tetragon
59 строк · 1.1 Кб
1apiVersion: cilium.io/v1alpha1
2kind: TracingPolicy
3metadata:
4name: "syswritefollowfdpsswd"
5spec:
6kprobes:
7- call: "fd_install"
8syscall: false
9args:
10- index: 0
11type: int
12- index: 1
13type: "file"
14selectors:
15- matchArgs:
16- index: 1
17operator: "Equal"
18values:
19- "/tmp/test"
20matchBinaries:
21- operator: "In"
22values:
23- "/usr/bin/vim"
24matchActions:
25- action: FollowFD
26argFd: 0
27argName: 1
28- call: "sys_close"
29syscall: true
30args:
31- index: 0
32type: "int"
33selectors:
34- matchActions:
35- action: UnfollowFD
36argFd: 0
37argName: 0
38- call: "sys_write"
39syscall: true
40args:
41- index: 0
42type: "fd"
43- index: 1
44type: "char_buf"
45sizeArgIndex: 3
46- index: 2
47type: "size_t"
48selectors:
49- matchArgs:
50- index: 0
51operator: "Equal"
52values:
53- "/tmp/test"
54matchBinaries:
55- operator: "In"
56values:
57- "/usr/bin/vim"
58matchActions:
59- action: Sigkill
60