tetragon
118 строк · 2.4 Кб
1# This 'process.credentials.changes.at.syscalls' Tracing Policy
2# monitors processes trying to change their credentials inside
3# a pid namespace. If you want to monitor all processes including
4# host ones, remove the matchNamespaces selector.
5#
6# Monitors the following system calls:
7# - setuid(), setgid(), setfsuid(), setfsgid()
8# setreuid(), setregid(), setresuid(), setresgid()
9#
10# - setgroups() TODO
11#
12
13apiVersion: cilium.io/v1alpha114kind: TracingPolicy15metadata:16name: "process.credentials.changes.at.syscalls"17spec:18kprobes:19- call: "sys_setuid"20syscall: true21args:22- index: 023type: "int"24selectors:25- matchNamespaces:26- namespace: Pid27operator: NotIn28values:29- "host_ns"30- call: "sys_setgid"31syscall: true32args:33- index: 034type: "int"35selectors:36- matchNamespaces:37- namespace: Pid38operator: NotIn39values:40- "host_ns"41- call: "sys_setreuid"42syscall: true43args:44- index: 045type: "int"46- index: 147type: "int"48selectors:49- matchNamespaces:50- namespace: Pid51operator: NotIn52values:53- "host_ns"54- call: "sys_setregid"55syscall: true56args:57- index: 058type: "int"59- index: 160type: "int"61selectors:62- matchNamespaces:63- namespace: Pid64operator: NotIn65values:66- "host_ns"67- call: "sys_setresuid"68syscall: true69args:70- index: 071type: "int"72- index: 173type: "int"74- index: 275type: "int"76selectors:77- matchNamespaces:78- namespace: Pid79operator: NotIn80values:81- "host_ns"82- call: "sys_setresgid"83syscall: true84args:85- index: 086type: "int"87- index: 188type: "int"89- index: 290type: "int"91selectors:92- matchNamespaces:93- namespace: Pid94operator: NotIn95values:96- "host_ns"97- call: "sys_setfsuid"98syscall: true99args:100- index: 0101type: "int"102selectors:103- matchNamespaces:104- namespace: Pid105operator: NotIn106values:107- "host_ns"108- call: "sys_setfsgid"109syscall: true110args:111- index: 0112type: "int"113selectors:114- matchNamespaces:115- namespace: Pid116operator: NotIn117values:118- "host_ns"119
120