tetragon
72 строки · 1.3 Кб
1apiVersion: cilium.io/v1alpha1
2kind: TracingPolicy
3metadata:
4name: "syswritefollowfdpsswd"
5spec:
6kprobes:
7- call: "fd_install"
8syscall: false
9args:
10- index: 0
11type: int
12- index: 1
13type: "file"
14selectors:
15- matchPIDs:
16- operator: NotIn
17followForks: true
18isNamespacePID: true
19values:
20- 0
21- 1
22matchArgs:
23- index: 1
24operator: "Equal"
25values:
26- "/etc/passwd"
27matchActions:
28- action: FollowFD
29argFd: 0
30argName: 1
31- call: "sys_close"
32syscall: true
33args:
34- index: 0
35type: "int"
36selectors:
37- matchPIDs:
38- operator: NotIn
39followForks: true
40isNamespacePID: true
41values:
42- 0
43- 1
44matchActions:
45- action: UnfollowFD
46argFd: 0
47argName: 0
48- call: "sys_write"
49syscall: true
50args:
51- index: 0
52type: "fd"
53- index: 1
54type: "char_buf"
55sizeArgIndex: 3
56- index: 2
57type: "size_t"
58selectors:
59- matchPIDs:
60- operator: NotIn
61followForks: true
62isNamespacePID: true
63values:
64- 0
65- 1
66matchArgs:
67- index: 0
68operator: "Prefix"
69values:
70- "/etc/passwd"
71matchActions:
72- action: Sigkill
73