Commit Graph

586 Commits

Author SHA1 Message Date
Thomas Stromberg
bd9320acfa
Include possible volume sources 2023-01-27 10:36:37 -05:00
Thomas Stromberg
66ee3484c0
Remove unused active fields, add WhatsApp ioreg exception 2023-01-27 08:46:48 -05:00
Thomas Stromberg
d51bd731a1
fpr: Parallels, nerdctl, Xorg, nvidia, Stream, etc 2023-01-26 20:40:47 -05:00
Thomas Stromberg
b671e30fce
Simplify unexpected-chrome-extensions exceptions for maintainability 2023-01-26 20:40:22 -05:00
Thomas Stromberg
7d8fa35eb4
fpr: Github Absolute Date, Snagit, Figma, Seagate, aws, etc 2023-01-26 16:30:14 -05:00
Thomas Stromberg
f5fe9a4aac
Refactor process_events queries for more accurate parenting 2023-01-26 11:40:54 -05:00
Thomas Stromberg
83cc38207e
fpr: minikube, tailscale, dex, pacman, virtualbox, steam, lsmod, busybox, etc 2023-01-23 20:33:52 -05:00
Thomas Stromberg
f7c1557aee
fpr: libinput, kue, updatedb, mariadb, terraform 2023-01-23 08:13:04 -05:00
Thomas Stromberg
280b187b20
fpr: systemctl calls, go tests, WebEx, MariaDB, Brave 2023-01-20 17:55:48 -05:00
Thomas Stromberg
d55bd17154
listening ports: Add goland exception 2023-01-20 10:00:40 -05:00
Thomas Stromberg
6858bb29eb
framework: Add exception for github runner 2023-01-20 09:59:43 -05:00
Thomas Stromberg
045b8ea524
execdir: exception for JetBrains 2023-01-20 09:57:12 -05:00
Thomas Stromberg
29d563f2df
Add more examples of legit executables, namely ibus-* and *Manager 2023-01-20 09:29:10 -05:00
Thomas Stromberg
e6824d87e9
Run 'make reformat' 2023-01-20 09:24:24 -05:00
Thomas Stromberg
e13773d9b7
Add fish & bash to parent missing disk exclusions 2023-01-20 09:08:45 -05:00
Thomas Stromberg
6014ca1e64
Add missing comma 2023-01-20 09:06:21 -05:00
Thomas Stromberg
dc154a6199
FPR: Meta Pixel Helper, systemctl, pia-daemon, 1Passwd, iTerm, Brave 2023-01-20 09:04:00 -05:00
Thomas Stromberg
8e9ae0fda3
Less false positives: particularly among systemctl calls 2023-01-20 08:40:08 -05:00
Thomas Stromberg
3de05139e3
Merge branch 'main' into fp4 2023-01-19 12:18:29 -05:00
Thomas Stromberg
b601d6c3b0
Add port 19305 (Google Meet) on Firefox 2023-01-19 12:18:22 -05:00
Thomas Stromberg
67fb9cad14
Remove false positive: apt-helper calls to systemctl 2023-01-19 12:16:20 -05:00
Thomas Strömberg
b9ea18e50f
Merge pull request #135 from tstromberg/fp4
Increase long uptime cutoff from 60d to 90d
2023-01-19 12:11:52 -05:00
Thomas Stromberg
0b057b45d2
Increase long uptime cutoff from 60d to 90d 2023-01-19 12:11:01 -05:00
Thomas Strömberg
8a9ad0d8cb
Merge pull request #134 from tstromberg/fp4
False positives: apt-daily, github runner, Slack helper, Foxit, syncthing
2023-01-19 11:52:56 -05:00
Thomas Stromberg
710ca28ed9
False positives: apt-daily, github runner, Slack helper, Foxit, syncthing 2023-01-19 11:52:31 -05:00
Thomas Strömberg
e3852a1e1f
Merge pull request #133 from tstromberg/net-parents
Add more paths to unexpected-hidden-system-paths, rename
2023-01-19 11:43:18 -05:00
