
|
2023-02-14 08:33:05 -05:00 |
|
Thomas Stromberg
|
34282eacec
|
Increase polling interval to 15 min
|
2023-02-10 10:24:20 -05:00 |
|
Thomas Stromberg
|
0b6e503627
|
New check: Launch Constraint Violation (macOS)
|
2023-02-10 10:22:13 -05:00 |
|