Thomas Stromberg
a100aa307f
Add more paths to unexpected-hidden-system-paths, rename 2023-01-19 11:42:44 -05:00
Thomas Strömberg
22b2594d58
Merge pull request #132 from tstromberg/net-parents
old binaries: fix errant mtime comparison
2023-01-19 11:42:19 -05:00
Thomas Stromberg
5abe66644b
old binaries: fix errant mtime comparison 2023-01-19 11:42:00 -05:00
Thomas Strömberg
0027df2995
Merge pull request #131 from tstromberg/net-parents
New detector: unexpected systemctl calls
2023-01-19 11:41:29 -05:00
Thomas Stromberg
24bdaa243a
New detector: unexpected systemctl calls 2023-01-19 11:39:52 -05:00
Thomas Strömberg
720ccbe4e4
Merge pull request #130 from tstromberg/net-parents
New detector: unexpected netutil calls
2023-01-19 11:39:27 -05:00
Thomas Stromberg
2f8cca819b
New detectors: unexpected netutil calls 2023-01-19 11:39:02 -05:00
Thomas Strömberg
8325325996
Merge pull request #129 from tstromberg/fp3
False positives: Chrome extensions, Steam games, tmp files, Photoshop
2023-01-18 14:42:10 -05:00
Thomas Stromberg
5c421f7c96
Refactor unexpected-tmp-executables for magic awareness 2023-01-18 14:41:36 -05:00
Thomas Stromberg
f5e08ceec2
False positives: Chrome extensions, Steam games, tmp files, Photoshop 2023-01-18 14:10:33 -05:00
Thomas Strömberg
0ea1146cd5
Merge pull request #128 from tstromberg/fp3
False positives: homekit, setxid overflows, buildx, tmp, Messenger, etc
2023-01-18 10:58:46 -05:00
Thomas Stromberg
ef5d8afdd0
False positives: homekit, setxid overflows, buildx, tmp files 2023-01-18 10:57:43 -05:00
Thomas Stromberg
7b79b19090
False positive reduction: Messenger, Chrome, Final Cut Pro, etc 2023-01-18 09:49:56 -05:00
Thomas Strömberg
c6221f9d7b
Merge pull request #127 from tstromberg/fp3
FP removal: plymouth, 1Password, firejail, systemd, compile
2023-01-16 13:58:43 -05:00
Thomas Stromberg
09601ed3f0
Switch interval back to 300 2023-01-16 13:58:24 -05:00
Thomas Stromberg
5db432b2c6
Add compile (Go Lang) to exceptions list 2023-01-16 13:57:14 -05:00
Thomas Stromberg
42e9f2721b
FP removal: plymouth, 1Password, firejail, systemd 2023-01-16 13:55:53 -05:00
Thomas Strömberg
45e11c16ec
Merge pull request #126 from tstromberg/fp3
FP's: Selenium, polkit, gephi, docker-credential-gcloud, firejail, etc
2023-01-16 12:57:54 -05:00
Thomas Stromberg
d415b36b57
FP removal: Selenium, PolKit helper, gephi, docker-credential-gcloud, firejail, etc 2023-01-16 12:56:39 -05:00
Thomas Strömberg
9553b75f54
Merge pull request #125 from tstromberg/fp2
False positives: terraform, docker, qemu, aws, lima, etc.
2023-01-14 08:21:14 -05:00
Thomas Stromberg
431720103e
Remove dupe entry 2023-01-14 08:20:11 -05:00
Thomas Stromberg
e3401a07c6
Weekend false-positive flush 2023-01-14 08:19:26 -05:00
Thomas Strömberg
f3c1ce8533
Merge pull request #124 from tstromberg/fp2
Filter out new false positives
2023-01-13 15:24:57 -05:00
Thomas Stromberg
cb896b9e10
Filter out new false positives 2023-01-13 15:24:18 -05:00